We all have experiences dealing with different type of personal data during our daily shopping, web-shops orders, be at our workplace, subscribing to newsletters… not to mention when we want to delete one of our accounts.
Our experiences vary and sometimes you might feel what happens is not right, but we just don’t want to make a fuss about it or we are simply in a hurry. Maybe we also think, “That is weird, why they ask me that… but some lawyer or someone must have checked it and found it is okay… right?”
No matter what your profession is, I am sure you also see your peers’ work with a critical eye and spot mistakes much more easily than the average human would do. As data privacy consultants, we do the exact same thing.
In this post, I would like to explain basic privacy concepts and perhaps help you feel more confident the next time you have to deal with “personal data.” We put personal data in quotes because it is a concept that many people misunderstand.
Deconstructing the GDPR Personal Data Definition
According to Article 4 of the GDPR:
“‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;”
It is pretty legal and broad, so let’s break it up a little.
In a nutshell, you should understand it this way: if you are able to piece information together and identify the specific person this information belongs to, then it becomes personal data.
But what about a simple birthdate, for example? Well, if you only have 05.05.2025 floating in a spreadsheet, it’s not personal data on its own. But if you have the birthday of the oldest person alive in a town, and you also have something else related to it like an eye color, then it is personal data because the crowd has narrowed down to a single human being.
Most people think personal data must be a name, an email address, a phone number, or a government ID number, but this is simply not the case.
What Does an “Identifiable Natural Person” Actually Mean?
To count as personal data, identifying the person has to be reasonably possible. If you would need to hire a private investigator to find out who the person is, then it is likely not personal data.
Although, with the age of AI, big data, and all our data randomly scattered around the internet, this “reasonable identification” question is going to be an interesting puzzle in the future.
Also, would a common name like John Doe be personal data? On its own, very unlikely. Unless it is a highly unique name, without any other hints or context you would not be able to identify a specific individual out of thousands of John Does.
The 3-Part Anonymity Litmus Test
Because identity can be tricky, European regulators and data protection authorities don’t just guess if data is personal—they run it through a strict, three-part litmus test derived from official EU guidelines.
To determine if your data has truly broken all ties to a real human being, ask your team these three questions:
- 1. Singling Out: Can you isolate an individual’s activity from the rest of your users, even without knowing their name? (Example: Tracking a unique browser session that views a specific pair of shoes).
- 2. Linkability: Can you connect two or more separate records across different systems to the same person? (Example: Linking a user’s anonymous mobile app usage history with their website purchase history).
- 3. Inference: Can you deduce a person’s traits or identity by looking at the surrounding context of the data? (Example: Correctly guessing who a redacted HR file belongs to by looking at a rare job title and a specific office location).
How to Use It in Practice
If your team answers “Yes” to even a single one of these questions, the dataset is legally personal data, and the GDPR applies in full.
True anonymization requires a definitive “No” to all three. If the data cannot be singled out, cannot be linked to other files, and allows zero inferences, only then is it safely outside the scope of European privacy law.
The Creepy Side of Location and Tracking Data
Ok, but what about broad things like location? If you are a customer of a web-shop, they will know where you are when you use their service. The most basic identifier used here is an IP address, which can lead back to a single house or even a specific apartment in a building.
I would certainly feel my privacy was violated if a random web-shop actively referenced that background data. Imagine receiving an automated email after you bought new headphones online:
“You must have had a small accident by the poolside at Hotel XY in Tenerife! But no worries, your headphones will be waiting for you at home when you get back from vacation. Buy our insurance now and your next pair will be covered.”
Here, as always, it depends on what is justifiable. A web-shop has a legitimate interest to protect itself from fraud and malicious actors, so they might temporarily keep logs of your IP address—hence, your location.
But they should not use that security data in their marketing or sales campaigns. They should be happy with your shipping address for sending you the order, and perhaps keep your city name on record for localized marketing purposes—and not correlate all this background information.
The GDPR actually asks all data to be used strictly for the specific aim it was collected, and requires those reasons to be explicitly justified. This is exactly why using AI to cross-reference these data points opens up completely new questions and legal dimensions.
Real-World Compliance Misconceptions
To round things out, let’s look at three incredibly common scenarios where businesses get the privacy rules completely wrong:
Myth 1: The Email Loophole
- The Scenario: A sales representative downloads a list of corporate work emails (like
john.doe@company.com) and says, “GDPR only covers private consumers, not people at work.” - The Reality: Wrong. A direct work email points to a specific person, meaning these lists must follow the exact same privacy laws. (Note: If the email address is generic, like
contact@company.com, then it does not identify a specific person in a big company, and sits outside this rule).
Myth 2: “We Only Track Machines”
- The Scenario: A mobile app logs phone serial numbers and IP addresses but no names or accounts, claiming, “We only track machines, not people.”
- The Reality: Wrong. Device IDs and IP addresses act as unique digital fingerprints. They allow companies to isolate, link, and track a single user’s behavior over time, which legally counts as personal data.
Myth 3: Anonymous CCTV
- The Scenario: A store owner installs security cameras that record customers’ faces but says, “We don’t know any of these people’s names or addresses, so it’s not personal data.”
- The Reality: Wrong. You don’t need a name tag to identify someone. Because the video captures distinct physical traits that allow a business to single out and track an individual’s specific actions, it is protected data.
Let’s Figure It Out Together
Did you get a little bit overwhelmed? Don’t worry, you don’t need to have all the answers mapped out. Privacy landscapes can be incredibly complex, and trying to decipher regulatory nuances on your own is a lot to ask.
Whether you’re looking to untangle a specific data workflow, want to chat through recent compliance updates, or just don’t know where to start, we are here to help. No sales pitch—just a friendly, expert team ready to support you.