Skip to content
Topic Contested in court

Personal Data

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Information relating to identified or identifiable natural persons

3,929 linked items 201 Laws426 Case Law442 Guidance2394 Enforcement344 News

Overview

28 sources · Aug 27, 2026

Legal Framework

The right to protection of personal data is constitutionally anchored in Article 16 of the EU Charter, which empowers the EU legislature to lay down rules on the processing of personal data and its free movement. The operational core of this framework is the GDPR, whose Article 4(1) defines the material scope of protection:

This definition is deliberately broad, encompassing both directly identified individuals and those identifiable through identifiers such as names, location data, online identifiers, or factors specific to physical, economic, cultural, or social identity. Pseudonymised data remains personal data under Article 4(5), since re-identification is possible with additional information.

Once information qualifies as personal data, the processing principles in Article 5(1) apply in full: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and security. Processing must additionally rest on at least one lawful basis under Article 6(1), whether consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests.

Key Developments

Enforcement decisions have sharpened the practical boundaries of what constitutes lawful processing of personal data. The Swedish DPA's decision against a school in Skellefteå illustrates the threshold for valid consent in sensitive-data contexts:

"consent can not be applied since students and their guardians cannot freely decide if they/their children want to be monitored for attendance purposes"
— Skellefteå school decision

The case involved facial recognition for attendance monitoring — biometric data triggering Article 9 — and the DPA found the measure disproportionate even though attendance monitoring itself can be lawful. The Baden-Wuerttemberg DPA similarly sanctioned a police officer who queried licence plate owner data without official cause, confirming that a valid legal basis for access does not authorise processing for unrelated personal purposes.

The Danish DPA's enforcement against IDdesign addressed storage limitation under Article 5(1)(e), where the company retained approximately 385,000 customers' data beyond the period necessary for the original purpose. The court reduced the fine based on the company's own turnover and mitigating factors, but confirmed the underlying violation.

Status of the Debate

The definition of personal data is settled in its core: any information relating to an identified or identifiable natural person falls within scope. What remains actively contested is the outer boundary — specifically, whether certain categories of data (dynamic IP addresses, hashed identifiers, device fingerprints) qualify as personal data in contexts where re-identification requires disproportionate effort. The CJEU's line of reasoning from Breyer through Schrems II suggests a context-dependent, risk-based approach, but courts diverge on how to weigh the means reasonably likely to be used for identification. No single post-GDPR ruling has definitively resolved this threshold question. A future CJEU reference on whether pseudonymised data in a specific technical configuration remains identifiable would provide needed clarity.

Practical Guidance

  • Classify data at the point of collection. Determine whether each data element, alone or combined with others, can identify a natural person under Article 4(1). When in doubt, treat it as personal data.
  • Anchor every processing operation in a specific lawful basis under Article 6(1). Document the basis at the time of collection and reassess it when purposes change.
  • Apply data minimisation rigorously. The Skellefteå and AEPD CCTV cases confirm that even a valid purpose does not justify disproportionate data collection; choose the least intrusive means.
  • Set and enforce retention deadlines. The IDdesign decision demonstrates that failing to establish deletion timelines — and failing to execute them — constitutes a standalone violation of Article 5(1)(e).
  • Verify consent quality, not just existence. Consent must be freely given, specific, and revocable. In contexts of power imbalance (schools, employment), consent will likely fail as a lawful basis, as the Skellefteå decision confirms.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 14 Information to be provided where personal data have not been obtained from the data subject Laws GDPR Apr 2016 information duties for indirect collection
why this is here
Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information

This provision directly regulates the obligations of controllers when processing personal data not obtained directly from the data subject, which is a central aspect of personal data protection under the GDPR.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 5 Principles relating to processing of personal data Laws GDPR Apr 2016 definition of personal data
why this is here
1. Personal data shall be:

The provision directly defines the criteria for personal data, which is the subject of the topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Guidance EDPB Apr 2023 definition of personal data breach
why this is here
a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data

The document defines what constitutes a breach of personal data, which is central to the concept of personal data.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Personal data in connected vehicles
why this is here
most of which can be considered personal data since they will relate to drivers or passengers

The document explicitly discusses what constitutes personal data in the context of connected vehicles, directly relevant to the concept of personal data.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

art 33 Notification of a personal data breach to the supervisory authority Laws GDPR Apr 2016 defines personal data breach
why this is here
In the case of a personal data breach, the controller shall without undue delay

The provision repeatedly references 'personal data breach', which is a concept within the scope of personal data protection, but the article itself is about notification obligations, not the definition or handling of personal data.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 9 Processing of special categories of personal data Laws GDPR Apr 2016 subcategory of personal data
why this is here
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership

The article regulates a specific subset of personal data, but it presupposes and partly defines what counts as personal data in this context.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 01/2021 Examples regarding Personal Data Breach Notification Guidelines ·EDPB Guidance EDPB Jan 2022 definition of personal data breach
why this is here
The GDPR defines a “personal data breach” in Article 4(12) as “a breach of security leading to...

The document focuses on breaches of personal data, thus supporting the concept of personal data as the subject matter, though it does not define personal data itself beyond the breach definition.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Personal data in video context
why this is here
collection and retention of pictorial or audio - visual information on all persons entering the monitored space that are identifiable

It explains when video footage constitutes personal data.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

art 12 Transparent information, communication and modalities for the exercise of the rights of the data subject Laws GDPR Apr 2016 contextual reference to data subjects and processing
why this is here
any communication under Articles 15 to 22 and 34 relating to processing to the data subject

While the provision repeatedly mentions 'data subject' and 'processing', it does not define or substantively regulate personal data itself; it only operates in the context where such data is already being processed.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 15 Right of access by the data subject Laws GDPR Apr 2016 data subjects' personal data scope
why this is here
access to the personal data and the following information

The provision operationalizes the concept of personal data by specifying how data subjects can access their own data, but it does not define or scope the concept of personal data itself.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

art 10 Processing of personal data relating to criminal convictions and offences Laws GDPR Apr 2016 Personal data scope
why this is here
Processing of personal data relating to criminal convictions and offences

The provision concerns personal data, but its specific subject is criminal data, not personal data generally; it touches on personal data only as a subset.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Guidance EDPB Apr 2023 Definition of personal data in access context
why this is here
The scope of the right of access is determined by the scope of the concept of personal data as defined in Art. 4(1) GDPR.

The document references the definition of personal data to define the scope of access, but it is not the main focus.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 05/2020 consent under Regulation 2016/679 Guidelines on consent Guidelines ·EDPB Guidance EDPB May 2020 Definition of personal data
why this is here
any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

The document defines consent in relation to personal data processing, but does not focus on defining personal data itself.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 5/2019 criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) Guidelines ·EDPB Guidance EDPB Jul 2020 Personal data in search results
why this is here
the processing of personal data carried out in the context of the activity of the search engine provider

The document focuses on delisting of personal data but does not define or analyze the concept of personal data itself.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

This is the top of each pile — all 201 Laws · all 442 Guidance · all 426 Case Law · all 2394 Enforcement · all 116 Literature · all 344 News