Spotting Personal Data Everywhere

The Morning Spreadsheet Trap

Imagine you’re starting your Monday morning as the office hero, organizing a team lunch. You create a quick spreadsheet with names, birthdays, and dietary requirements.

In the eyes of the GDPR, you haven't just made a list—you’ve created a database of personal data.

Imagine you’re starting your Monday morning. You decide to be the 'office hero' and organize a team lunch. You create a quick spreadsheet with everyone’s names, their birthdays, and their dietary requirements. It feels like a helpful, everyday task, right? But in the eyes of the GDPR, you haven’t just made a lunch list—you’ve created a database of personal data. If this file is saved on a public drive or emailed to the wrong person, it could lead to a data breach.

What Exactly is Personal Data?

Think of personal data as a trail of digital breadcrumbs. Any piece of information that can identify a living person—either on its own or when combined—counts.

You don't need to be a lawyer to get this right. Think of personal data as any piece of information that can be used to identify a living person. It’s like a trail of digital breadcrumbs that leads back to a specific individual. Sometimes it's direct, like a name. Other times, it's indirect, like an ID number or a location. Each piece of data adds a layer of identity. When you combine them, the individual becomes clearly identifiable.

Obvious vs. Hidden Data

Personal data isn't just names and addresses. It includes work-related details and hidden identifiers like IP addresses.

Let's break down the types of data you handle daily. First, we have the obvious ones: names and home addresses. Then, there's work-related data. Yes, business emails like j-smith at company dot com still count! Finally, there's hidden data like IP addresses or location data from a company phone.

Broad and Surprising Examples

The definition of personal data is wider than most realize. Common office items like birthday calendars and customer lists are strictly protected.

Some examples often catch employees off guard. A shared birthday calendar is a great team-builder, but it contains specific birth dates—that's personal data! Similarly, a simple list of 'Active Clients' with names and roles is protected. Sharing these via an unencrypted chat app is a major no-no.

What Would You Do?

You are moving to a new department and want to take a list of your 50 most successful leads (names and phone numbers) to show your progress. Is this okay? Practice explaining your reasoning to the Data Protection Officer (DPO).

You're about to switch departments and want to bring your lead list with you. You've reached out to the Data Protection Officer to ask if this is okay. How would you justify or ask about this move?

Spot the Personal Data

Examine this internal email draft. Click on all pieces of personal data you can find before the email is sent.

Before this email goes out, we need to be vigilant. Look at this draft carefully. Click on every piece of information that counts as personal data. Great job! You identified the name, the business email, the employee ID, and even the dietary requirement. All of these together make this a sensitive document.

The Personal Data Filter

Before you hit 'send' or 'save,' run your data through this three-question checklist.

To stay safe, use the 'Personal Data Filter'. Question 1: Identification. Can I tell exactly who this is about? Question 2: Context. Does the information tell me something about that person, like their role or a preference? And Question 3: Combination. If I combine this with other info, could I identify them? If you answer 'Yes' to any of these, follow protocol or ask your DPO.

Human Error: Our Biggest Risk

Most leaks aren't from hackers; they happen because of human error. A simple mistake like using CC instead of BCC can expose an entire customer list.

It’s a surprising fact: most data leaks aren't caused by hackers. They happen because of human error. Imagine accidentally CCing a whole customer list instead of BCCing them. Everyone now has everyone else's email address. Being vigilant and double-checking your recipients is your best defense.