Definitions #
Any information that relates to an identified or identifiable living person, such as a name, email, IP address, or health records.
Technical Under the GDPR, personal data is any information relating to an identified or identifiable natural person; pseudonymised data falls within scope if re-identification is reasonably possible.
Example Our privacy policy explains how we process personal data such as customer email addresses and browsing habits.
Etymology #
From personal (relating to a person) + data (plural of Latin datum), the legal sense was codified in European data protection law in the 1995 Data Protection Directive.
Collocations #
- personal data breach 个人数据泄露(违反保密、丢失或未授权访问)
- special categories of personal data 特殊类别个人数据(如健康、种族、宗教等)
- data subject 数据主体(个人信息的所属人)
Real Business Examples #
- Under GDPR, the controller must provide a privacy notice before collecting employees' personal data.
- The court ruled that a dynamic IP address can constitute personal data when combined with other identifiers.
Register & Variants #
- Register: formal
- BrE/AmE: 全球通用,EU 法律语境中为直接术语
Synonyms & Antonyms #
- Synonyms: personal information, PII (in US context)
- Antonyms: anonymous data, aggregate data
Common Errors #
- 认为已去标识化的数据一定不是个人数据 伪匿名数据若可结合其他信息识别个人,仍属个人数据;只有匿名化不可逆才出范围
- 把个人信息和隐私等同 个人数据范围更广,隐私指合理期待保护的信息,两者法律依据不同
Confusable Terms #
- Sensitive Data vs Personal Data
- Sensitive data 是个人数据中特殊类别,如健康、政治观点;普通个人数据不含这些
Frequently Asked Questions
员工考勤记录是否属于个人数据?
属于,因为它涉及可识别员工的出勤时间和位置
公司网站 IP 地址算个人数据吗?
视情况,若结合其他信息可识别用户,则算
处理个人数据的合法性基础有哪些?
主要包括同意、合同履行、法律义务、公共利益、合法利益等,视情形而定