GDPR

Knowledge Base | GDPR | What personal data is not covered by GDPR?

What personal data is not covered by GDPR?

The GDPR protects information relating to identified or identifiable living people. Information that falls outside this protection includes:

  • Truly anonymised data, where a person can no longer be identified using methods reasonably likely to be used.

  • Information relating solely to a company or another legal entity, such as its registration number. However, details identifying employees, directors or sole traders can still be personal data.

  • Information concerning deceased people, although national laws may provide separate protections.

The European Commission’s explanation of personal data also distinguishes truly anonymous information from data that has simply had identifiers removed. Encrypted, pseudonymised or publicly available information can still be personal data.

Some processing of personal data can also fall outside the GDPR. For example, the GDPR does not generally apply to purely personal or household activities, such as keeping a private address book. Non-automated notes may also fall outside the GDPR if they are not part of, or intended to form part of, a structured filing system.