Skip to main content

Finepost · Notes · Law

personal data

noun · personenbezogene Daten

Personal data are personenbezogene Daten, any information relating to an identified or identifiable natural person, Art. 4 Nr. 1 DSGVO. The everyday phrase persönliche Daten narrows the idea towards private or intimate matters, but the legal term is wide: a name, a number plate, location data or an online identifier all qualify, and the term decides whether the GDPR applies at all.

Which translation, when

Legaldefinition, weitthe breadth: personenbezogene Daten are all information relating to an identified or identifiable natural person, Art. 4 Nr. 1 DSGVO, identifiable directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data or an online identifier; the content need not be private or sensitive, a work email address or a customer number qualifies.
persönlich-Fallethe trap: the everyday rendering persönliche Daten suggests the private and intimate sphere, and a reader can take technical identifiers to fall outside it; since the term is the gateway to the regulation, that narrowing works like a scope decision, taking processing out of the GDPR that the statutory term keeps in, so the fixed rendering is personenbezogene Daten.
Grenze zu anonymthe outer edge: pseudonymised data, attributable to a person only with separately kept additional information, remain personenbezogene Daten, Art. 4 Nr. 5 DSGVO, while truly anonymous information, no longer relating to an identifiable person, falls outside the regulation; conflating pseudonymised with anonymous removes data from the GDPR that the law keeps inside.

Why

Personal data are personenbezogene Daten, and the pair is the load-bearing wall of the whole field, because the term defines the material scope of the regulation: what is personenbezogen is governed, what is not falls outside. Art. 4 Nr. 1 DSGVO draws the term wide, all information relating to an identified or identifiable natural person, and spells the breadth into the text: identifiable directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or factors specific to the person’s physical, physiological, genetic, mental, economic, cultural or social identity. Nothing in that requires the information to be private, sensitive or intimate; a business email address, a customer number or a vehicle registration relating to an individual is personenbezogen. That is why the everyday rendering persönliche Daten is a trap: the adjective persönlich pulls towards the private sphere, and a reader of a translated policy can conclude that log files, identifiers or professional details are not covered, which is a scope error dressed as a word choice. At the outer edge, Art. 4 Nr. 5 DSGVO keeps pseudonymised data inside the term, since they can still be attributed to a person with separately kept additional information, while truly anonymous information falls outside the regulation altogether. So a translation should hold the statutory phrase personenbezogene Daten throughout and resist both the cosy persönliche Daten and any silent slide between pseudonymised and anonymous.

Typical mistakes

  • The statutory term is personenbezogene Daten and it is wide, Art. 4 Nr. 1 DSGVO, so the everyday persönliche Daten narrows the idea towards the intimate sphere and misstates the scope.
  • Identifiers such as names, numbers, location data and online identifiers are expressly inside the definition, so treating only private or sensitive content as covered is wrong.
  • Pseudonymised data remain personenbezogen, Art. 4 Nr. 5 DSGVO, while anonymous information falls outside the regulation, so the two must not be conflated.

What matters

Rendering a privacy policy or data clause, the translation should use personenbezogene Daten wherever the source says personal data, keep the breadth of the definition visible, and hold the line between pseudonymised data, still inside the term, and anonymous information, outside the regulation.

Authority

  1. Art. 4 Nr. 1 DSGVO

What the machine misses

Machine output often renders personal data as persönliche Daten, the everyday phrase that pulls towards the private and intimate sphere. That narrows the gateway term of Art. 4 Nr. 1 DSGVO and invites the reading that identifiers, log data or professional details fall outside the regulation. It can also blur the line between pseudonymised data, still covered, and anonymous information, outside it. The rendering misstates the scope of the GDPR.

See what the machine does with this clause →

Examples

the processing of personal datadie Verarbeitung personenbezogener Daten
special categories of personal databesondere Kategorien personenbezogener Daten
erasure of personal dataLöschung personenbezogener Daten
any information relating to an identified or identifiable natural personalle Informationen, die sich auf eine identifizierte oder identifizierbare natürliche Person beziehen
Checked 30 Jul 2026 finepost.co.uk/notes/personal-data