Personal Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Information relating to identified or identifiable natural persons
Overview
28 sources · Aug 27, 2026Legal Framework
The right to protection of personal data is constitutionally anchored in Article 16 of the EU Charter, which empowers the EU legislature to lay down rules on the processing of personal data and its free movement. The operational core of this framework is the GDPR, whose Article 4(1) defines the material scope of protection:
This definition is deliberately broad, encompassing both directly identified individuals and those identifiable through identifiers such as names, location data, online identifiers, or factors specific to physical, economic, cultural, or social identity. Pseudonymised data remains personal data under Article 4(5), since re-identification is possible with additional information.
Once information qualifies as personal data, the processing principles in Article 5(1) apply in full: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and security. Processing must additionally rest on at least one lawful basis under Article 6(1), whether consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests.
Key Developments
Enforcement decisions have sharpened the practical boundaries of what constitutes lawful processing of personal data. The Swedish DPA's decision against a school in Skellefteå illustrates the threshold for valid consent in sensitive-data contexts:
"consent can not be applied since students and their guardians cannot freely decide if they/their children want to be monitored for attendance purposes"
— Skellefteå school decision
The case involved facial recognition for attendance monitoring — biometric data triggering Article 9 — and the DPA found the measure disproportionate even though attendance monitoring itself can be lawful. The Baden-Wuerttemberg DPA similarly sanctioned a police officer who queried licence plate owner data without official cause, confirming that a valid legal basis for access does not authorise processing for unrelated personal purposes.
The Danish DPA's enforcement against IDdesign addressed storage limitation under Article 5(1)(e), where the company retained approximately 385,000 customers' data beyond the period necessary for the original purpose. The court reduced the fine based on the company's own turnover and mitigating factors, but confirmed the underlying violation.
Status of the Debate
The definition of personal data is settled in its core: any information relating to an identified or identifiable natural person falls within scope. What remains actively contested is the outer boundary — specifically, whether certain categories of data (dynamic IP addresses, hashed identifiers, device fingerprints) qualify as personal data in contexts where re-identification requires disproportionate effort. The CJEU's line of reasoning from Breyer through Schrems II suggests a context-dependent, risk-based approach, but courts diverge on how to weigh the means reasonably likely to be used for identification. No single post-GDPR ruling has definitively resolved this threshold question. A future CJEU reference on whether pseudonymised data in a specific technical configuration remains identifiable would provide needed clarity.
Practical Guidance
- Classify data at the point of collection. Determine whether each data element, alone or combined with others, can identify a natural person under Article 4(1). When in doubt, treat it as personal data.
- Anchor every processing operation in a specific lawful basis under Article 6(1). Document the basis at the time of collection and reassess it when purposes change.
- Apply data minimisation rigorously. The Skellefteå and AEPD CCTV cases confirm that even a valid purpose does not justify disproportionate data collection; choose the least intrusive means.
- Set and enforce retention deadlines. The IDdesign decision demonstrates that failing to establish deletion timelines — and failing to execute them — constitutes a standalone violation of Article 5(1)(e).
- Verify consent quality, not just existence. Consent must be freely given, specific, and revocable. In contexts of power imbalance (schools, employment), consent will likely fail as a lawful basis, as the Skellefteå decision confirms.
why this is here
Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information
This provision directly regulates the obligations of controllers when processing personal data not obtained directly from the data subject, which is a central aspect of personal data protection under the GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
1. Personal data shall be:
The provision directly defines the criteria for personal data, which is the subject of the topic.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data
The document defines what constitutes a breach of personal data, which is central to the concept of personal data.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
most of which can be considered personal data since they will relate to drivers or passengers
The document explicitly discusses what constitutes personal data in the context of connected vehicles, directly relevant to the concept of personal data.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
In the case of a personal data breach, the controller shall without undue delay
The provision repeatedly references 'personal data breach', which is a concept within the scope of personal data protection, but the article itself is about notification obligations, not the definition or handling of personal data.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership
The article regulates a specific subset of personal data, but it presupposes and partly defines what counts as personal data in this context.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
The GDPR defines a “personal data breach” in Article 4(12) as “a breach of security leading to...
The document focuses on breaches of personal data, thus supporting the concept of personal data as the subject matter, though it does not define personal data itself beyond the breach definition.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
collection and retention of pictorial or audio - visual information on all persons entering the monitored space that are identifiable
It explains when video footage constitutes personal data.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
any communication under Articles 15 to 22 and 34 relating to processing to the data subject
While the provision repeatedly mentions 'data subject' and 'processing', it does not define or substantively regulate personal data itself; it only operates in the context where such data is already being processed.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
access to the personal data and the following information
The provision operationalizes the concept of personal data by specifying how data subjects can access their own data, but it does not define or scope the concept of personal data itself.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
Processing of personal data relating to criminal convictions and offences
The provision concerns personal data, but its specific subject is criminal data, not personal data generally; it touches on personal data only as a subset.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
The scope of the right of access is determined by the scope of the concept of personal data as defined in Art. 4(1) GDPR.
The document references the definition of personal data to define the scope of access, but it is not the main focus.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
The document defines consent in relation to personal data processing, but does not focus on defining personal data itself.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the processing of personal data carried out in the context of the activity of the search engine provider
The document focuses on delisting of personal data but does not define or analyze the concept of personal data itself.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Nothing of this type on this topic.
This is the top of each pile — all 201 Laws · all 442 Guidance · all 426 Case Law · all 2394 Enforcement · all 344 News · all 116 Literature