Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. What is Personal Data? (Art. 4.1)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 5/54 Part I — General Introduction Beginner Reviewed 2026-08-23

What is Personal Data? (Art. 4.1)

Article 4(1) GDPR defines personal data broadly as any information relating to an identified or identifiable natural person, directly or indirectly via an identifier.

Open in interactive reader
⚖️ Binding Definition 🏛️ CJEU Case Law C-582/14 Breyer

Definition of Personal Data (Art. 4.1)

⚡ In 30 seconds

Under Article 4(1), personal data means any information relating to an identified or identifiable natural person ('data subject'). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier.

Direct Identification

Information clearly designating an individual without ambiguity: Full Name, National Identity Number, facial biometric template, official email address.

Indirect Identification

Data pieces that reveal an individual through cross-referencing: IP address, cookie identifier, license plate, serial number, granular geolocation trajectory.

⚡ Key Takeaways
  • Broad, dynamic definition: subjective or factual data are equally covered.
  • Contextual test: data is personal if anyone has reasonable legal means to re-identify the subject.
  • Legal persons (corporations) are excluded; only living human beings qualify as data subjects.
⚠️ Common Pitfall

Claiming data is non-personal simply because names have been substituted with random numerical tokens.

🛠️ In Practice

Treat system logs, telemetry metrics, and device fingerprints as personal data subject to GDPR principles.

⚖️ Official Sources: Art. 4(1) GDPR · Recitals 26–30 · CJEU C-582/14 Breyer · WP29 Opinion 4/2007 ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Identification can be direct (name, passport) or indirect (employee ID, IP address, RFID).
  • Online identifiers and geolocation records constitute personal data.
  • Identifiability assessment depends on all reasonable means likely to be used by any person (Recital 26).

⚠ Common pitfall: Asserting that dynamic IP addresses are never personal data; CJEU case law (Breyer, C-582/14) confirms they are when combined with ISP logs.

→ Actionable practice: Treat technical logs, MAC addresses, and advertising identifiers as personal data across all risk assessments.

← Scope of Application: Material & Territorial (Art. 2 & 3) Data Typology: Anonymous vs Pseudonymous vs Sensitive Data →