What is personal data: personal data defined
Personal data is any information relating to an identified or identifiable living person, which under Article 4(1) GDPR covers far more than a name or an address: a photograph, a video clip, a voice recording and an online identifier all qualify. Context decides the edge cases.
Article 4(1) sets the test in two halves. The information has to relate to a person, and that person has to be identified or identifiable, directly or indirectly, by reference to an identifier such as a name, an identification number, location data or an online identifier. Sensitivity is not part of the definition, so ordinary operational information counts.
What does personal data mean in practice?
Almost no real argument is about the definition. The argument is about identifiability, and Recital 26 GDPR answers it with a practical test: account should be taken of "all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments."
Two consequences follow, and both bite in day to day operations:
- Pseudonymised data is still personal data. Replacing a name with a case reference does not take the file out of scope while somebody holds the key that links the two.
- Genuinely anonymous information is out of scope. Recital 26 says the principles do not apply to information that does not relate to an identifiable person. The bar is high. Aggregate reporting usually clears it, a redacted file usually does not.
When is an image or a video personal data?
Whenever the person in the frame can be recognised. The Court of Justice of the European Union settled the point in Rynes (Case C-212/13, judgment of 11 December 2014), holding that the image of a person recorded by a camera is personal data because it makes it possible to identify the person concerned. A domestic security camera that also caught a public footpath was enough to pull the recording inside data protection law.
That matters for any claims, service or field workflow built on customer supplied media. A damage video shot on a driveway routinely picks up a face at a window, a passer by, a child, a colleague. Every one of them is a data subject inside that file, even though only one of them is the claimant.
Audio sits on the same footing. A spoken explanation recorded alongside the capture, and any transcript generated from it, is personal data about the speaker and often about the people they describe.
Number plates, house fronts and why context decides
A vehicle registration mark identifies a vehicle rather than a person, which is why teams assume it falls outside the rules. The ICO takes the opposite view for most uses. Its guidance on automatic number plate recognition states that a VRM is personal data in most circumstances, and that it is personal data at the point of collection where it is processed as part of a surveillance system for the purpose of identifying an individual, for example to serve a parking fine.
A house exterior behaves the same way. A photograph of a front door is a picture of a building right up until it is tied to an address, a policy, a tenancy or a claim reference, at which point it says something about the people who live behind that door. The same image can sit outside scope in one system and be personal data in another. What your organisation can link it to is the deciding factor, not the content of the frame.
Personal data explained: a worked example
A motor insurer receives a customer video of a damaged bumper. The frame holds the claimant's number plate, a neighbour's parked car, the front of the house, and thirty seconds of the claimant narrating what happened. That one file contains personal data about the claimant, probably about the neighbour, and location information about a private address. Because it is retrievable by claim reference, it falls inside the retention schedule and inside any access request that follows.
What personal data gets confused with
- Special category data, the narrower set listed in Article 9 GDPR such as health data and biometrics used for identification, which needs an extra condition on top of a lawful basis.
- Confidential business information, which can be commercially sensitive and still fall entirely outside data protection law.
- Evidence, which is a use rather than a category. Material can be strong evidence and personal data at the same time, which is why retention keeps surfacing in every evidence integrity discussion.
How the UK and other regimes handle it
The UK kept a near identical definition after Brexit. The UK GDPR carries Article 4(1) across and works alongside the Data Protection Act 2018, but it is a separate statute read by the ICO and the UK courts, and the Data (Use and Access) Act 2025 has already pulled parts of the regime away from the EU text. Elsewhere the ideas are comparable rather than the same. Several US state laws work from "personal information" with their own carve outs, and regimes such as Brazil's LGPD, Canada's PIPEDA and India's DPDP Act set their own scope. An EU answer does not travel unchecked.
For a claims or service operation the safe working assumption is that any customer supplied image, video or audio file is personal data, with retention, redaction and access designed around that. The teams that get caught out are the ones that classified a workflow by its business purpose instead of by what the files actually contain, which is why photo evidence in insurance claims and data subject requests keep landing on the same desk.