3 ms·
We're talking past each other here. The definition of personal data is "any information that relates to an identified or identifiable living individual [...] d
by eivarv 6y ago
We're talking past each other here.
The definition of personal data is "any information that relates to an identified or identifiable living individual [...] directly or indirectly"
This says nothing about being linked. It's about whether the candidate can be theoretically identified. This includes both _any_ information unique enough (having enough entropy, in the information theory -sense of the word) in and of itself, as well as information that can identify the data subject in combination with other data.
In summary: Whether a piece of data constitutes "personal data" is not dependent on "whether an individual is identifiable" from that isolated piece of data itself.
The concept is thus much broader, and totally different from Personally Identifiable Information (PII).
- mytailorisrich 6y agoI used the word "linked", fine, I could have used "relate". I think "linked" is clearer because that what "relate" means in the context. > Whether a piece of data constitutes "personal data" is not dependent on "whether an individual is identifiable" from that isolated piece of data itself. Neither I not the GDPR claim that the person must be identifiable by the piece of data in itself, but rather that the person must be identifiable by the data the controller possesses or can have access to. That's the definition and the opinion of the ECJ on the matter (I linked a summary), and also what all the articles linked to in our discussion say. For example, if I take a hospital database of all patients and their blood types, the blood types relate to (are linked to) identifiable individuals: They are personal data. Now, I extract those blood types and go home with a list of blood types and nothing more. Now they are anonymous, they no longer relate to identified or identifiable individuals (I cannot know whom they relate to, they are no longer linked to identifiable individuals). Therefore, they are no longer personal data. The same holds for IP addresses. In general, I cannot identify individuals if I only have IP addresses. That's why my point, and the legal position, is that IP addresses in themselves are not personal data. You need to consider a specific case and scenario to determine if they are personal data in that specific case. Note that this is law, not science. "Theoretically identified" is not a legal concept. "Reasonably identified" is. Can an IP address at time t identify an individual? Yes. But in practice can the owner of a website reasonably make that connection? No, unless the individual has provided further information about themselves (see ECJ case). Again, and in conclusion: The statement "IP addresses are personal data" is a shortcut and is not correct, though it can be used as a matter as good practice. The correct statement of the law is: "IP addresses can be personal data depending on the circumstances".