Privacy

Personal data

Also called personal information.

Personal data is any information relating to an identified or identifiable natural person. Under GDPR, names, emails, location data, and online identifiers all count.

How it is measured

Ask whether you, or anyone with reasonable means, could single out a person from the data. Cookie IDs, IP addresses, and device IDs can qualify even without a name attached.

Test with a field-level table. Mark each column as directly identifying, indirectly identifying, or neither, and note which other columns it can be joined with.

Worked example

A booking form stores name, email, phone, a note, and an IP. A separate log table stores a timestamp, a page, and the same IP. Joined on the IP, the log becomes personal data too.

The team removes the IP from the log table. Now the two tables cannot be linked, and only the booking table carries obligations.

How it differs

Personal data is the GDPR concept. Personally identifiable information is a US-style label that depends on the statute. Personal data includes online identifiers; PII may or may not, depending on the law.

Common errors

Assuming hashed data is anonymous. Ignoring IPs and device IDs. Thinking business emails are exempt. Forgetting free-text fields. Believing aggregate counts are always safe at small sizes.

In practice

Build a field-level list of what you store. Mark identifiers and joins. Remove what you do not need.

See also

Personally identifiable information, GDPR, IP address

Sources

Count this on a real site.

Watch my website