YOUR GUIDE TO:

What counts as personal data under UK GDPR?

Learn what personal data is, why some information receives extra protection and how criminals can use seemingly harmless details to build a picture of you.

Join the Claim is not a law firm. This information is for general guidance only and does not constitute legal advice. While every effort has been made to ensure the information is accurate, regulations, details, and legal proceedings may change. 

Woman holding a cup on her computer

What exactly is personal data?

Most of us hand over personal information every day without giving it much thought. We type in our email address to shop online, share our date of birth to verify our identity and upload photos to social media.

But what actually counts as personal data? The answer is broader than many people realise.

Understanding what personal data is can help you appreciate why organisations have legal responsibilities to protect it, why some data breaches are more serious than others and what your rights are if your information is exposed.

Key takeaways

What is UK GDPR?

The UK General Data Protection Regulation (UK GDPR) is one of the main laws that governs how organisations collect, use, store and share personal information.

It gives people important rights over their personal data and requires organisations to handle that information responsibly. It also sets out when organisations can collect personal data, how they should keep it secure and what they should do if a data breach occurs.

UK GDPR works alongside the Data Protection Act 2018, which provides additional rules in certain areas, such as law enforcement, intelligence services and some types of sensitive personal information.

Whether you’re shopping online, using a mobile app, visiting your GP or applying for a job, UK data protection law helps ensure your personal information is treated fairly and kept secure.

What is personal data?

Personal data is any information that identifies you, or could be used to identify you when combined with other information.

Some types of personal data identify you immediately, such as your name or passport number. Other pieces of information might not identify you on their own but can still become personal data when linked with other details.

Think of it like a jigsaw puzzle. One piece may not reveal much, but put enough pieces together and it becomes clear who they belong to.

Personal data can include information that is:

Everyday examples of personal data include:

Organisations can face serious consequences when personal data is exposed.

Explore the latest data & privacy claims

Here are some of the data breach claims and investigations we are spotlighting. They involve a wide range of personal information, from contact details and financial information to sensitive health and identity data.

What isn't personal data?

For information to be personal data, it must relate to an identifiable person. If someone cannot be identified from the information, either on its own or when combined with other data that is reasonably available, it is generally not classed as personal data.

Examples of information that is not usually personal data include:

However, it’s important to understand that anonymous and pseudonymised data are not the same thing.

For example, if a company replaces names with customer ID numbers but keeps a separate file showing which ID belongs to which customer, the data is still personal data because people can still be identified.

In practice, truly anonymous data is relatively rare. Much of the information organisations hold can still identify someone, directly or indirectly, and therefore remains protected under UK data protection law.

What is special category data?

Some types of personal data are considered particularly sensitive and receive extra protection under UK data protection law. This is known as special category data.

If this information is lost, stolen or accessed without permission, it can have a much greater impact on someone’s privacy, wellbeing or even their safety. That’s why organisations must meet stricter requirements when collecting, using and protecting it.

Special category data includes information about a person’s:

Many organisations hold this type of information as part of their day-to-day activities. For example:

Because this information is especially private, organisations must have a valid legal reason for collecting and using it and take appropriate steps to keep it secure.

Flo data privacy claim

If sensitive health information is shared, exposed or used without permission, you may have the right to seek compensation.

One example attracting international attention is the Flo data privacy case, which concerns allegations that users’ sensitive health information was shared with third parties without their knowledge or informed consent.

What about criminal offence data?

Information about criminal convictions and offences is not classed as special category data, but it is still given additional protection under UK data protection law.

This includes information relating to a person’s:

Organisations can only process this type of information in specific circumstances and must have appropriate safeguards in place.

For example, criminal offence data may be processed by:

Like other personal data, criminal offence data must be kept secure. If it is exposed in a data breach, it can have serious consequences for the people involved, including damage to their reputation, employment prospects and privacy.

Although criminal offence data is protected differently from special category data, both types of information require organisations to handle them with particular care because of the potential impact if they are misused or disclosed.

Why some data breaches are more serious than others

No two data breaches are the same.

The impact of a breach depends on several factors, including the type of information involved, how much of it was exposed and how it could be misused.

For example, if a mailing list containing only email addresses is accessed, the main risk may be an increase in phishing emails or spam.

However, if a breach includes names, addresses, financial details and copies of identity documents, the consequences could be much more serious.

It’s also important to remember that the same type of information can have a different impact depending on the circumstances. 

For one person, a leaked email address may be little more than an inconvenience. For another, the exposure of personal information could increase the risk of fraud, identity theft or significant emotional distress.

Ultimately, it’s not just what information was exposed that matters, but how it could affect the people involved. That’s why organisations are expected to assess the risks of every data breach carefully and take appropriate action to protect those affected.

Factors that can make a data breach more severe include:

How criminals can build a profile about you

Cyber criminals don’t always need a single piece of highly sensitive information to commit fraud. Instead, they often collect small amounts of personal data from multiple sources and combine them to build a detailed picture of an individual.

On their own, individual pieces of information may seem harmless. But when they’re brought together, they can help criminals impersonate someone, bypass security checks or make scams appear much more convincing.

How different pieces of data can be misused

Email address

Sending convincing phishing emails or spam.

Phone number

Smishing (text message scams) or phone scams.

Date of birth

Passing identity checks or answering security questions.

Home address

Identity fraud or targeted scams.

Login credentials

Accessing online accounts.

Financial information

Attempting fraud or unauthorised transactions.

Health information

Creating highly personalised scams or attempting blackmail.

Customer account details

Impersonating you when contacting organisations.

The more information criminals have, the easier it can become to make their scams look genuine. For example, an email that includes your name, address and details of a recent purchase is far more convincing than a generic message sent to thousands of people.

This is one reason why organisations are expected to protect all personal data they hold. Even information that seems relatively ordinary can become valuable when combined with other data from previous breaches or publicly available sources.

Protecting yourself after a data breach

If you’ve found out your data has been compromised, don’t panic – but don’t ignore it either.

Whether it’s a leaked email address, stolen passwords, or worse, a data breach can leave you exposed to scams, ID fraud, and credit damage. But you’re not powerless.

Our guide explores what you can do right now to protect yourself and hold the offending organisation accountable.

What organisations must do to protect your data

Whenever an organisation collects your personal information, it has a responsibility to keep it safe.

There isn’t a single checklist that every organisation must follow. Instead, the steps they take should reflect the type of information they hold and the risks involved.

Depending on the circumstances, organisations may need to:

Organisations also have responsibilities if something goes wrong

If they discover a personal data breach, they should act quickly to investigate what happened, contain the incident and reduce the risk of further harm. In some cases, they may also need to report the breach to the Information Commissioner’s Office (ICO) and inform the people affected.

No organisation can guarantee that it will never experience a cyber attack or data breach. However, they are expected to take appropriate steps to protect the personal information they hold and respond responsibly if an incident occurs.

When organisations fail to meet these responsibilities, the consequences can extend far beyond financial loss. Data breaches can expose people’s privacy, damage trust and leave individuals vulnerable to fraud, identity theft and other forms of harm.

Your rights under UK GDPR

UK data protection law gives you a number of rights over your personal information. These rights are designed to help you understand how your data is being used and give you greater control over it.

Depending on the circumstances, you have the right to:

Having these rights doesn’t mean organisations must agree to every request. There are circumstances where they can refuse, for example if they have a legal obligation to keep certain records or if an exemption applies.

Understanding your rights can help you ask the right questions, challenge poor data handling practices and make informed decisions about how your personal information is used.

Making a subject access request

A subject access request (SAR) is a request you can make to an organisation to find out what personal data it holds about you.

Under UK data protection law, you have the right to ask an organisation whether it is processing your personal data, receive a copy of that information, and understand how it is being used.

Our guide explains what a SAR is, when it can help, how to make one, and what to do if an organisation does not respond properly.

How Join the Claim can help

Understanding data protection law can feel overwhelming, especially if you’ve recently discovered that your personal information has been exposed.

At Join the Claim, we’re here to make things clearer.

We explain how data breach claims work in plain English, keep you informed about major data breaches affecting UK consumers and provide practical guidance to help you understand your rights.

If a regulated UK law firm decides to pursue a group action relating to a particular data breach, we may also help eligible people connect with that law firm.

Whether you’re trying to understand what personal data is, looking for practical advice after a data breach or wondering whether compensation may be available, our aim is to give you the information you need to make informed decisions.

Latest data breach & privacy claim news

Frequently asked questions about personal data

Personal data is any information that identifies you or could be used to identify you. Special category data is a smaller group of particularly sensitive personal information, such as health records or biometric data, which receives extra protection under UK data protection law.

Yes. An email address can identify you directly or indirectly, especially if it includes your name or is linked to your account with an organisation.

It can be. Although an IP address doesn’t usually identify you by name, it can often be linked to your device or online activity and may therefore be considered personal data.

A postcode on its own isn’t usually enough to identify someone. However, when combined with other information, such as a house number or name, it can become personal data.

Yes, if the person in the photograph can be identified. The same generally applies to video recordings, CCTV footage and voice recordings.

Yes. Information such as your bank account details, payment card information and transaction history is personal data and should be protected appropriately.

Organisations collect personal information for many legitimate reasons, such as providing services, processing payments, preventing fraud, communicating with customers and complying with legal obligations. They should only collect the information they genuinely need and must keep it secure.

No. In most cases, organisations should only keep personal data for as long as it is needed for the purpose it was collected. After that, it should be securely deleted or anonymised unless there is a legal reason to retain it.

Follow any guidance provided by the organisation involved, change passwords if necessary, be alert to phishing emails or scam calls, and monitor your financial accounts for unusual activity. If you’re unsure what steps to take, our guide to protecting yourself after a data breach can help.

No. Not every data breach results in a legal claim or compensation. Whether compensation may be available depends on the circumstances of the breach and the legal merits of the case.

Help and advice for data breach and data misuse victims

If your personal information has been exposed due to a data breach, or has been otherwise misused, being informed can help protect your rights while you fight for the justice and compensation you deserve.

Did you know we have a newsletter?

Sign up for our newsletter to stay up to date.