Personal Data Essentials
Recognise personal data before you handle it. The Article 4(1) definition and the online identifiers people assume are anonymous, the Article 9 special categories that hide in free-text notes, and the controller, processor and third-party split.
What Is Personal Data Essentials?
Most privacy incidents do not start with an attacker. They start with an employee who did not recognise that the file in front of them was personal data, or who assumed a long-standing vendor was already covered by the company's contracts. This exercise builds the vocabulary that prevents both. A new starter at an online marketplace works through the company's privacy foundation module, then applies it immediately to a real recruiting export: a candidate longlist carrying an application IP and device identifier column nobody asked for, and free-text recruiter notes holding health data and trade union membership. The learner identifies what the regulation actually counts as personal data under Article 4(1), separates the Article 9 special categories from data that merely feels sensitive, works out whether each recipient is a processor or a separate controller, and replies to the recruiter with an assessment that routes the real decision to the Data Protection Officer.
What You'll Learn in Personal Data Essentials
- Apply the Article 4(1) definition of personal data, including the indirect identification test and pseudonymised records
- Recognise online identifiers such as IP addresses, device IDs, cookie identifiers and location data as personal data
- Distinguish the closed Article 9 list of special categories from commercially sensitive data that falls outside it
- Spot special-category data that arrives inferred from free-text notes, attachments and photographs
- Assign the controller, processor and third-party roles under Article 4(7) to (10) and explain what changes when data leaves the organisation
- Route a request that carries a privacy question to the Data Protection Officer instead of deciding it at your desk
Personal Data Essentials — Training Steps
-
Access on Hold
Marktvel runs a marketplace with millions of listings, which means almost every internal tool touches someone's personal data. Your request for access to the customer records system came back with a condition attached: the privacy foundation module has to be completed first. It is not a formality. Most privacy incidents at companies like this one start with somebody who genuinely did not know that what they were handling counted as personal data.
-
A Note From the DPO
Ines Haller, the Data Protection Officer at Marktvel, has sent the enrolment mail with the portal link.
-
Opening the Portal
The module sits on the internal privacy portal.
-
Signing In
The portal uses your regular Marktvel work account.
-
What the Law Calls Personal Data
Section one opens with the definition from Article 4(1), and then with the part that catches people out: the list of things that are personal data even though they carry nobody's name. The test is not whether you can look at a value and see a person. The test is whether the person can be singled out from it, by anyone, using means reasonably likely to be available.
-
The Analytics Export
A colleague on the growth team wants to share a raw traffic export with an outside consultant. He tells you it is fine to send without any approval because the file contains no names, no email addresses and no account numbers, only IP addresses, device identifiers and timestamps.
-
The Categories That Need More Care
Section two covers Article 9. A short list of categories is treated as inherently riskier, because getting it wrong exposes people to discrimination rather than inconvenience. Processing this data is prohibited by default. It becomes lawful only when one of the narrow exceptions in Article 9(2) applies, which is a much higher bar than the ordinary legal bases.
-
Who Is Responsible for What
Section three is the one that decides what you are allowed to do when another company is involved. The GDPR splits the roles by who decides, not by who holds the data. Marktvel is the controller for its customer and candidate data. Everyone else is either processing on Marktvel instructions, or acting for their own purposes, and the difference changes what has to be in place before data moves.
-
A Request From the Vendor
The module closes section three with a scenario drawn from a real support ticket. Hirelane, the applicant tracking system Marktvel uses, has written to several customers proposing to use the candidate records already in its platform to train and improve its own matching algorithm, at no extra cost.
-
The Module Meets Real Work
The module is done. Within the hour the theory turns into an actual request. Tomas Brandl in Talent Acquisition is running the backend engineer hire and wants to move the longlist along. He has attached the export and asked you to pass it to two places.