Personal information is any information about an identifiable individual. Under Canadian privacy law, this definition is intentionally broad.

What Counts as Personal Information

Personal information includes obvious items like name, address, phone number, email, and date of birth. But it also includes:

  • IP addresses and device identifiers
  • Location data and GPS tracks
  • Browsing history and online behaviour
  • Photographs and video recordings
  • Biometric data (fingerprints, facial recognition)
  • Health and medical information
  • Financial information
  • Employee records
  • Opinions and views expressed about a person
The Identifiability Test

Information is personal if it can be used to identify an individual, either alone or in combination with other information. A postal code alone may not identify someone, but a postal code combined with age and gender might. This is why combining datasets can create privacy risks even when individual datasets seem harmless — a concept called the aggregation problem.

Sensitive Personal Information

Some categories of personal information are considered especially sensitive and warrant extra protection: health information, financial information, ethnic or racial origin, political opinions, religious beliefs, sexual orientation, and biometric data. These categories appear in both PIPEDA and Quebec's Law 25, which requires explicit consent for collecting sensitive information.

Business Contact Information

Under PIPEDA, business contact information used for business purposes — name, title, business address, phone number — is generally not considered personal information. However, the same information used in a personal context may be. A business email address used to send marketing messages to an individual in their personal capacity may trigger privacy obligations.

Anonymization and De-identification

Removing obvious identifiers like name and address does not always make data non-personal. Re-identification attacks have shown that seemingly anonymous datasets can be linked back to individuals using publicly available information. True anonymization requires careful analysis and often statistical techniques like k-anonymity or differential privacy.

Key Takeaways

  • Personal information is any data that can identify an individual, directly or indirectly
  • The definition is broad — location data, device IDs, and behaviour all qualify
  • Combining non-personal datasets can create personal information
  • Sensitive categories require heightened protection and explicit consent
Next Step

Learn about collecting only what you need in Data Minimization.

← Privacy Fundamentals Data Minimization →