Personal Data vs Sensitive Data – Understanding the Difference

At the heart of the GDPR (General Data Protection Regulation) is the subject of ‘personal data’.

But what is personal data? Are names and email addresses classified as personal data? What about photographs and ID numbers? What about business data?

And where does ‘sensitive personal data’ fit in? Officially it is known as ‘Special Category Data’.

If you’re unsure of the difference between personal and sensitive data, keep reading. We explain everything you need to know and provide examples of personal and sensitive personal data.

Personal Data

Simply put, personal data is any piece of information that someone can use to identify, with a degree of accuracy, a living person.

For example, the email address [email protected]” is considered personal data, because it indicates there can only be one John Smith who works at Company 123. However, in isolation that is not necessarily the case, as there might be a jsmith@ or johns@ etc.

Likewise, your physical address or phone number is considered personal data because you can be contacted using that information. However, it doesn’t necessarily identify you.

Personal data is also classed as anything that can affirm your physical presence somewhere. For that reason, CCTV footage of you is personal data, as are your fingerprints.

Simple eh?

This is the GDPR so no, not really. However, things become complex when each piece of information isn’t taken independently. 

Organisations typically collect and store large amounts of information on each data subject. The sum of that information can be considered personal data if it can be pieced together to identify a likely data subject. But, how many pieces are needed to complete the picture?

Imagine a jigsaw of your personal data.

There are many pieces, some more important than others. The cyber criminals do not have a box with a picture to refer to. Let’s look at the pieces.

Under certain circumstances, any of the following can be considered personal data:

  • A name and surname – even better, middle name or names
  • A home address
  • An email address – work and personal
  • An identification number – National Insurance, driving licence or a passport number
  • Location data
  • An Internet Protocol (IP) address
  • The advertising identifier of your phone

The ICO (Information Commissioners Office) explains it’s not that simple:

“By itself the name John Smith may not always be personal data because there are many individuals with that name. However, where the name is combined with other information (such as an address, a place of work, or a telephone number) this will usually be sufficient to clearly identify one individual.”

However, the ICO also notes that names aren’t necessarily required to identify someone:

“Simply because you do not know the name of an individual does not mean you cannot identify [them]. Many of us do not know the names of all our neighbours, but we are still able to identify them.”

What is sensitive data?

Sensitive personal data, also known as special category data, is a specific set of “special categories” that must be treated with extra security. This can also be referred to as protected characteristics.

List of Special Category Data (Article 9 – GDPR)

  • Racial or ethnic origin;
  • Political opinions;
  • Religious or philosophical beliefs;
  • Trade union membership;
  • Genetic data;
  • Data related to a person’s sex life or sexual orientation; and
  • Biometric data (where processed to uniquely identify someone).

Sensitive personal data should be held separately from other personal data, preferably in a locked drawer or filing cabinet. If held electronically, it must be held on a separate system and properly secured.

As with personal data generally, it should only be kept on laptops or portable devices if the file has been encrypted and/or pseudonymised.

Since the arrival of the GDPR, consent has been misunderstood and often demanded when not needed.

In fact, consent is only one of six lawful grounds for processing personal data. The strict rules regarding lawful consent requests make it the least preferable option.

However, there will be times when consent is the most suitable basis. Organisations need to be aware that they need explicit consent to process sensitive personal data.

Nuances like this are common throughout the GDPR. Any organisation that hasn’t taken the time to study its compliance requirements thoroughly is liable to be tripped up.

This could lead to lasting damage, such as enforcement action, regulatory fines, bad press and loss of customers.

If you need help understanding the different types of data and how to record and manage this data, please get in touch.