What is not covered by the General Data Protection Regulation?

GDPR neither covers information of organizations, nor covers anonymized information.

Information of organizations

The General Data Protection Regulation only covers data from individual people, no other data relative to any type of organization is covered by the General Data Protection Regulation.

Anonymized information

In anonymized data all identifying information from data is removed, making it impossible to identify the person. Anonymized data cannot be used for any purpose that requires identifying information. Once anonymized, data is no longer considered personal information and is exempt from General Data Protection Regulation.

Anonymization means that is not possible to identify, directly or indirectly, one person, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, as mentioned in the number 26 of the introduction of the General Data Protection Regulation:

“The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes.”