Below, you can read the second article in our series of specialized contents on the General Data Protection Regulation. You can access the complete series on our blog.

Todo lo que querías (y necesitas) saber sobre la normativa RGPD

What Is Personal Data Under the GDPR: Definition in Article 4.1

According to Article 4.1 of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), personal data is any information relating to an identified or identifiable natural person. A person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as their name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person. The question to ask as the headline of this article is very common in environments where the GDPR has some influence or even in our personal life, when a company asks us for consent to process our personal data for different purposes. “Well, why not, but first I would like to know what is considered personal data“.

We will respond in depth.

To get straight to the point, we will say that personal data is any information and/or characteristic that makes it possible to identify or make identifiable any person. This is defined in Article 4.1 of the GDPR.

Consequently, the image of a person is personal data, as is any information that allows to determine, directly or indirectly, his identity, such as, for example, a name, an identification number, a telephone number, a vehicle license plate, an IP address… Or even anthropometric characteristics that allow to unequivocally identify a person, as the Spanish Data Protection Agency (AEPD) has considered on numerous occasions.

On the other hand, personal data would not be those that do not facilitate the identification of the natural person, such as, for example: commercial registration number (CIF), a generic e-mail address, such as info@, and others.

Categories of personal data recognized by the GDPR

The GDPR recognizes the existence of categories of personal data and even determines a very specific one referring to specially protected data.

Below is an approximate list of the types of personal data that exist:

  1. Identifying data: name, ID card number, Social Security number, telephone number, address, signature, user name, IP address, etc.
  2. Personal characteristics: physical characteristics, preferences, hobbies, date of birth, etc.
  3. Family and social circumstances: number of children, leaves of absence, leaves of absence, etc.
  4. Employment information: professional category, job position, professional experience, payroll, etc.
  5. Academic and professional data: education, degrees, academic history, etc.
  6. Time and attendance control: clocking in at the workstation or access control to the facilities.
  7. Financial: income, income, bank details, etc.

Special categories of personal data under Article 9 of the GDPR

In relation to the category of specially protected data, provided for in article 9 of the GDPR, are those data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data[1], biometric data[2] aimed at uniquely identifying a natural person, data concerning the health or life and sexual orientations of a natural person.

The processing of this type of data is prohibited, unless it complies with a number of exceptions, such as the following:

  • ExplicitGDPR consent from the data subject.
  • Fulfillment of obligations and exercise of rights in the field of labor law and social security and protection.
  • Protection of vital interests of the data subject
  • Processing carried out within the scope of foundations or associations whose purpose is political, philosophical, religious or trade union.
  • Processing of manifestly public data.
  • Processing necessary for the formulation, exercise or defense of claims, or processing carried out by courts in the exercise of their judicial function.
  • For reasons of public interest in the field of public health.
  • Processing necessary for archiving and public interest purposes, scientific or historical research purposes or statistical purposes.

How to Collect Personal Data in Compliance with the GDPR: Channels and Evidence

Data can be collected through any channel (paper, electronic format, voice…). However, both at the time of collection and subsequently, the controller[3] must provide information on how your data will be processed in accordance with Articles 13 and 14 of the GDPR.

In this case, and depending on the type of communication channel used, the way of providing this information may vary (paper, email, or WhatsApp are some of the possible channels). The layer system is very useful to facilitate the information in a data collection process. That is to say, in a first layer the basic information is provided and in a second layer the additional information.

For more details on how and when to provide this information, it is advisable to consult the Guide for the fulfillment of the duty to inform, published by the Spanish Data Protection Agency.

In any case, this information must be provided in clear and simple language, in a concise, transparent, intelligible and easily accessible form. For this reason, the importance of the data collection process by the data controller must be emphasized, who can collect data through forms, models or templates, sent through any channel. The important thing is to have evidence that can guarantee that the process has been carried out in compliance with the requirements of the GDPR.

In principle, any means of data collection is valid. Nowadays there are many channels for collecting data, and most of them, besides being agile, are very usable by the general public, as is the case of WhatsApp. What is essential is that the data controller is able to accredit its collection and to prove that it has the consents that may be attached to it for specific purposes.

As indicated above, it is up to the company’s data controller to provide the information and to prove that it has been fulfilled. To do this, it can rely on a qualified trusted service provider, as is the case with Mailcomms Group, which, moreover, thanks to its experience in sending personalized omnichannel communications, can adapt to the data collection needs of any customer and company. And, always, providing the data controller with the necessary evidence in case of complaint, since it enjoys the presumption iuris tantum.

Similarly, MailComms Group offers a tool capable of obtaining, processing and managing, from start to finish, these consents with guaranteed regulatory compliance. Would you like to know more about it?

[1] Genetic data: data relating to the inherited or acquired genetic characteristics of a natural person that provide unique information about that person’s physiology or health, obtained in particular from the analysis of a biological sample from that person. For example, through a chromosomal analysis, or any analysis that allows obtaining unique information on the physiology and health of a person.

[2] Biometric data: personal data obtained from specific technical processing, relating to the physical, physiological or behavioral characteristics of a natural person that enable or confirm the unique identification of that person, such as facial images or dactyloscopic data.

[3] Data Controller: Any person who could decide on the purposes and means of data processing.

Frequently Asked Questions

What is personal data under the GDPR?

According to Article 4.1 of the General Data Protection Regulation (GDPR), personal data is any information relating to an identified or identifiable natural person. A person is considered identifiable if they can be identified directly or indirectly, in particular by means of a name, identification number, location data, online identifier, or factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity. A person’s image, IP address, or vehicle license plate number constitutes personal data if it allows the individual to be identified.

What is not considered personal information?

Personal data does not include information that does not allow a natural person to be identified, either directly or indirectly. For example: a company’s business registration number (CIF/NIF), a generic email address such as info@empresa.com, or completely anonymized statistical data. The key is that the information must not, either on its own or when combined with other data, make it possible to determine the identity of the person to whom it refers.

What is specially protected data or sensitive data?

Special categories of personal data (or sensitive data) are a special category defined in Article 9 of the GDPR. These include data revealing ethnic or racial origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data intended to uniquely identify a person, health data, and data concerning sexual life or sexual orientation. The processing of such data is prohibited except in cases specifically provided for by the GDPR.

What types of personal data does the GDPR recognize?

The GDPR recognizes various categories of personal data: identifying data (name, national ID number, address, phone number, IP address), personal characteristics (physical characteristics, preferences, date of birth), family and social circumstances, employment information, academic and professional data, attendance records, and financial data. Additionally, Article 9 establishes the specially protected categories (sensitive data) that require a stronger legal basis for their processing.

How must the data controller demonstrate that it has collected the data correctly?

The data controller is required to be able to demonstrate, at any time, that data collection was carried out in accordance with the GDPR: that the data subject was informed, that consent was validly obtained (if that is the legal basis used), and that the method and timing of collection are documented. To this end, the data controller may rely on a Qualified Trust Service Provider (QTSP) to certify the communications, providing evidence admissible before the AEPD or in any complaint.

Soraya de Caso

Manager Consultoría Legal de Negocio.

Licenciada en Derecho por la Universidad de Valladolid. Esta especializada en protección de datos y seguridad de la información tanto en el sector publico como en el sector privado como Compliance Officer & Data Protection Officer. Posee la certificación Lead Auditor ISO/IEC 27001 y numerosas formaciones en materia de seguridad y privacidad.-

Leave us your details in this form and we will contact you to find a solution adapted to your business.

    Name*

    Last Name*

    Company email*

    Phone*