Personal data (GDPR)
In EU data protection, personal data is any information relating to an identified or identifiable person, as defined in article 4 of the GDPR. It is the canonical concept in Spain and the EU, and it is broader than the US term PII: it covers online identifiers, IP addresses, cookies and pseudonymised data that can still be linked back.
What it is
Personal data is any information that identifies a person, describes them or can be linked back to them. It covers what identifies directly, such as a name, an address or an identification number, and also what identifies in combination, such as a date of birth alongside a place of residence.
Sensitivity depends on the context: the same piece of data can be harmless when it does not reveal whose it is and critical when it does. And protecting it is not optional, because the General Data Protection Regulation (GDPR) sets out how personal data is collected, stored and processed, with concrete obligations for whoever handles it.
Three fronts of work come out of that. Consent and transparency about what the data is going to be used for. The security of its collection and storage, with encryption and access control. And the lifecycle: how long it is kept and how it is deleted once it is no longer needed, because data that is not kept cannot be lost.
How it works
Article 4 of the GDPR defines personal data as any information relating to an identified or identifiable natural person, and the reach of “identifiable” is what makes the concept wide. It includes the obvious fields (name, national identifier, contact details) but also online identifiers, IP addresses, cookie and device identifiers, and data that has been pseudonymised, because pseudonymised data can still be re-linked to a person and so remains personal data. A separate, stricter category, the special categories in article 9 (health, biometric, genetic, political and similar data), carries heavier obligations. In Spain the GDPR is complemented by the national law, the LOPDGDD, and supervised by the AEPD. This is the concept that governs processing, not the market shorthand.
What goes wrong
The recurring error is scoping data protection around the narrower US term PII, which quietly drops exactly the data that carries obligations: the online identifiers, device data and pseudonymised records that are still personal data under the regulation. A programme built on the narrow definition leaves that processing uncovered, and a data protection officer catches it immediately. From a security standpoint the consequence is concrete: the assessment protects the fields someone thought of as personal and ignores the logs, identifiers and analytics stores where the regulated data actually accumulates, which is often where a breach would draw them from.
Where this shows up in an audit
We scope data-protection testing against the legal definition, not the shorthand: which processing involves personal data as article 4 defines it, including online identifiers and pseudonymised records, and whether any falls into the article 9 special categories that raise the bar. Data classification is the practical instrument, and where high-risk processing appears we point at a data protection impact assessment. Findings are tied to the correct legal concept so the scope reflects what actually carries obligations. This is part of how we scope testing to what carries obligations.