Much like the Data Protection Act 1998, GDPR applies to personal data. The current Data Protection Directive defines personal data as:
"Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity."
However, GDPR expands this definition slightly by explicitly including online identifiers such as IP addresses as personal data.
🔐 Sensitive Personal Data
GDPR refers to sensitive personal data as “special categories of personal data” which uniquely identify a person. This includes:
Genetic data
Biometric data
These categories require additional protection due to their sensitive nature.