All articles
19. 9. 2018
1 min read

Even data without a birth number or name and surname are personal data under the GDPR

According to the GDPR, personal data is any information about an identified natural person. So it includes data that can be indirectly linked to a specific person.


You may have thought that if you remove data such as birth number or name from your database, you’re all set. Unfortunately, it’s not that simple. According to the GDPR, personal data is any information about an identified natural person. So this includes data that can be indirectly associated with a specific person.

So if you have personal information about an employee in your records such as age, education, qualifications, salary level, it is still personal data even if you remove the direct identifiers.

In practice, even data that the controller modifies, for example by a technique known as hashing, is personal data. Although no direct identifiers are contained thanks to this technique, the moment the controller passes it on to a third party, this data is again treated as personal data. Does this seem nonsensical to you? Not quite. Because the administrator is still able to make a retrospective identification based on the original data. If the controller removes the original data, then it will be pseudonymised data that is protected by a security measure, which means a significant reduction in risk, but still subject to GDPR.

The only way a controller can exempt certain data from the GDPR regime is by anonymising it. The data must be redacted in such a way that it cannot be associated with a specific individual.

Do you want to make sure you are handling your data correctly and following everything you need to be GDPR compliant? Our team is here for you!

Have a project?

Get in touch and we'll discuss how we can help.
Contact us

More articles

1 Aug 2026

Cyber Resilience Act: New Rules for Secure Software and Digital Products

The European Union is introducing another important regulation in the field of cybersecurity. It is called the Cyber Resilience Act, or CRA for short, and applies to all products with a digital component. This means not only smart devices, but also software, applications, and systems that connect to a network or communicate with another service…
Read the article
15 Jul 2026

Withdrawal button – Wontilles responds in advance to new legislative requirements

The legislative environment in the field of e-commerce is undergoing constant changes, which place high demands on online shop operators.
Read the article
1 Jun 2026

Railsformers at the Faculty of Arts at the OU: Ruby on Rails in practice and now also in IT business

At the Faculty of Science of the University of Ostrava, we have long been giving students practical experience with Ruby on Rails development and showing them what it looks like to work on real web applications. From the original pilot course, we have developed a stable course Ruby on Rails I and II, which we…
Read the article