Privacy
Personal data
Also called personal information.
Personal data is any information relating to an identified or identifiable natural person. Under GDPR, names, emails, location data, and online identifiers all count.
How it is measured
Ask whether you, or anyone with reasonable means, could single out a person from the data. Cookie IDs, IP addresses, and device IDs can qualify even without a name attached.
Test with a field-level table. Mark each column as directly identifying, indirectly identifying, or neither, and note which other columns it can be joined with.
Worked example
A booking form stores name, email, phone, a note, and an IP. A separate log table stores a timestamp, a page, and the same IP. Joined on the IP, the log becomes personal data too.
The team removes the IP from the log table. Now the two tables cannot be linked, and only the booking table carries obligations.
How it differs
Personal data is the GDPR concept. Personally identifiable information is a US-style label that depends on the statute. Personal data includes online identifiers; PII may or may not, depending on the law.
Common errors
Assuming hashed data is anonymous. Ignoring IPs and device IDs. Thinking business emails are exempt. Forgetting free-text fields. Believing aggregate counts are always safe at small sizes.
In practice
Build a field-level list of what you store. Mark identifiers and joins. Remove what you do not need.