What Actually Counts as “Personal Data”?
Names and email addresses are personal data. But what about an IP address? Device identifier? Location information? Customer ID?
Founders can underestimate how much personal information moves through a product because they look only at the information users intentionally type into a form.
If you are trying to understand your company’s privacy obligations, the first step is knowing what data you actually have.
What Founders Need to Know
Personal data generally refers to information relating to an identified or identifiable individual, although the precise definition varies by applicable law.
The category can extend well beyond obvious identifiers.
Depending on the information and legal framework, it may include:
- names and email addresses
- phone numbers
- IP addresses
- device or advertising identifiers
- location information
- account or customer identifiers
- online activity
- employment information
- financial information
- information that can be combined with other data to identify someone
Some information may also fall into specially regulated categories of sensitive personal information, which can include certain financial, health, biometric, precise geolocation, identification, or other information depending on the applicable law.
Why does the distinction matter?
Privacy laws may give individuals, sometimes referred to as data subjects, specific rights concerning their personal information. Depending on the law and circumstances, those data subject rights can include rights to access, correct, delete, or receive information about how their data is being used.
What This Looks Like in Practice
Imagine your company operates a productivity app.
When asked what personal data the product collects, the founder says, “Just email addresses. We need them for account creation.”
Then the team looks more closely.
The application logs users’ IP addresses. An analytics provider assigns device identifiers and records how users navigate the product. The billing system contains names and transaction information. Customer support stores conversations tied to individual accounts.
A new mobile feature also collects precise location information when users enable it.
The company’s data picture now looks very different from “just email addresses.”
Then a user asks the company to provide the personal information it holds about them.
Can your team identify which systems contain that person’s information? Does the request cover only the account database, or could relevant information also exist in analytics, support, billing, and other systems?
Understanding what counts as personal data changes the question from “What fields are on our signup form?” to “What information about an individual exists across our product and vendors?”
Three Common Founder Mistakes
- Looking only at information users type in. Products can collect information automatically through infrastructure, analytics, cookies, and other technologies.
- Assuming identifiers have to reveal someone’s name. Information may still relate to an identifiable person even when a name is not attached to it.
- Treating all personal information the same way. Certain categories can create additional obligations or risks.
10-Minute Founder Self-Check
Pick one user and imagine tracing their information across your business:
- What information do they provide directly?
- What does the product collect automatically?
- What identifiers are assigned to them?
- Do analytics tools collect information about their activity?
- Do payment systems hold information about them?
- Does customer support store their communications?
- Do we collect location, financial, biometric, health, or other potentially sensitive information?
- Which vendors receive information connected to that person?
- Could we locate their information if they exercised a privacy right?
What to Do Next
Do not begin your privacy review with assumptions about what “counts.”
Inventory the information your product and vendors actually collect, then determine how the relevant privacy rules apply to it.
Download Primum Law Group’s Data Mapping Worksheet to document what your product collects, where the information goes, and who has access to it.