Personal Data (Article 4(1) GDPR)
Personal data as the threshold for the applicability of data protection law: relating to an identified or identifiable natural person, direct and indirect identifiability, data relating to objects and synthetic data, distinction from anonymous data.
Personal data means any information relating to an identified or identifiable natural person (Article 4(1) GDPR). The concept determines whether data protection law applies at all: only those who process personal data are subject to the GDPR. Where there is no link to a person, its obligations do not apply. This concept is therefore the central threshold for the applicability of the entire body of data protection law.
Key takeaways
- Personal data means any information about an identified or identifiable natural person (Article 4(1) GDPR); the concept is the entry threshold of data protection law.
- A person is identifiable where they can be determined directly (e.g., by name) or indirectly (e.g., by IP address, license plate); the benchmark is all the means reasonably likely to be used (Recital 26 GDPR).
- Anonymous data is not personal data; pseudonymized data remains personal data for the controller who holds the additional information.
- Within personal data, special categories (Article 9 GDPR) and criminal-offense data (Article 10 GDPR) are subject to significantly stricter requirements.
- The link to a person is relative: the same information may be anonymous for a recipient with no means of attribution, while it remains personal data for the controller who has additional knowledge.
1 Overview
1.1 Core of the definition
An item of personal data requires three elements: there must be a natural person, that person must be at least identifiable, and the information must relate to them. This covers not only identification features such as name, address, or date of birth, but any information about the person. This includes external characteristics (sex, eye color, height, weight), internal states (opinions, motives, wishes, convictions, value judgments), and factual information about the person's circumstances (financial and property situation, communication and contractual relationships, other relationships with third parties and with the surrounding world). Information that arises only from processing, such as an assessment of creditworthiness, is also personal data.
1.2 Classification and distinction
The definition in Article 4(1) GDPR corresponds in essence to the definition in Article 3(1) of Regulation (EU) 2018/1725 for the Union institutions and is to be interpreted in the same way. Within personal data, the GDPR distinguishes special categories of personal data (Article 9 GDPR) and data relating to criminal convictions and offenses (Article 10 GDPR), whose processing it makes subject to stricter requirements (see the sensitive data categories). Tax data is also personal data. Under Union law, the Regulation on the free flow of non-personal data (Regulation (EU) 2018/1807) recognizes only the distinction between personal and non-personal data; there is no third category.
The link to a person is the entry threshold of data protection law. Where it is established, all obligations of the GDPR apply. Where it is absent, because the information cannot be attributed to any identifiable natural person, the GDPR does not apply. The analysis therefore always begins with the question of whether personal data exists at all.
2 Natural person
2.1 Restriction to natural persons
Only natural persons are protected. The background is the right to informational self-determination, which the German Federal Constitutional Court (BVerfG) developed in the Census judgment (BVerfG, judgment of 15 December 1983, 1 BvR 209/83 and others, Census). Legal persons under private law such as a stock corporation, GmbH, GmbH & Co. KG, or cooperative are not expressly covered by Article 4(1) GDPR.
2.2 Distinction from legal persons
Under German case law, legal persons under private law may invoke the right to informational self-determination insofar as their members are entitled to protection against the unlimited collection of individualized data. Under data protection law, however, the following applies: where public registers publish the name, signature, and contact details of a natural person who represents a legal person, this is personal data of that natural person. The fact that disclosure serves solely the purpose of identification does not change this. This view is based on Article 8 of the Charter of Fundamental Rights (protection of personal data), which is closely connected with Article 7 of the Charter (respect for private life).
Data of legal persons is thus covered only indirectly, namely insofar as their name determines a natural person. The decisive factor is always the natural person behind it. Member States remain free to extend protection beyond the GDPR; Italy, Austria, and Luxembourg have in part extended protection to data of legal persons. In Germany, trade and business secrets are covered by social confidentiality (§ 35 of the German Social Code Book I (SGB I) in conjunction with § 67 of the German Social Code Book X (SGB X)).
3 Living and deceased persons, holders of public functions
3.1 Living persons
Every living person is a natural person, regardless of age and nationality. The treatment of the nasciturus, that is, data collected before birth such as ultrasound images or amniotic fluid analyses, is disputed. An anticipatory effect of the right to informational self-determination is conceivable. In the case of a frozen embryo, too, protectable genetic and medical information is at stake.
3.2 Deceased persons
Data of deceased persons is not personal data within the meaning of the GDPR (Recital 27 GDPR). The same information may, however, at the same time be data of a living person, for example where the data of a deceased person allows inferences to be drawn about hereditary diseases of a descendant; to that extent it is protected. The general right of personality (Article 2(1) of the German Basic Law (GG)) lapses upon death, whereas its commercial components continue to exist. Member States may provide their own rules for the data of deceased persons (Recital 27 GDPR). Under German law, the data of deceased persons remains covered by social confidentiality (§ 35(1) SGB I in conjunction with § 67 SGB X), and tax law contains its own rule (§ 2a(5)(1) of the German Fiscal Code (AO)). Medical confidentiality as well as statistical and tax secrecy likewise continue to have effect beyond death.
3.3 Persons with a special status
Holders of public functions act in their function not as bearers of fundamental rights. Behind the function, however, there is always a natural person entitled to protection of their personality, so that their data is personal data and has a dual character. Processing is in part permissible to a greater extent than for purely private data. Examples are the name badge of police officers or the video recording of police officers on duty, which does not exclude the application of the GDPR. The evaluation of teaching courses likewise concerns personal, often subjective, data about the teaching staff. In the case of public figures of contemporary history, the interests warranting protection are lower (cf. § 23(1)(1) of the German Act on the Copyright in Works of Art and Photography (KUG)). The media privilege applies to journalistic processing (§ 41 of the German Federal Data Protection Act (BDSG), which refers to the press laws of the Länder).
4 Identifiability
4.1 Benchmark
A person is identifiable where they can be determined directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity (Article 4(1) GDPR). Whether someone is identifiable is assessed by reference to all the means reasonably likely to be used by the controller or another person; account is to be taken of objective factors such as costs, the amount of time required, and available technology (Recital 26 GDPR). The information needed for identification need not be held by a single entity. Both objective and subjective information is covered, provided that it relates to the person.
There is no indirect identifiability where identification is prohibited by law or is not practicable, for example because it would require a disproportionate effort and the risk of identification is therefore in fact insignificant. The principles of data protection do not apply to anonymous information (Recital 26 GDPR). The GDPR does not expressly regulate anonymization; it is sufficient that re-identification is not practicable. This is an ongoing assessment task: as long as data can be re-attributed, it remains personal data (further on pseudonymization).
The following decision tree illustrates when an item of information is to be classified as personal data and when it is considered anonymous.
4.2 Direct vs. indirect identifiability
The following table uses typical examples to show when direct and when indirect identifiability exists.
| Feature | Direct identifiability | Indirect identifiability |
|---|---|---|
| Identifying feature | Directly personal, no intermediate step needed | Requires combination with further information or data from third parties |
| Typical examples | Name, social security number, tax identification number | IP address, license plate, cookie identifier, job title |
| Additional information | No further information required | Access to registers, databases, or additional knowledge needed |
| Case law example | Recipient of agricultural subsidies with name and place of residence | Dynamic IP address held by the service provider (CJEU C-582/14, Breyer) |
4.3 Direct identifiability
A person is directly determinable, for example, by their name. The social security number and the tax identification number, which functions as a de facto personal identification number, also allow direct determination. Where names are identical, determination may be made by means of additional information such as date of birth or address. The publication of the recipients of agricultural subsidies with name, place of residence, postal code, and amount is a form of direct identifiability (German Federal Administrative Court (BVerwG); following the case law of the CJEU).
4.4 Indirect identifiability
A person is indirectly determinable by information that enables recognition without stating the name, for example by the license plate, the telephone number, the passport or ID card number, or by the activity carried out. A name is not required for identification.
IP addresses, including dynamic ones, relate to a determinable person. A dynamic IP address stored by a provider of online media services is personal data for that provider where it has the legal means enabling it to have the data subject determined with the help of additional information held by the access provider (CJEU, judgment of 19 October 2016, C-582/14, Breyer). Cookie identifiers and radio frequency identifiers are likewise personal data (Recital 30 GDPR). The so-called TC string, which stores users' consent preferences in online advertising, is also personal data, because it can be attributed to an identifier such as the IP address (CJEU, judgment of 7 March 2024, C-604/22, IAB Europe). A private key of a blockchain is personal data insofar as it can be attributed to a person.
The term "any information" is to be understood broadly; the information must be linked to a specific person by reason of its content, its purpose, or its effects. On this basis, graffiti tags, GPS data for locating company vehicles, license plates (attributable to the keeper or driver), and the data stored in the vehicle (vehicle identification number, position, time, speed, and braking data) can also relate to a person. Image and audio recordings that record a person are likewise covered: the camera image of a person is personal data where they can be identified; the same applies to a recorded voice and to GPS data associated with photographs.
The written answers given by a candidate in a professional examination and the examiner's comments on them are personal data of the candidate (CJEU, judgment of 20 December 2017, C-434/16, Nowak). A memory-based record of an oral examination, insofar as it contains statements about the examiner, contains the examiner's personal data. Information attributed to a person is also personal data, even if it is incorrect, for example attribution to a marketing group. A form of address that corresponds to a person's gender identity may be personal data (CJEU, judgment of 9 January 2025, C-394/23, Mousse). Finally, a letter or reply from a data subject and a controller's internal communication about them are personal data that may be subject to the right of access (German Federal Court of Justice (BGH)).
5 Data relating to objects
Data relating to objects initially relates to an object and not to a person, for example the top speed of a vehicle. It becomes personal data where it also concerns legal, economic, or social positions of a person or describes their individual circumstances. Thus an evidence-securing expert report on an object is personal data, because it concerns the position of the owner. Geodata and land data such as parcel, house number, or standard land values can also relate to a person as soon as the level of detail is so high that a person's address can be determined; at a coarse scale, there is no link to a person. Building permit files contain personal data with the information on the building owner.
The transition from a link to an object to a link to a person is strikingly illustrated by the vehicle identification number: taken on its own, it is data relating to an object. Through the registration certificate, it can be linked to the keeper's data and then becomes personal data, provided that access to that data opens up a means of identification (CJEU, judgment of 9 November 2023, C-319/22, Gesamtverband Autoteile-Handel v Scania). The same logic underlies geoscoring, in which inferences about a person's economic situation are drawn from location information.
6 Synthetic data
Synthetic data is artificially generated, realistic datasets that, in the context of artificial intelligence, serve to generate and validate models and as a means of anonymization. Its classification follows the general benchmark of Recital 26 GDPR: if it cannot be traced back to a real person, it is non-personal. If, on the other hand, it is possible to compute back to the underlying real persons, it remains attributable to a person and thus personal data.
7 Data subject
The data subject is the natural person whose data is at issue (Article 4(1) GDPR). They are to be protected against impairments of their right of personality through the handling of their data. They are to be distinguished from the controller and from the third party: a person who decides on the processing or who stands outside the processing is not a data subject. The data subject gives, where applicable, consent and can assert their data subject rights under Articles 15 to 18 GDPR. Their data may at the same time include data of other data subjects. With respect to the debtor's tax data, the insolvency administrator is not the data subject (BVerwG).
8 Distinction from anonymous data
The link to a person is relative and is to be assessed from the perspective of the party processing the data. The following table contrasts the three categories.
| Category | Link to a person | Example | GDPR applicable? |
|---|---|---|---|
| Personal | Clearly present; person identified or identifiable | Name, email address, IP address held by the controller with additional knowledge | Yes, fully |
| Pseudonymized | Personal for the controller with additional information; anonymous for the recipient without the key | Hashed email address, number instead of name in study data | Yes, as long as the controller can attribute it |
| Anonymous | Re-identification practically excluded | Aggregated statistics without any link to individual cases, irreversibly noise-added data | No |
Data remains personal as long as the controller can re-identify it; this applies in particular to pseudonymized data where the controller has the additional information. Where pseudonymized data is passed on to a third party who cannot attribute it to anyone, it is anonymous for that third party, so that the GDPR does not apply in that respect; the decisive factor is whether re-identification by the recipient is excluded (CJEU, judgment of 4 September 2025, C-413/23 P, EDPS v SRB). The assessment is made on a case-by-case basis: if the recipient has a legal or other possibility of attribution, the link to a person persists. Conversely, non-personal data can become personal data where the controller passes it to a person who has means with which the data subjects are likely to be identified.
Pseudonymized data is not a free pass. For the controller with access to the additional information, it remains personal data, and the obligations of the GDPR apply in full. It becomes anonymous only in the hands of a party that in fact cannot carry out re-identification. The classification must therefore be assessed separately for each entity involved.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Concepts and Definitions
The central legal definitions of Article 4 GDPR in detail: personal data, processing, pseudonymization, controller, processor, and further defined terms, with interpretation and delimitation.
Processing (Article 4(2) GDPR)
The GDPR concept of processing: any handling of personal data, automated or manual, from collection through storage and disclosure to erasure.