Ch.10 Protecting Personal Data and Privacy Regulation 252 words

Personal data: the 'identifiable person' test

Any info relating to an identified or identifiable natural person. The trap: indirect identifiers (e.g., job title + postcode) can also count.

Аудио

Слушай тази страница (бета)

Субтитри

Under GDPR, personal data isn't just obvious items like a full name or national ID number. It covers any information that can identify a living person, either directly or indirectly. For example, a person's job title combined with their postcode might be enough to single them out, even if you never knew their name. The key contrast is between data that identifies someone on its own (direct identifier) and data that only does so when combined with other pieces (indirect identifier). Both fall under the regulation.

A common exam trick is to present a dataset with a name removed but still containing a unique employee number or a precise GPS location. Remember that any online identifier, such as an IP address or cookie ID, also qualifies if it can be linked back to an individual. To avoid falling for a distractor, ask yourself: could a reasonable person, using available information, connect this data to a specific natural person? If yes, it's personal data. Also watch for pseudonymised data—it remains personal data if the key to re-identify still exists somewhere.

A quick mental test: imagine you find a spreadsheet with only 'Customer 123' and a purchase history. If you also hold a separate list linking 'Customer 123' to 'Jane Smith', then both datasets contain personal data. The moment any piece of information can be tied to a real person, even through a code or combination, GDPR applies. This is the core of the 'identifiable person' test—focus on the link, not just the label.

Свързана флашкарта

What counts as personal data under GDPR?

Any information relating to an identified or identifiable natural person.

Обратно към флашкартата Виж всички флашкарти