Personal Data Processing Defined

The General Data Protection Regulation (GDPR) provides the regulatory framework for processing personal data within the European Union (EU) and the UK. It defines key terms like data subjects (individuals whose data is processed), data controllers (entities that determine processing purposes), and data processors (entities that handle data on behalf of controllers).

In short the GDPR regulates the processing of personal data for non-personal reasons. In this article we are going to explore what these terms mean and discuss what fall inside and outside the GDPR regulation.

To understand more about the GDPR you can read our introduction to this topic here

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Understanding the Data Landscape: Personal and Non-Personal Data Defined

To differentiate between purely personal and non-personal data processing, it’s crucial to grasp the definitions of these terms. Personal data encompasses information that directly or indirectly identifies an individual, such as names, addresses, or unique identifiers. On the other hand, non-personal data, also known as anonymised or aggregated data, has been altered to remove identifying elements, or never had personal identifiers in the first place.

The GDPR defines personal data in Article 4 as:

“anything that by itself or in combination with other data could lead to a person being identified”

This makes the scope of personal data very broad because even if a data point doesn’t identify a person, if it is combined with other data in a way that could identify a person, it still counts as personal data.

Personal Data

Processing personal data involves various activities, from collecting and storing to analysing and using data that can directly or indirectly identify individuals. For instance, when an online retailer stores customer names and addresses for shipping purposes, this is processing people’s data. Examples of personal data include:

  • Name
  • National insurance number
  • Sexual orientation
  • Address
  • NHS number
  • Religious beliefs
  • Telephone number
  • Car number plate
  • Political views
  • Data of Birth
  • Salary
  • Favourite colour
  • Email address
  • Gender
  • Fingerprints

Non-Personal Data

Non-personal data processing focuses on information that has been transformed to remove identifiers, ensuring anonymity. This can be achieved through techniques like anonymisation, which eliminates personal identifiers, or aggregation, which combines data to generate insights without revealing specific individuals’ details. Examples of non-personal data include:

  • financial information
  • interest rates
  • floorplans
  • weather forecasts
  • aggregated survey results
  • project plans
  • traffic volumes
  • inventory numbers
  • purely personal processing
  • sales volumes
  • instruction manuals
  • anonymised data
  • opinion polls
  • product prices
  • pseudonymised data

A Note on Anomymised Data, Pseudonymised Data, and Purely Personal Data Processing

Anonymised data means data with all possible identifiers removed. This, as noted above, is hard to do given the definition of personal data and the broad range of data it then applies to.

Pseudonymised data is similar to anonymised data but it is a more complex arrangements. What happens is the data set is duplicated, each individual is allocated a unique reference number and then the duplicate data set is anonymised (but keeping the reference number). This means that an individual can be reidentified if need be but the duplicate data set is effectively anonymised. This is useful in, for example, medical research. Researchers may identify concerns about an individual’s health and can arrange for that person to be identified to receive healthcare. They will not be able to identify the person themselves, however. You can read more about pseudonymisation here.

Finally, the GDPR does not apply to processing people’s data for personal reasons. That means, for example, sharing family photos on your personal social media is not regulated by the GDPR and is not the kind of thing you need to worry about. Still, it is important to be mindful of where the boundary lies as this case shows.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

How the GDPR Applies

The GDPR applies to the processing of personal data, but not the processing of non-personal data. Processing people’s information requires compliance with the regulation’s requirements to have a clear lawful basis for the processing, rights of data subjects, and data security obligations. Non-personal processing, while exempt from certain GDPR provisions, must still adhere to ethical considerations and effective data security practices.

Balancing Privacy and Innovation

Non-personal data processing offers innovative opportunities for businesses while maintaining privacy. For instance, aggregated data can reveal trends without revealing personal identities. It’s essential, however, to ensure that personal data remains protected and that non-personal data usage aligns with ethical standards.

Ensuring Compliance: Addressing Challenges and Obligations

There are challenges to processing identifiable data lawfully such as complying with the data privacy principles and respecting data subjects’ rights. In non-personal data processing, challenges include maintaining data anonymisation and ensuring secure storage. Both approaches demand careful consideration of ethical, legal, and technical aspects.

Importance of Transparency and Accountability

Transparency plays a crucial role in personal data processing, as data subjects have the right to know how their information is used. In non-personal data processing, accountability becomes essential to ensure that data has been properly anonymised and aggregated, safeguarding privacy.

Navigating Consent and Data Subjects’ Rights

If you are relying on consent to process personal data, obtaining informed consent is paramount. Individuals must be able to make informed decisions about their data. If you are not you must still have a clear lawful basis for your data processing and make people aware of it. Data subjects also have rights to access, rectify, and sometimes erase their data. You must be able to comply with people’s wishes when they exercise their rights.

Non-personal data processing, while anonymised, should still adhere to ethical considerations to prevent unintended reidentification which would be a breach of GDPR.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial

Conclusion: Key Takeaways on Personal Data Processing

The evolution of data processing continues to shape the privacy landscape. Innovations in non-personal data utilisation, such as AI-driven insights from aggregated data, offer valuable possibilities but that may require more regulation. As data practices evolve, ethical and legal frameworks will play a crucial role in guiding responsible data processing.

In essence, understanding the difference between purely personal and non-personal data processing under the GDPR is pivotal in ensuring compliance, protecting privacy, and fostering innovation. Organisations must navigate these distinctions to balance data-driven insights with ethical considerations, contributing to a responsible and privacy-conscious digital world.