What is location data under the GDPR?
Location data is personal data when it relates to an identified or identifiable person. GDPR Article 4(1) expressly lists location data among the identifiers that can make a natural person identifiable. The answer therefore depends on context, not on whether a coordinate contains a name.
A device coordinate, route history or location-linked identifier falls within the GDPR when an organisation can single out or identify the person, directly or indirectly. Removing the visible name does not necessarily anonymise it.
Common examples of location data
| Signal | What it can reveal | GDPR point |
|---|---|---|
| GPS coordinates | Precise position and movement | Usually personal when linked to a device or account |
| Mobile cell data | Approximate location and travel | Can identify patterns even without GPS |
| Wi-Fi or Bluetooth observations | Presence near a router, beacon or venue | Persistent device identifiers can single someone out |
| IP address | Network and approximate geography | Article 4 also recognises online identifiers |
| Travel, access or payment records | Where a person entered, travelled or paid | Location may be inferred from another transaction |
Location data is not automatically special-category data
Article 9 does not list location as a special category by itself. However, a location trail may reveal attendance at a clinic, place of worship, political meeting or other activity from which special-category information is inferred. That changes the risk analysis and may require both an Article 6 lawful basis and an Article 9 condition.
What should a controller check?
- Purpose. State why the location is needed.
- Lawful basis. Identify an Article 6 basis before collecting it.
- Necessity. Use the least precise location and shortest retention period that achieves the purpose.
- Transparency. Explain the collection, precision, frequency, recipients and retention.
- Risk. Consider a DPIA where tracking is systematic, large-scale or otherwise likely to create high risk.
- Security. Protect raw coordinates, histories and linked identifiers against misuse.
Three CIPP/E traps
- Pseudonymous is not anonymous. A device ID can still be personal data when re-identification is reasonably possible.
- Approximate can still identify. Repeated coarse locations may expose a home, workplace or routine.
- The inference matters. Ordinary location data may expose sensitive beliefs or health information.
Primary sources
- GDPR on EUR-Lex, especially Article 4(1), Recital 30, Articles 5, 6, 9, 13 and 35.
Reviewed 29 August 2026. This is an independent study aid, not legal advice.
Continue with the CIPP/E study guide or test yourself in the practice exam.
Sources and study method
This independent study material uses the current published CIPP/E outline, active recall, spaced retrieval and scenario practice. Read the full method. Current sources are identified in the article.
Frequently asked questions
Is location data personal data under the GDPR?
Location data is personal data when it relates to an identified or identifiable natural person. Article 4(1) expressly lists location data as an identifier that may make a person identifiable.
Is location data special-category data?
Not automatically. It can become or reveal special-category data when it exposes matters such as health, religion, politics or sexual orientation.
Does an IP address count as location data?
An IP address is an online identifier and may also support approximate location. Whether it is personal data depends on whether a person is identified or identifiable in context.