Personal data: why it matters for EU small businesses
"I only collect name and email, so I don't process personal data."
That's the reaction I often get when barely mentioning that I help small businesses handle personal data in a compliant way.
And that’s the first signal the person I am talking to might be getting things wrong, unknowingly.
I get that name and email are the kind of information people share publicly all the time. But that doesn't make them any less personal data according to the privacy laws and authorities. That’s why small businesses that handle this or similar information need to be aware of how they might be processing it.
That’s required by law, expected by customers and partners alike, and useful for limiting damage if issues ever arise.
Definition of personal data
In the EU, personal data is defined by the General Data Protection Regulation (GDPR).
Simply put, the GDPR describes personal data as any information that identifies, or could identify, a living individual. Legally speaking, the living individual is called a data subject.
Now, coming back to our example, this description makes it immediate to identify information such as name and surname as personal data, because these identify a living individual directly.
But there's actually more to it.
The GDPR's definition also covers all those data which, when combined with other information, could make the data subject identifiable (i.e. indirectly).
Let’s take an email address as an example to clarify the difference between direct and indirect identification.
An email address structured as name.surname@domain.ext is personal data that identifies a living individual directly.
A random email address like dgwq@domain.ext, instead, doesn’t allow for identifying an individual directly. However, it could contribute to doing that indirectly when combined with other data, such as the name and surname provided to create the email account.
Examples of personal data
I am aware that the above paragraph might have opened a whole Pandora’s box of data that could be defined as personal under GDPR.
To save you some research, here are some examples of information that fall under the personal data umbrella:
name
physical address
email address
telephone number
photo
camera images on which someone can be recognised
sound recordings on which someone can be recognised
IP address
national identification number
a cookie ID and personal data gathered via cookies
the advertising ID of a digital device
bank account number
information about what someone does or buys on the internet
customer or employee number
Please note that this list is not comprehensive and only mentions examples of ordinary personal data, the most common category of personal data.
The GDPR also identifies other categories, for which additional rules are set. I'll cover these categories in a separate article soon.
Follow FRA on LinkedIn or visit FRA’s Articles & News to find out more.
Misconceptions around personal data
The previous paragraphs touched on some of the most common misconceptions I run into when talking to small businesses about personal data.
But there are several of them, and they rarely come one at a time. They're also frequent enough to have become deeply rooted, which makes them even harder to spot in your own business.
I’ve already detailed the direct vs indirect distinction earlier in this article. So I’d like to surface the others more explicitly here.
Living individual vs legal identity: even data that looks like it belongs to a business can be personal data.
For example, a company email address built from someone's own name or used by just one employee still identifies a real person behind it.
Publicly available vs non-publicly available: the legal definition of privacy and personal data is often mixed up with the general concepts of private, reserved or even secret. This misconception often generates the belief that if information is made public, it is not personal data.
Taking the same case we started from as an example, even if a person posts his/her name publicly online, this information is still his/her personal data and requires businesses to treat it according to privacy laws.
High risk information vs low risk information: similarly to the previous case, information that is commonly shared is perceived as low-risk for the data subject and, therefore, not as personal data governed by laws.
This is incorrect. The level of risk of each type of personal data determines how it needs to be handled (e.g. security measures). But that’s a separate consideration, and personal data are defined as such regardless of the level of risk.
Personal data handled knowingly vs unknowingly: many small businesses aren't fully aware of which personal data they handle and how.
One reason for that is that some processes, like data collection through cookies for example, happen underneath user-friendly interfaces, and are therefore invisible to the non-technical eye.
Another reason is that those processes are often mentioned in terms and conditions, data processing agreements, and all those long, dense documents often accepted without reading.
Handling personal data doesn’t mean infringing the law: I believe this myth is the worst of all, because it often prevents entrepreneurs from taking action or asking for professional help.
Suddenly realising that personal data are actually handled often brings up two fears: doing something wrong, and damaging the business by surfacing it.
But the issue isn't handling personal data. The issue is not knowing which personal data are processed and how. And that’s also the first question any authority is going to ask in case of a data leak, a complaint or any other issue.
So the best way to protect your business is not to ignore the problem, but to arm yourself with the right visibility on your business operations to own them intentionally.
Book a free call to learn how FRA can help you identify the personal data processed by your business and how to manage them better.