[LT-06]
The Quasi-PII Problem
GDPR Article 4 defines personal data as "any information relating to an identified or identifiable natural person." The key word is "identifiable" — not just currently identified, but capable of identification through additional processing. A value that is not directly identifying but can be linked to a real person through internal systems is personal data under GDPR.
Internal employee IDs are the most common example. "EMP-EU-123456" does not directly identify anyone....