
Personal data is one of those terms that gets thrown around constantly, yet few people can confidently say what it actually covers. Whether you’re a business owner processing customer records, an employee filling in HR forms, or simply someone browsing the web, personal data touches almost every part of daily life.
Understanding what counts as personal data matters more than ever. Since the UK GDPR came into force, organisations of all sizes have legal obligations around how they collect, store, and use information that can identify a living person.
What Is the GDPR in Simple Terms?
The five most commonly encountered examples of personal data are names, email addresses, home addresses, phone numbers, and IP addresses. Each of these, on its own or combined with other details, is enough to identify a specific individual, which is the core test under UK data protection law.
What often surprises people is how broad this definition is in practice. A name paired with an employer, a postcode combined with a date of birth, or even a photograph can all constitute personal data if they make it reasonably possible to single out one person from the rest.
| Type of Personal Data | Example | Risk Level |
|---|---|---|
| Name | John Smith | Low (alone), High (combined) |
| Email address | john.smith@email.com | Medium |
| Home address | 14 High Street, Manchester | High |
| Phone number | 07700 900000 | Medium |
| IP address | 192.168.1.1 | Medium |
| National Insurance number | AB 12 34 56 C | Very High |
| Biometric data | Fingerprint scan | Very High |
| Health records | GP diagnosis notes | Very High |
Looking to ensure your data remains GDPR compliant? Take a look at our Database Information here

What Are the Types of Personal Data Recognised in UK Data Protection Law?
UK data protection law, governed by the UK GDPR and the Data Protection Act 2018, splits personal data into two broad categories: standard personal data and special category data. Standard personal data covers the everyday identifiers most people are familiar with, such as names, contact details, and financial information.
Special category data receives a higher level of protection because of its sensitivity. This includes information about racial or ethnic origin, religious beliefs, political opinions, trade union membership, health data, genetic data, biometric data, sexual orientation, and data relating to criminal convictions. Processing this type of data requires a lawful basis plus an additional condition under Schedule 1 of the Data Protection Act 2018.
What Are the 7 Personal Data Principles That Organisations Must Follow?
The seven principles of data protection form the backbone of how organisations must handle personal information. They are laid out in Article 5 of the UK GDPR and apply to any organisation that processes personal data about UK residents, regardless of where that organisation is based.
| Principle | What It Means in Practice |
|---|---|
| Lawfulness, fairness and transparency | Data must be processed legally, fairly, and with clear communication to the individual |
| Purpose limitation | Data collected for one purpose cannot be reused for an unrelated one |
| Data minimisation | Only collect what is strictly necessary for the stated purpose |
| Accuracy | Personal data must be kept up to date and corrected without delay |
| Storage limitation | Data should not be kept longer than necessary |
| Integrity and confidentiality | Appropriate security measures must protect the data |
| Accountability | Organisations must be able to prove they comply with all six principles above |
What Are Examples of Personal Data in Online and Digital Contexts?
Online activity generates personal data at a remarkable rate, much of it without users realising. Cookies, device identifiers, location data collected through mobile apps, and browsing histories can all qualify as personal data when they are linked, or are linkable, to an individual.
For businesses running websites, this has significant practical implications. Even a basic contact form that captures a name and email address triggers data protection obligations, including the need for a compliant privacy notice and, in many cases, a lawful basis for processing that information.
Understanding What Are 5 Examples of Personal Data and Why It Matters for Compliance
The question of what counts as personal data is not merely academic; it sits at the centre of how UK businesses operate responsibly in the digital age. From a sole trader in the home counties collecting customer emails through to a large manufacturer holding staff records, the obligation to understand and protect personal data applies universally.
Getting this right is largely about building awareness into everyday processes. A payroll team that understands why an employee’s salary details are personal data will naturally handle that information with greater care. A marketing team that recognises IP addresses as personal data will think twice before installing third-party tracking scripts without proper consent mechanisms in place.
The consequences of getting it wrong are real and increasingly visible. The ICO has issued fines running into the millions for serious breaches, but even smaller penalties and enforcement notices can damage an organisation’s reputation significantly. Treating data protection as a core operational discipline, rather than a compliance tick-box, is the most reliable route to avoiding those outcomes.
What Are 5 Examples of Personal Data: Frequently Asked Questions
Under the UK GDPR, personal data is any information relating to an identified or identifiable living individual. For a fuller breakdown of the definition and its origins, the Wikipedia article on personal data provides useful context alongside the legal text.
A job title alone is not usually enough to identify a specific person, but when combined with a name or employer it almost always qualifies as personal data. Context is everything under UK data protection law.
Yes, photographs of an individual are generally considered personal data because they can be used to identify that person. This is particularly relevant for organisations publishing staff images on websites or social media.
A work email address such as john.smith@companyname.co.uk is personal data because it identifies a specific individual, even though it is also a corporate identifier. Generic addresses like info@companyname.co.uk are less likely to qualify.
Standard personal data covers general identifiers such as names and contact details, while sensitive personal data (known as special category data under the UK GDPR) covers information like health records, biometrics, and religious beliefs. Special category data requires a higher legal threshold to process lawfully.
Truly anonymised data, where re-identification is not reasonably possible, falls outside the UK GDPR’s scope. Pseudonymised data, where a person could still be identified with additional information, remains personal data and must be handled accordingly.
The UK GDPR sets out six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Organisations must identify and document a lawful basis before collecting or using personal data.
There is no fixed retention period under UK law; organisations must keep data only for as long as it is necessary for the original purpose. The ICO recommends documenting retention periods in a formal data retention policy.
Yes, the UK GDPR applies to virtually all organisations that process personal data about UK residents, regardless of their size. The ICO offers specific guidance for small businesses at https://ico.org.uk/for-organisations/sme-web-hub/.
Individuals have eight rights under the UK GDPR, including the right to access their data, the right to rectification, and the right to erasure (often called the right to be forgotten). These rights must be responded to within one calendar month in most circumstances.
CCTV footage that captures identifiable individuals is personal data and is subject to the UK GDPR, as well as additional guidance from the ICO on surveillance. Organisations operating CCTV systems must display clear signage and have a legitimate purpose for the recording.
If a breach is likely to result in risk to individuals’ rights and freedoms, it must be reported to the ICO within 72 hours of the organisation becoming aware of it. High-risk breaches must also be communicated directly to the affected individuals without undue delay.
Yes, the UK retained and adapted the EU GDPR into domestic law as the UK GDPR, which continues to apply in full. Organisations transferring data between the UK and the European Economic Area must also consider the rules on international data transfers.
The ICO is the UK’s data protection authority and publishes comprehensive, up-to-date guidance at https://ico.org.uk. Their resources cover everything from individual rights to sector-specific advice for healthcare, education, and financial services.
