Filing System (Article 4(6) GDPR)
Article 4(6) GDPR defines the filing system as any structured set of personal data which are accessible according to specific criteria. In the case of manual processing, this concept is the decisive threshold for the material scope of the GDPR.
Article 4(6) GDPR defines the filing system as any structured set of personal data which are accessible according to specific criteria, whether centralized, decentralized or dispersed on a functional or geographical basis. In practice, the concept is relevant above all in the case of manual, non-automated processing: only if the data are stored or intended to be stored in a filing system does such processing fall within the scope of the GDPR at all (Article 2(1) GDPR).
Key takeaways
- A filing system exists where personal data are structured and accessible according to specific criteria, regardless of whether they exist in digital form or on paper.
- In the case of fully automated processing, the concept is irrelevant, because the GDPR then applies regardless of any filing system.
- The decisive factor for manual sets is the uniform structure: a consistent structure that enables data to be found quickly is sufficient.
- A minimum number of data subjects or files is not required; even very small sets can constitute a filing system.
- Unordered files without a retrieval criterion do not fall within the concept and therefore not within the scope of the GDPR (Recital 15 GDPR).
1. Overview
1.1 Significance of the concept
The filing system is one of the central connecting factors for the material scope of the GDPR. In the case of fully automated processing, the Regulation always applies, without the existence of a filing system being relevant. In the case of non-automated, that is, manual processing, by contrast, the filing system is the decisive hurdle: if there is no structured set within the meaning of Article 4(6) GDPR, the processing does not fall within data protection law.
In practical terms, this means: unstructured handwritten notes, unsorted stacks of paper, or filing collections created according to no comprehensible criterion are excluded from the scope of protection. However, as soon as a systematic structure is discernible that permits specific data to be found, the threshold is crossed.
1.2 Legislative history and predecessor law
In substance, the concept ties in with Article 2(c) of the former Data Protection Directive 95/46/EC, which still referred to a "file". The GDPR slightly adjusted the terminology but essentially retained the substantive content.
2. Requirements of the filing system
2.1 Structured set
The core characteristic is structure: the data must be ordered according to criteria that enable targeted access to individual records or specific categories of data. The criterion for ordering may relate to a person (name, date of birth, personnel number, address) or to a subject matter, provided that it ultimately permits the retrieval of data relating to specific individuals (e.g. file reference, vehicle registration number, job title, region).
Purely subject-related characteristics that do not establish any link to a natural person, by contrast, are not sufficient.
2.2 Uniform structure as an indicator
In the case of sets of files, the uniform design is the decisive indicator. If files are structured uniformly according to their external labeling, e.g. following the pattern of surname, first name, personnel number, a filing system will as a rule already exist. The decisive factor is that the uniform structure facilitates the retrieval and finding of data.
This also applies to files organized by subject area, person, or customer, as well as to uniformly structured forms and case files.
Whether the data exist on paper, as a card index, or in digital form is irrelevant to the concept of the filing system. The legislature deliberately opted for a technology-neutral formulation (Recital 15 GDPR).
2.3 No minimum number required
The existence of a filing system does not require any minimum number of data subjects, files, or records. Even two case files stored in a structured manner may suffice. The decisive factor is solely the manner of organization, not the size of the set.
3. Distinction: filing system or not?
The following table summarizes typical examples:
| Set | Filing system? | Reasoning |
|---|---|---|
| Personnel files with a uniform cover sheet (name, personnel number) | Yes | Uniform structure, targeted retrieval possible |
| Patient card index / medical record cards | Yes | Classic card index, always structured |
| Examination records in paper form, ordered by matriculation number | Yes | Criterion enables targeted access |
| Court files ordered by case reference number | Yes | Retrieval feature present |
| Handwritten notes from door-to-door visits, sortable by name | Yes | Capability of being structured suffices (CJEU, judgment of 10 July 2018, C-25/17, Jehovah's Witnesses) |
| Loose notes placed unsorted into a box | No | No retrieval criterion discernible |
| Unstructured stack of paper without discernible order | No | Lack of structure, Recital 15 GDPR |
| Purely subject-related file with no personal reference in the ordering feature | No | Criterion establishes no link to a person |
4. Scope: manual and handwritten sets included
The concept expressly covers both forms: analog sets on paper and digital sets. Card indexes, e.g. for patients or customers, always constitute a filing system.
Handwritten records may also fall within the scope. What matters is whether the content can be easily accessed and the individual data can be found without disproportionate effort. The CJEU has clarified in this respect that neither a specific register system nor a formalized filing arrangement is required; it is sufficient if the data are retrievable on the basis of specific criteria (CJEU, judgment of 10 July 2018, C-25/17, Jehovah's Witnesses).
5. Relationship to manual processing and the scope of the GDPR
The main practical application of the concept lies in the distinction: the GDPR applies to manual processing operations only if the data are stored or intended to be stored in a filing system (Article 2(1) GDPR). If this requirement is not met, the activity lies, in legal terms, outside the regulatory scope of data protection law.
The filing system thus constitutes both a protection gap and a systemic boundary: the legislature deliberately decided not to cover purely unstructured manual activities, because the effort associated with the GDPR would be disproportionate for such situations. However, anyone who collects personal data even merely with the aim of subsequently making them accessible in an ordered set already falls within the scope.
Processing
Article 4(2) GDPR: In the case of manual processing, the filing system is a prerequisite for the applicability of the GDPR.
Personal data
Article 4(1) GDPR: The filing system must contain personal data.
CJEU, Jehovah's Witnesses (C-25/17)
Handwritten records from door-to-door visits as a filing system; broad concept of the filing system.
Article 4(6) GDPR
Legal definition of the filing system in the wording of the Regulation.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Pseudonymization (Article 4(5) GDPR)
Pseudonymization as a technical and organizational measure: separation of the additional information, distinction from anonymization, the persisting link to a person, and special forms such as encryption and de-identification.
Controller (Article 4(7) GDPR)
Whoever determines the purposes and means of processing is a controller and the central party bound by the obligations of the GDPR: definition, distinction from processor and joint controllership, case groups.