What is Personal Data?
Definition
Personal data is any information relating to an identified or identifiable natural person. Besides direct identifiers such as a name or national ID number, it includes email addresses, phone numbers, IP addresses, cookie IDs, location data and photos whenever they can single out a person, alone or combined with other information. Data about health, biometrics or religious beliefs forms special categories that are subject to stricter rules.
Also known as: personal information, PII, personally identifiable information, special category data, sensitive personal data, data privacy

Identifiable is enough
The key word in the definition is “identifiable”. A piece of information does not have to name anyone; if it can single out a person when combined with other information by reasonable means, it is personal data. That is why far more personal data flows through a typical website than its owners assume:
- IP addresses and user-agent strings in server logs
- cookie and device identifiers assigned by analytics and ad tools
- work email addresses (
[email protected]points straight at a person) - location, licence plates, voice recordings, CCTV footage
- behavioural records of what a signed-in user did on the site
Information about a legal entity, such as a company's tax number or revenue, is not personal data. Information about the company's sole owner or its employees still is.
Special category data
Some data gets extra protection because exposure can lead to discrimination or serious harm. The GDPR lists racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify someone, health data, and data about a person's sex life or sexual orientation; criminal convictions are handled in a separate article. Turkey's KVKK has a similar but not identical list that also covers appearance and dress, membership of associations and foundations, and criminal convictions.
In practice this means a clinic booking form, face-recognition login, fingerprint-based staff attendance or a health app needs its legal basis and security measures settled at design time. Such data usually has to rest on explicit consent or one of a few narrow exceptions defined by law.
Anonymous, pseudonymous or personal?
| Situation | Example | Personal data? |
|---|---|---|
| Direct identifier | Name, email, phone | Yes |
| Pseudonymous | Customer record keyed by a hash of the email | Yes, even if the key or lookup table is stored elsewhere |
| Anonymous | “1,240 orders in March, 38% on mobile” | No, provided nobody can be traced back |
A common mistake is believing that running an email address through a hash function anonymises it. The same address always yields the same hash, so anyone holding a list of emails can match them. That is pseudonymisation: it lowers risk but the result is still personal data.
Data privacy in day-to-day engineering
- Collect less: a newsletter needs an email address, not a birth date and a phone number.
- Restrict access: each admin role should see only what its job requires, following the principle of least privilege.
- Protect it: encrypt in transit and at rest, and treat backups with the same care as the live database.
- Watch your logs: error reports should not capture form contents, passwords or card numbers.
- Set retention periods: once the purpose is fulfilled, delete or anonymise the data.
This entry is general information; whether a specific dataset counts as personal data in your context is a question for a privacy professional.

