Personal data according to GDPR: definition, categories and operational consequences
Personal data is the trigger for every GDPR obligation. Anyone who clearly defines the term from Art. 4 No. 1 GDPR identifies risks earlier, documents processing in a verifiable manner and accelerates audits and reporting paths in accordance with Art. 33 GDPR.
According to Art. 4 No. 1 GDPR, personal data is all information that relates to an identified or identifiable natural person. This legal definition is the central lever on which every further obligation of the regulation depends. Only when a date is classified as personal do the principles according to Art. 5 GDPR, the legality conditions according to Art. 6 GDPR, the rights of those affected according to Art. 12 to 22 GDPR and the reporting obligations according to Art. 33 and Art. 34 GDPR apply. Practice shows that the classification is often incorrect. IP addresses, cookie IDs, personnel numbers or location data are considered purely technical, although the ECJ has classified them as personal in several decisions. Anyone who draws too narrow a personal reference misses the level of protection and risks fines according to Art. 83 GDPR of up to 20 million euros or 4 percent of global group sales.
This article provides a verifiable definition, classifies special categories according to Art. 9 GDPR and shows what operational consequences arise for those responsible, processors and the data protection officer. You will also learn how CIVAC, as a compliance platform and officer-as-a-service, brings together the processing directory, deletion concept and reporting path in an audit-proof workspace. Licence the workspace for your internal representatives or have our representatives order it. Both models lead to the same result. The appointment certificate, signed, filed, verifiable.
Key Takeaways
- According to Art. 4 No. 1 GDPR, personal data is all information that makes a natural person directly or indirectly identifiable, including online identifiers, location and device data.
- Special categories according to Art. 9 GDPR are subject to a fundamental ban on processing with narrow exceptions and require documented technical and organisational protective measures.
- All processing must be recorded in the register in accordance with Art. 30 GDPR, provided with a legal basis and closed using a deletion concept so that requests for information and deletion are answered within the monthly deadline.
What Art. 4 No. 1 GDPR defines as personal data
Art. 4 No. 1 GDPR defines personal data as all information that relates to an identified or identifiable natural person. The standard deliberately uses the wording all information because the European legislator wanted to avoid any formal limitation to certain data types. Objective information such as the date of birth is recorded as well as subjective assessments, such as a personnel assessment or an internal credit rating. Structured database entries as well as unstructured free texts in emails, file notes or audio recordings from a service centre are recorded.
A person can be identified as soon as they can be recognised directly or indirectly via an identifier such as name, identification number, location data or online identifiers. Recital 26 GDPR specifies that all means that the controller or a third party is likely to use based on general discretion must be taken into account. The personal reference is therefore a relative concept. An isolated customer number is personal in address trading, but pseudonymous in the internal system of a processor with its own key. The prospect of a link in the future can also justify the personal reference, provided it is realistic and not purely theoretical.
In operational practice, this means that those responsible check each data flow based on the linking risk. Pseudonymous data sets remain personal as long as the key is held by the person responsible or a processor. Only after real anonymization, i.e. the irretrievable decoupling of identifiers, does the date fall out of the scope of the GDPR. The CIVAC workspace carries out a documented personal reference assessment for each processing, so that the external data protection officer can prove at any time why a data record was classified as personal, pseudonymous or anonymous. This evaluation is the basis for all subsequent information and every deletion process.
Special categories according to Art. 9 GDPR and their protection logic
Art. 9 Paragraph 1 GDPR subjects certain types of data to a fundamental ban on processing. This includes information about racial or ethnic origin, political opinions, religious or ideological beliefs, trade union membership, genetic and biometric data for unique identification, health data and data on sex life or sexual orientation. Any processing is prohibited unless one of the ten exceptions under Article 9 Para. 2 GDPR applies. The exceptions range from express consent to employment law obligations to medical care, public health interests and defence of legal claims.
The practical consequence is a significantly higher burden of duties. Those responsible must adapt technical and organisational measures in accordance with Art. 32 GDPR to the increased protection requirements, carry out a data protection impact assessment in accordance with Art. 35 GDPR and assign authorizations restrictively. In clinical studies, the data protection-compliant pseudonymization regime with separate key storage in a separate organisational unit also applies. In the human resources area, there are also co-determination rights under the Works Constitution Act, for example when processing health data in company integration management according to Section 167 SGB IX or when evaluating health statistics.
Biometric data also deserve special attention. A photo only becomes a biometric data within the meaning of Article 9 GDPR when it is linked to a technical process for clear identification, such as facial recognition or biometric access control. Pure employee portraits on the intranet, on the other hand, fall under Art. 6 GDPR. The CIVAC workspace classifies processing according to protection classes and stores the associated audit templates for each class from the inventory of 490 prefabricated templates, so that the justification for technical and organisational measures can be checked at any time. The auditor calls, the evidence is ready.
Online identifiers, IP addresses and cookie IDs as personal data
Recital 30 GDPR specifically mentions online identifiers, IP addresses, cookie IDs and device fingerprints as examples of identifying characteristics. The ECJ made it clear in the Breyer decision (Az. C-582/14) that dynamic IP addresses are personal for a website operator if the website operator has legal means to obtain identification from the provider. This means that almost all IP addresses logged on the server side are under GDPR protection, including the log files in web servers, firewalls, load balancers and application performance monitoring tools. Even shortened IP addresses are only sufficiently anonymized if the shortening affects at least the last octet and there is no chaining with other identifiers.
The ECJ also specified the consent requirement for cookie IDs and pixel trackers in the Planet49 decision (ref. C-673/17). The national implementation through the TTDSG, since 2026 TDDDG, requires active consent for all cookies that are not absolutely necessary. Advertising trackers, conversion pixels and profiling scripts are therefore based on Art. 6 Para. 1 lit. a GDPR in conjunction with Section 25 TDDDG. Consent must be verifiable, granular, informed and revocable at any time. A consent management system is mandatory; proof must be kept in an audit-proof manner for at least three years.
Operationally, there are three mandatory layers. Firstly, every online processing must be recorded with a legal basis in the processing register in accordance with Art. 30 GDPR. Secondly, data transfer to third-country providers, especially to the USA, must be secured via standard contractual clauses and a transfer impact assessment. Thirdly, the reporting line to the data protection officer must ensure that new tracking tools are evaluated before they go live. A tool onboarding process is stored in the CIVAC workspace, which carries out the check as a workflow and at the end generates a release or rejection with documented reasons.
Processing, legal basis and principles according to Articles 5 and 6 GDPR
As soon as personal data is available, any operation on it is considered processing within the meaning of Art. 4 No. 2 GDPR. This includes collection, recording, organisation, storage, adaptation, reading, querying, use, disclosure, transmission, deletion and destruction. Each of these operations requires its own legal basis according to Art. 6 Para. 1 GDPR. In the employment context, Section 26 BDSG is added as a special standard; in direct marketing, the legitimate interest according to lit. f with documented balancing of interests often applies. This balancing of interests is not a formality, but rather a substantive examination of the reasonable expectations of the data subject and the intrusiveness of the processing.
Art. 5 Paragraph 1 GDPR formulates six principles that all processing must comply with. Legality, good faith and transparency, purpose limitation, data minimization, accuracy, storage limitation as well as integrity and confidentiality. In addition, according to Art. 5 Para. 2 GDPR, there is an obligation to account. The person responsible must not only ensure compliance with the principles, but also be able to prove it. This reversal of the burden of proof is at the core of modern data protection audits. Without a documented process, the principle is considered to be violated, even if the processing is materially correct. Practice shows that fines often fail because of the documentation, not because of the matter itself.
Accountability turns the GDPR program into a documentation discipline. Processing directories, order processing contracts, data protection impact assessments, training certificates, deletion protocols and reporting correspondence must be in a discoverable repository. The CIVAC workspace maps these requirements as interlinked modules, with versioning, change history and audit trail. Others run compliance like a filing cabinet. We run it like software. In the event of a request from the supervisory authority, the data protection officer exports the relevant evidence in less than two working days instead of the classic two to six weeks. This speed is the difference between an orderly inspection process and a fine procedure with public impact.
Pseudonymization, anonymization and data minimization in detail
Art. 4 No. 5 GDPR defines pseudonymization as the processing of personal data in such a way that the data can no longer be assigned to a specific person without the use of additional information. The prerequisite is that this additional information is stored separately and is subject to technical and organisational measures that prevent unauthorized combination. Pseudonymized data remains personal, but as a technical protective measure according to Art. 32 GDPR, enjoys a privileged position in the balancing of interests, impact assessment and reporting assessment in the event of data breaches.
Anonymization within the meaning of Recital 26 GDPR requires irreversible decoupling. Statistical aggregates, k-anonymity above appropriate thresholds or differential privacy are considered anonymous depending on the context. The key test is re-identification risk using available additional information, including public datasets, social networks and commercial data brokers. This risk must be documented and periodically reviewed because new data sources may enable chaining. The federal and state supervisory authorities publish guidance on this, which should be referenced in every impact assessment.
Data minimization according to Art. 5 Para. 1 lit. c GDPR requires that only the data necessary for the purpose be collected. In practice, this often fails due to established forms and CRM fields that have been expanded over the years without old fields being removed. The CIVAC workspace therefore carries out a field inventory as a recurring workflow in which each field is assigned to processing and the reason for its necessity is stored. Fields without justification will be suggested for deletion. This discipline not only reduces risk, but also speeds up requests for information because a person's data card is clearly delineated.
Rights of those affected: information, correction, deletion, objection
Articles 12 to 22 GDPR give data subjects comprehensive rights against the person responsible. The information according to Art. 15 GDPR is the most important in terms of quantity. Controllers must provide a complete data map within one month of receipt, including processing purposes, categories, recipients, storage period and sources. The deadline is strict, the extension of two months according to Art. 12 Para. 3 GDPR only applies if complexity is proven and must be communicated with reasons within the first month. A blanket extension without justification is considered a violation of accountability.
Correction according to Art. 16 GDPR, deletion according to Art. 17 GDPR and restriction according to Art. 18 GDPR are subject to the same deadlines. The right to deletion is particularly sensitive because it often conflicts with retention obligations under Section 147 AO or Section 257 HGB. The person responsible must document in a deletion concept which data in which systems is due to be deleted and when and which blocked deletions remain in place for legal reasons. The DIN 66398 deletion rules provide an established system with specific deletion classes and deletion periods for each data category.
Operational difficulty usually arises not in the legal assessment, but in the data determination. Personal data is distributed in CRM, ERP, email archives, backups, log files and in contract processors. The CIVAC workspace keeps a system inventory with data cards for each system for each person responsible, so that requests for information are answered along a verifiable query chain. The average processing time drops from the typical 18 to 6 days, and the proof remains audit-proof. The clock starts on awareness. This clarification is the most common reason for missed deadlines in decentralized organisations.
Data breaches: obligation to report according to Art. 33 and Art. 34 GDPR
Art. 33 Para. 1 GDPR obliges the person responsible to report a violation of the protection of personal data to the responsible supervisory authority immediately, if possible within 72 hours of becoming aware of it. The clock starts on awareness. Knowledge occurs as soon as the person responsible can assume with sufficient certainty that a security incident has led to a violation. Late reports must be justified, which in practice leads to fines if the justification is not convincing. A zero report followed by a correction report is also permissible and is often the safer option in unclear facts because it meets the deadline and creates space for forensic processing.
In terms of content, the report requires a description of the type of violation, the categories and approximate number of affected persons and data sets, the contact details of the data protection officer, the likely consequences and the measures taken or proposed. Art. 34 GDPR applies if there is a high risk to rights and freedoms. Then those affected must be informed immediately in clear and simple language. The threshold is a risk assessment, not a blanket requirement, and should be decided using a documented assessment framework that takes into account the sensitivity, scope and likelihood of damage.
The CIVAC workspace provides a pre-built 72-hour path for data breaches. The incident is recorded in an initial form, the DPO automatically receives an assessment task, a classification according to the ENISA scheme is proposed, and the reporting document for the supervisory authority is generated from the fields. For NIS-2 relevant sectors, the 24-hour early warning path is also sent to the BSI, followed by the 72-hour follow-up report and the final assessment after one month. Audit-proof, documented, paragraph-proof. This double path logic avoids duplication of work and closes gaps between GDPR and NIS 2 obligations, which in practice often lead to contradictory reports.
Processing directory according to Art. 30 GDPR as an operational backbone
Art. 30 GDPR requires the person responsible to keep a list of all processing activities. This obligation applies to practically every company with ten or more employees because the exception under Article 30 Para. 5 GDPR is very narrow and does not apply if personnel are processed regularly. The directory is not just a form, but the central control basis for data protection management. It combines the purpose, legal basis, data categories, recipients, deletion periods and protective measures for each processing and serves as the first subject of review for every request from the supervisory authorities. Processors maintain their own directory in accordance with Article 30 Paragraph 2 of the GDPR with a different focus.
In practice, good directories contain 60 to 200 entries, depending on the industry and size. Each processing is carried out with a unique identifier, a version history and a person responsible from the department. Changes to tools, providers or data flows trigger an audit task to the DSB. Without this discipline, the directory will become obsolete within twelve months, which will be considered a breach of accountability when audited. Supervisory authorities regularly require the directory as the first item to be checked, followed by order processing contracts and deletion concepts. The completeness of the entries is more important than the level of detail of individual fields.
The CIVAC workspace maintains the directory as a living repository with links to order processing contracts, impact assessments and training courses. Each entry carries a data card so that information, correction and deletion requests are processed along the way. Those responsible who choose the Officer-as-a-Service model receive an initial directory of 490 audit templates as a starting point and thus a verifiable baseline in two working days instead of several weeks of initial recording. The baseline will be refined in the following months through structured departmental interviews and provided with change notifications, each of which triggers a version release by the DSB.
Turn reading into a mandate.: CIVAC for those responsible
Whoever processes personal data bears the burden of proof for legality, transparency and security. This burden of proof is not a one-time project but an ongoing discipline. Data flows change, providers change, case law changes, and with each change the level of protection shifts. CIVAC is the compliance platform and officer-as-a-service for companies that do not want to manage this discipline as a filing cabinet, but as software. The workspace brings together the processing directory, procedures for information and deletion requests, order processing management, impact assessments, reporting paths and training records under a single reporting line and thus maps all 25 representative roles with the respective audit templates.
You have two options. Licence the workspace for your internal representatives, then your data protection officer and your departments work in an environment with EU data residency, 93 ISO/IEC 27001:2022 controls, 490 audit templates and a structured 72-hour path for data breaches. Or have our officers appointed it. CIVAC then takes on the role of external data protection officer with an appointment certificate, reporting line and SLA. Both models result in the same proof. The appointment certificate, signed, filed, verifiable. The choice between the models depends on internal staff strength, risk exposure and the willingness to mandate external responsible persons.
If you receive a request for information today, a data breach has to be reported or you call a supervisory authority, the quality of your documentation will determine the response time. CIVAC shortens this response time to two working days instead of the classic two to six weeks. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de/faq to start an initial assessment of your data protection situation. You will receive feedback within 24 hours with the next steps and an indicative cost estimate for both models.
FAQ
What exactly is personal data according to Art. 4 No. 1 GDPR?
Personal data means any information relating to an identified or identifiable natural person. A person can be identified as soon as they can be recognised via identifiers such as name, identification number, location data or online identifiers. Indirect identification through the combination of several characteristics also falls under the term, provided that the effort is not disproportionately high and realistic means of chaining exist.
Are IP addresses always personal data?
As a rule, yes. In the Breyer decision, the ECJ ruled that dynamic IP addresses are personal for website operators if the provider has legal means of identification. Static IP addresses can usually be clearly assigned anyway. Log files that contain IP addresses are therefore subject to the GDPR and require a legal basis, storage limitations and technical and organisational protective measures.
Which data are considered special categories according to Art. 9 GDPR?
This includes data on racial and ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data for unique identification, health data and data on sex life or sexual orientation. A fundamental ban on processing applies to these categories with exceptions in accordance with Article 9 (2) GDPR, such as consent, employment context or medical care.
When is data anonymous and therefore outside the GDPR?
Data is anonymous if the link to the person is irreversibly broken and re-identification is not possible even with the use of available additional information. Pure pseudonymization is not enough because the key enables chaining. Anonymity is a risk assessment that must be documented and periodically reviewed because new data sources can increase the risk of re-identification.
What deadlines apply for information, deletion and data breaches?
According to Article 12 Para. 3 GDPR, requests for information, correction, deletion and restrictions must be answered within one month, in complex cases with a justified extension of up to three months. According to Art. 33 GDPR, data breaches must be reported to the supervisory authority within 72 hours of becoming aware of them; if the risk is high, they must also be reported to the data subjects in clear language according to Art. 34 GDPR.
Who is liable for violations of the GDPR?
The person responsible within the meaning of Art. 4 No. 7 GDPR is the body that decides on the purposes and means of processing. It is primarily liable, including fines in accordance with Art. 83 GDPR of up to 20 million euros or 4 percent of global group sales. Processors are independently liable for their obligations in accordance with Art. 28 GDPR. The data protection officer himself is not personally liable, but is responsible for advising the management.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.