Basics 3 minutes read

What "personal data" actually means

No name, no address, no account – and personal data all the same. The term reaches far further than the wording suggests, and that reach decides whether the GDPR applies at all.

Personal data is any information relating to an identified or identifiable person. The second word carries all the weight. Identifiable means it would be possible to make the link with reasonable effort – not that the link is actually made.

The detour through third parties counts

The decisive point was settled by the highest court in 2016: an IP address is personal data even where the website operator alone cannot attribute it to anyone. It is enough that legal means exist to reach the name via the access provider.

That largely removes the popular defence "but we have no idea who this is". What counts are all means that could reasonably be used – by anyone, not only by the party doing the storing.

What an ordinary website learns without any login

  • Network characteristics: IP address, approximate location
  • Device characteristics: browser, operating system, screen
  • Stored identifiers: cookies, local storage
  • Behaviour: pages opened, time spent, referring link
The shares stand for how often each kind of characteristic arises on an ordinary page view – not for how telling it is. Each of the four groups can be personal data in its own right.

Pseudonymous is not anonymous

The two terms are often treated as the same, and the difference matters: pseudonymous data falls fully under the GDPR, anonymous data not at all.

The difference lies in reversibility

Pseudonymised
Anonymised
The name is replaced by an identifier
The link is removed beyond recovery
Somewhere a key exists to trace it back
No key, not even at a third party
The GDPR applies in full, data subject rights included
The GDPR no longer applies
A good security measure – but not an exit from the duties
Harder to achieve than it sounds

Data under special protection

A small group of data enjoys stricter protection: health, ethnic origin, political opinion, religion, trade union membership, sex life, biometric and genetic data. For these there is a general prohibition on processing with narrower exceptions.

  • The protection also applies to indirect indications: visiting a page about a particular illness is health data.
  • For advertising based on such data, practically only explicit consent comes into question – legitimate interests do not carry here.
  • Anyone running a website on a sensitive topic should therefore be especially cautious with embedded third-party services.

A record without a name is not anonymous data. Most of the time it is data under a different name.

Published 1 August 2026 · last changed 2 September 2026

This article explains general principles and does not replace legal advice on an individual case.

Back to the overview