Personal information
From The IT Law Wiki
[edit] Definition
Personal information is any recorded information about an identifiable individual, such as a person’s religion, age, financial transactions, medical history, address, or blood type. The term includes both identifying personal information and nonidentifying personal information.
[edit] EU Data Protection Directive
Under the EU Directive on the Protection of Personal Data, personal information is "[a]ny information relating to an identified or identifiable natural person ('data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity."[1]
This definition is meant to be broad. The principles of protection must apply to any information concerning an identified or identifiable person. In order to determine whether a person is identifiable, account should be taken of all the means reasonably likely to be used either by the controller or by any other person to identify the said person. Some examples of “personal data” are a person’s address, credit card number, bank statements.[2]
[edit] References
- ↑ EU Directive on the Protection of Personal Data, Art. 2(a).
- ↑ See Opinion No 4/2007 on the concept of personal data issued by the Article 29 Working Party (WP 136).
