Glossary
2026-07-27 00:00 Glossary

Personal Data: Legal Definition and Meaning

Personal data is any information that relates to an identified or identifiable living person. The concept sits at the heart of modern privacy law and affects virtually every business that collects, stores, processes or shares information about individuals. Understanding the precise legal meaning of personal data is not optional for international operators - it determines which regulatory frameworks apply, what obligations arise and what penalties are at stake if the rules are breached. This guide covers the legal definition, the categories of data that qualify, the distinction between ordinary and sensitive data, how the concept applies across major jurisdictions, and the practical steps businesses must take to stay compliant.

What personal data means in law

Personal data, in its most widely accepted legal formulation, is information relating to an identified or identifiable natural person. The person to whom the data relates is called the data subject. "Identifiable" is the operative word: a person is identifiable if they can be singled out directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.

This definition originates in European data protection law and has been adopted, with variations, across dozens of jurisdictions worldwide. The breadth of the definition is intentional. Legislators recognised that technology makes it increasingly easy to combine fragments of information that, individually, seem innocuous but together identify a specific person. A name alone may be personal data. An IP address may be personal data. A photograph is personal data. Even a combination of job title, employer and approximate age can be sufficient to single out an individual in a small organisation.

The definition applies only to living natural persons. Information about deceased individuals and about legal entities such as companies does not, as a general rule, qualify as personal data under most frameworks, although some jurisdictions extend limited protections to information about the recently deceased.

The scope of identifiability: direct and indirect identification

The concept of identifiability has two dimensions. Direct identification occurs when the data itself names or uniquely designates the individual - a full name, a national identity number, a passport number, or a biometric record. Indirect identification occurs when the data, alone or in combination with other information, allows the individual to be singled out without naming them explicitly.

Indirect identification is where the legal analysis becomes nuanced. A vehicle registration plate does not contain a name, but it can be traced to a registered keeper. A cookie identifier does not carry a name, but it can be linked to a browsing profile and, through additional steps, to a specific person. Courts and regulators have consistently held that the test is not whether identification is easy or immediate, but whether it is reasonably possible given the means likely to be used by the controller or any third party.

The "reasonable means" standard matters enormously in practice. A data controller must assess whether the information it holds, combined with data it could realistically obtain from public sources or from other parties, would allow identification. If the answer is yes, the information is personal data and the full weight of applicable data protection law applies. A common mistake among businesses is to assume that pseudonymised or aggregated data falls entirely outside the definition. Pseudonymised data - data from which direct identifiers have been removed but which can be re-linked using a separate key - remains personal data. Truly anonymised data, from which re-identification is not reasonably possible, is outside the definition, but achieving genuine anonymisation is technically demanding and often underestimated.

Categories of personal data: ordinary and special

Not all personal data carries the same legal weight. Most frameworks distinguish between ordinary personal data and a narrower category of especially sensitive information that attracts heightened protection.

Ordinary personal data covers the broad range of information described above: names, contact details, financial records, employment history, behavioural data, location data, device identifiers and similar information. Processing ordinary personal data requires a lawful basis - such as consent, contractual necessity, legal obligation, legitimate interests or vital interests - but the compliance requirements, while substantial, are manageable for most businesses.

Special categories of personal data are subject to stricter rules. The categories most commonly recognised across jurisdictions include:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometric data processed for the purpose of uniquely identifying a person
  • Health data
  • Data concerning a person';s sex life or sexual orientation

Processing special category data is generally prohibited unless one of a limited set of explicit exceptions applies. These exceptions typically include explicit consent from the data subject, processing necessary for employment law obligations, processing necessary to protect vital interests, processing by not-for-profit bodies in the course of legitimate activities, data manifestly made public by the data subject, processing for legal claims, processing for reasons of substantial public interest, processing for medical or public health purposes, and processing for archiving, research or statistical purposes.

Criminal conviction and offence data is treated as a separate, similarly sensitive category in many frameworks, with processing restricted to official authorities or those acting under official authority.

How the definition applies across major legal frameworks

The most influential articulation of the personal data definition is found in the General Data Protection Regulation, which applies across the European Economic Area and has shaped privacy legislation globally. The GDPR';s definition - "any information relating to an identified or identifiable natural person" - is now the de facto international benchmark.

The United Kingdom retained the GDPR framework after its departure from the EU, incorporating it into domestic law through the UK GDPR and the Data Protection Act. The definition and the core principles are substantively identical to the EU version, though the UK has signalled an interest in diverging in certain technical respects over time.

In the United States, there is no single federal personal data law equivalent to the GDPR. Instead, a patchwork of sector-specific federal laws - covering health information, financial data, children';s data and others - and a growing number of state-level comprehensive privacy statutes define personal data or "personal information" in ways that broadly track the European model but with important variations. Several state laws adopt a narrower definition focused on data that is "linked or reasonably linkable" to a particular consumer or household, which is functionally similar to the EU approach but differs in detail.

Brazil';s Lei Geral de Proteção de Dados, Canada';s Personal Information Protection and Electronic Documents Act, Japan';s Act on the Protection of Personal Information, and the privacy laws of Australia, Singapore, South Korea and many other jurisdictions all define personal data or personal information in ways that share the core logic of identifiability, though the precise scope, the categories of sensitive data and the lawful bases for processing vary. Businesses operating internationally must map their data flows against each applicable framework, not simply assume that GDPR compliance covers all obligations.

A non-obvious requirement that frequently catches international businesses is the treatment of employee data. Employment records - payroll information, performance reviews, disciplinary records, health and absence data - are personal data in every major jurisdiction. Many companies apply robust consumer data practices but overlook the equivalent obligations for their own workforce.

Personal data in practice: business obligations and common mistakes

Understanding the definition of personal data is the starting point, not the end point. Once a business determines that it processes personal data, a chain of obligations follows. These obligations vary by jurisdiction but share a common architecture.

The first obligation is transparency. Data subjects must be informed about who is collecting their data, for what purposes, on what legal basis, for how long, and with whom it will be shared. This information is typically delivered through a privacy notice or privacy policy. A common mistake is to publish a generic privacy notice that does not accurately reflect the actual processing activities of the business - regulators treat this as a compliance failure in its own right.

The second obligation is to establish and document a lawful basis for each processing activity. Consent is the most visible basis but is not always the most appropriate. Businesses that rely on consent must ensure it is freely given, specific, informed and unambiguous, and must be able to demonstrate that consent was obtained. Consent cannot be bundled into terms and conditions or made a condition of service where the processing is not strictly necessary.

The third obligation is data minimisation. Businesses should collect only the personal data they actually need for the stated purpose. In practice, many organisations accumulate data opportunistically - collecting everything that might be useful one day - and then struggle to justify the retention of large volumes of data they cannot account for. This creates both regulatory risk and operational complexity.

The fourth obligation is security. Personal data must be protected by appropriate technical and organisational measures against unauthorised access, loss, destruction or disclosure. What is "appropriate" depends on the sensitivity of the data, the volume processed and the state of available technology. Security obligations apply to processors - third-party service providers that handle personal data on behalf of the controller - as well as to controllers themselves. Contracts with processors must include specific data protection clauses.

The fifth obligation is rights management. Data subjects have rights - to access their data, to correct inaccuracies, to request erasure in certain circumstances, to restrict processing, to data portability and to object to processing. Businesses must have processes in place to receive and respond to these requests within the timeframes prescribed by applicable law, which is typically one month under the GDPR model.

If you need to assess whether your current data processing activities are correctly structured, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.

Personal data and cross-border data transfers

One of the most practically significant aspects of personal data law for international businesses is the restriction on transferring personal data across borders. Most major frameworks prohibit or restrict the transfer of personal data to countries that do not provide an adequate level of protection.

Under the GDPR, transfers to third countries are permitted where the European Commission has issued an adequacy decision recognising the destination country';s legal framework as equivalent in protection. Where no adequacy decision exists, transfers must be covered by appropriate safeguards - most commonly Standard Contractual Clauses issued by the Commission, Binding Corporate Rules for intra-group transfers, or other approved mechanisms.

The UK operates a parallel system following its departure from the EU, with its own adequacy regulations and its own version of standard contractual clauses. Businesses transferring data between the EU and the UK, or between either and third countries, must map each transfer and ensure the correct mechanism is in place.

A practical scenario: a European company uses a US-based cloud provider to store customer records. The data is personal data. The transfer to the US requires a valid transfer mechanism - historically the Privacy Shield framework, which was invalidated by the Court of Justice of the EU, and now typically Standard Contractual Clauses supplemented by a transfer impact assessment. Many businesses discovered this requirement only after the fact, resulting in significant remediation work.

A second practical scenario: a multinational group centralises HR data processing in a shared services centre located outside the EEA. Employee data from EU entities flows to the shared services centre. This is a restricted transfer requiring a lawful mechanism, typically Binding Corporate Rules or Standard Contractual Clauses, and the employees must be informed. Many underestimate the compliance burden of intra-group transfers, treating them as internal movements rather than regulated cross-border transfers.

The consequences of unlawful transfers are serious. Under the GDPR, fines for violations can reach significant percentages of global annual turnover, and regulators have demonstrated a willingness to impose substantial penalties. Beyond fines, businesses face reputational damage, suspension of processing activities and potential civil claims from data subjects.

FAQ

What is the difference between personal data and sensitive personal data?

Personal data is the broad category covering any information that identifies or can identify a living individual. Sensitive personal data - sometimes called special category data - is a defined subset that attracts stricter legal protection because of the particular risks its misuse poses to individuals. The special categories typically include health data, genetic and biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, and data about sex life or sexual orientation. Processing sensitive personal data requires not only a lawful basis but also a separate, explicit condition drawn from a limited list of exceptions. Businesses that handle health records, HR data involving disability or religion, or any biometric identification systems must ensure they have identified and documented both the lawful basis and the applicable special category condition before processing begins.

How long can a business retain personal data?

There is no universal retention period prescribed by data protection law. The principle of storage limitation requires that personal data be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which it was collected. In practice, retention periods are determined by the purpose of processing, any statutory minimum or maximum retention requirements in applicable sector-specific law, and the organisation';s own documented retention policy. Employment records, financial records and certain health records are subject to minimum retention requirements under employment, tax and healthcare legislation in most jurisdictions. A common mistake is to retain data indefinitely because deletion is operationally inconvenient, or to apply a single blanket retention period to all data regardless of purpose. Regulators expect businesses to maintain a documented retention schedule and to implement deletion or anonymisation at the end of the applicable period.

Does personal data law apply to business-to-business data?

The short answer is: it depends on whether the data relates to identifiable natural persons. Information about a company as a legal entity - its registered name, address, company number - is generally not personal data. However, much B2B data does relate to individuals. Contact details for named employees, email addresses in the format info@vlolawfirm.com, and records of individual purchasing decisions or communications are personal data because they relate to identifiable natural persons. Businesses operating in B2B markets frequently underestimate their personal data obligations, assuming that because their customers are companies rather than consumers, data protection law does not apply. This is incorrect. The relevant question is always whether the information relates to an identifiable living individual, not whether the commercial relationship is B2B or B2C.

Conclusion

Personal data is a foundational concept in modern law, defining the scope of privacy obligations for businesses worldwide. The definition is broad, technology-neutral and designed to capture information that can identify individuals directly or indirectly. Businesses that process personal data - which means virtually all businesses - must understand what qualifies, how sensitive categories are treated differently, and what obligations arise under each applicable framework.

VLO Law Firms advises international clients on personal data compliance, data protection frameworks and cross-border data transfer structures. We can assist with privacy assessments, documentation, lawful basis analysis and regulatory correspondence. To request a consultation, contact: info@vlolawfirm.com