Skip to main content

SponsoredBuild your website with Vincony

Disclaimer: This is not legal advice. Legislation and case law change. Always consult a qualified solicitor for your specific situation.

UK Law Reference
Full glossary
Legal term
Data Protection & Privacy Law

Personal Data

Any information relating to an identified or identifiable living individual (data subject). Includes names, identification numbers, location data, online identifiers, and factors specific to physical, genetic, or social identity.

Independent editorial summary — not the official statute text. Read the official version on legislation.gov.uk.

Personal data is the central concept that determines whether the UK GDPR and the Data Protection Act 2018 apply to information. The ICO's guidance explains that the UK GDPR defines personal data as any information relating to an identified or identifiable natural person, and that an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity. In practice, this means personal data has to be information that relates to an individual, and that individual must be identified or identifiable, either directly or indirectly.

Some personal data is treated as more sensitive and requires a higher level of protection: the UK GDPR refers to this as 'special category data', covering information such as race, ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health data, sex life and sexual orientation, as well as data about criminal convictions and offences. Pseudonymised data, where identifying details are replaced with a reference number but could still be linked back to an individual using separately held information, remains personal data; only data that has been fully anonymised, such that the individual can no longer be identified by any reasonably available means, falls outside the UK GDPR.

Two important limits apply to the concept. The UK GDPR only applies to information which relates to an identifiable living individual, so information relating to a deceased person does not constitute personal data and therefore is not subject to the UK GDPR. Equally, information about a company or other legal entity is not personal data, though information about an individual acting as a sole trader, employee, partner or director can still be personal data if it relates to them as an individual.

Example

A spreadsheet listing customers' names alongside a reference number that a business can use, together with other information it holds, to trace those customers is personal data, even though the reference number alone does not name anyone.

Related terms

Official sources

This explanation is drawn from the official sources below; every substantive statement is verified against them. For advice on a specific matter, see our find help page.