Personal, or Not?
Twelve things a system holds. One call each: is it personal data? The expensive mistake is never the over-call — it is the confident no on something that identifies a person the moment two tables are joined.
1. A SHA-256 hash of a customer's e-mail address, stored beside their order history.
2. An IP address in your public website's access log.
3. Yesterday's visitor count from Riyadh: 4,182.
4. A device advertising ID from a phone the whole family shares.
5. A CCTV still in which the only person is blurred past recognition.
6. An employee number in a spreadsheet with no name column anywhere in the file.
7. A survey UUID whose link table was destroyed, verifiably and irrecoverably.
8. The registration plate of a company van.
9. A supplier's registered company number and VAT registration.
10. A model output: this account is 87% likely to be pregnant.
11. Latitude and longitude to five decimals, timestamped, from one phone.
12. A MAC address broadcast by a laptop hunting for Wi-Fi in a shopping centre.
13. A deceased customer's full medical history.
Answers follow GDPR / UK GDPR — Recital 26 on pseudonymisation, Breyer (C-582/14) on dynamic IPs, Article 9 on inferred health data, Recital 27 on deceased persons. Educational, and not legal advice: your own regulator and national law decide the close ones.