Under the UK and EU GDPR (General Data Protection Regulation), organisations are required to protect a wide range of data — but not all personal data is treated equally. A critical distinction exists between personal data and special category data (formerly known as sensitive personal data), and understanding the difference is vital for ensuring your organisation’s compliance.
As enforcement actions continue to rise in 2025 — with fines regularly exceeding millions of pounds — failure to distinguish between these categories can lead to disproportionate risk exposure, reputational harm, and even criminal liability.
Let’s break down what qualifies as personal data vs special category data, when each applies, and how to handle both responsibly in today’s regulatory landscape.
What is personal data under the GDPR?
Article 4(1) of the GDPR defines personal data as:
“Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly…”
This includes:
- Name
- Email address (especially work emails like [email protected])
- Telephone number
- IP address
- Employee ID or customer ID
- Location data
- Cookies (when tied to identifiable users)
- Photos or CCTV footage
Essentially, any information that can be linked to a living individual — even indirectly — is considered personal data.
For example, a hotel chain using facial recognition to streamline check-ins must treat the collected biometric data as personal data at a minimum – and, depending on use, possibly special category data too.