Skip to content

Privacy Hub · plain-language reference

← Privacy Hub

Personal data and personal information

Also known as: identifiable information, information about a person, personal information, personally identifiable information, pii

Personal data is information that relates to an identified or identifiable person. It includes obvious identifiers, such as a name or identity number, and information that can identify someone when combined with other details. Some laws use the term “personal information”. The exact definition and the rules that apply depend on the selected jurisdiction.

ZW_CDPA
EU_GDPR
GB_UK_GDPR
v2 · published 31 Jul 2026

Term explanation

At a glance

Personal data is information connected to a real person. Sometimes the connection is obvious: a name, photograph, email address or identity number. In other cases, the information becomes personal only when it is combined with context, such as a location trail, device identifier, employee number or unusual set of characteristics.

The important question is not simply, “Does this record contain a name?” It is, “Could a person be identified or singled out from this information using means that are reasonably available?” If the answer may be yes, treat the information cautiously until its status has been assessed.

In plain language

Personal data can appear in customer files, employee records, application logs, photographs, recordings, survey results, health records, payment histories and online identifiers. An opinion about a person may also be personal data. So may a score, prediction or profile created about them.

A record can remain personal even when a person’s name has been replaced with a code. If someone can reconnect the code to the person using additional information, the record is usually pseudonymised rather than truly anonymous. Properly anonymised information is different: identification should no longer be reasonably possible. Removing a name alone is rarely enough to prove that result.

Why it matters

The same fact can be harmless in one setting and identifying in another. A job title such as “finance manager” may describe many people in a large company but identify one person in a small organisation. A location point may identify nobody on its own but reveal a home address when combined with repeated observations.

This is why privacy work begins with data mapping. Organisations need to know what information they hold, where it came from, what it is used for, who can access it, where it is sent and how long it is retained.

A practical example

A delivery business stores a customer’s name, phone number, address and order history. Each item is personal data. A driver ID may also be personal data if the business can link it to a named driver. A report showing only the total number of deliveries by city may be anonymous if nobody can be identified from it or the underlying output.

General principles

Personal data and sensitive information

Not all personal data carries the same level of risk. Health information, biometric data, political views, children’s information and other sensitive categories can require stronger safeguards or additional legal conditions. The labels and category boundaries vary by jurisdiction, so the selected jurisdiction view should be checked before relying on a general explanation.

Practical next steps

Create an inventory of the personal data your organisation handles. Include information held by suppliers and cloud services, not only information in your own systems. Classify higher-risk categories, document why each dataset is needed, limit access, set retention rules and check whether sharing or international access introduces additional requirements.

Related terms: data subject; processing; sensitive data; controller; processor; anonymisation; pseudonymisation

Jurisdiction guidance

Select more lenses from the Hub landing page to compare across jurisdictions.

GLOBAL
Global baseline

No jurisdiction-specific guidance is published for this lens yet.

Sources & citations

Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.


Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.