What Counts as Personal Data Under GDPR?
GDPR's definition of personal data is broader than most businesses assume, it covers far more than names and emails. Here's what actually counts, including the identifiers most sites overlook.
A lot of GDPR confusion traces back to underestimating how broadly the law defines “personal data.” Businesses often assume it means names, email addresses, and payment details, the obviously personal stuff, and conclude their site doesn’t handle much personal data at all. GDPR’s actual definition is considerably wider, and it’s worth understanding precisely because so many of the law’s other obligations (lawful basis, consent, breach notification) only kick in when personal data is involved.
The legal definition
Article 4(1) of GDPR defines personal data as: “any information relating to an identified or identifiable natural person.” The key phrase is identifiable, not just directly identifying. If a piece of data can be used, on its own or combined with other data you hold or could reasonably obtain, to single out a specific individual, it’s personal data, even if it doesn’t look like it in isolation.
What clearly counts
- Name, email address, phone number, home address
- Government ID numbers, passport numbers
- Photos and video where a person is identifiable
- Financial information (account numbers, transaction history)
- Health, biometric, and genetic data (also subject to extra “special category” protections)
What people underestimate
- IP addresses. The European courts and data protection authorities have repeatedly confirmed IP addresses are personal data, since they can identify a device and, through an ISP, potentially a person. This is a major reason server logs and analytics tools fall under GDPR.
- Cookie identifiers and device IDs. Any persistent identifier used to recognize a browser or device across visits, exactly what most analytics and advertising cookies do, counts, even without a name attached.
- Online identifiers generally. Article 4(1) explicitly lists “online identifier” alongside name and ID number as an example of what makes someone identifiable.
- Location data. Even approximate location derived from IP address can be personal data; precise GPS-level location gets extra protection as sensitive data in several related US laws, covered in our GA4-focused sensitive data guide.
- Employee and B2B contact data, work email addresses and job titles are personal data too, a point covered separately in our B2B data guide.
Pseudonymous data is still personal data
A common misconception: replacing a name with a random ID (pseudonymization) takes data out of GDPR’s scope. It doesn’t. Pseudonymized data is still personal data under GDPR as long as the original identity can be re-linked, by you or anyone else, using a key or additional information. Pseudonymization is a security measure GDPR encourages, not an exemption from the law.
What actually falls outside the definition: anonymous data
Data only escapes GDPR entirely when it’s truly anonymized, meaning re-identification is not reasonably possible by any means likely to be used, not just difficult in theory. Aggregated statistics with no path back to an individual (e.g., “12% of visitors are from Germany” with no underlying per-visitor record retained) are the clearest example. True anonymization is a much higher bar than most businesses assume, and if you retain the underlying raw data alongside an aggregate, the raw data is still personal data even if the aggregate isn’t.
CookieYes
Because cookie identifiers and IP addresses count as personal data on their own, most of what a standard analytics or advertising setup collects is in scope well before you ever add a name or email field. CookieYes is built around that reality, gating exactly this category of identifier-level data behind proper consent.
Why this definition matters practically
Almost every obligation elsewhere in GDPR, lawful basis requirements, consent, breach notification, data subject rights, is triggered by processing personal data. If you’ve been assuming your site “doesn’t really handle personal data” because you don’t collect names, it’s worth re-checking against this broader definition, since your analytics and cookie setup very likely does.
This guide is educational and not legal advice. Whether specific data your business handles counts as personal data under GDPR depends on the facts of your setup; consult a privacy attorney for your specific situation.