Define: Personal Information
In a contract, Personal Information refers to any data that identifies or could identify an individual, such as names, contact details, financial identifiers, or health and employment records. Contracts define this term to establish which data is subject to privacy obligations, confidentiality duties, and applicable data protection law, including how it may be collected, used, shared, or destroyed.
Legal accuracy standard set & glossary spot-checked by Imad Mohammed Nazar , Skadden-trained M&A lawyer, Legal Engineer at GenieAI
What Personal Information Means in a Contract
Personal Information is a defined term used in contracts to identify the category of data that triggers privacy, security, and confidentiality obligations between the parties. When a contract uses this term, it is signaling that specific handling rules, such as restrictions on disclosure, retention limits, or breach notification duties, apply to any data falling within the definition. Without a clear definition, parties risk disputes over whether particular data, such as an IP address or an employee ID number, is covered.
The term typically appears in agreements where one party collects, processes, stores, or transmits data belonging to the other party's customers, employees, or other individuals. Because Personal Information often carries regulatory significance under the law governing the contract, its definition anchors compliance obligations throughout the agreement, from security standards to indemnification for mishandling.
Understanding this term matters not just for compliance teams but for anyone drafting or reviewing a contract that involves the exchange of data about identifiable individuals, since the scope of the definition directly shapes the parties' risk exposure.
How Personal Information Is Defined or Measured
Contracts generally define Personal Information by reference to categories of identifiable data rather than a fixed numerical measure. Common categories include name, address, phone number, email, date of birth, financial account numbers, government identification numbers, and health or education records. Some agreements also include indirect identifiers, such as device identifiers or location data, that could be combined with other information to identify a person.
The scope of the definition can vary significantly depending on the industry and the applicable law governing the contract. A healthcare agreement, for example, may define the term broadly to include medical history and treatment details, while a retail agreement may focus narrowly on purchase history and payment details. Parties should consider:
- Whether the definition includes information about employees as well as customers or third parties
- Whether pseudonymized or aggregated data is excluded from the definition
- Whether the definition aligns with terminology used in a related Data Processing Agreement or similar instrument
Because there is no single universal definition, the contract's own wording controls how the term is measured and applied in practice.
Where Personal Information Appears in Agreements
Personal Information appears in a wide range of contract types, including employment agreements, service contracts, vendor agreements, and licensing arrangements. It is especially prominent in agreements governing outsourced data processing, where one party handles data on behalf of another, as well as in confidentiality and non-disclosure clauses that carve out special treatment for identifiable data.
The term also surfaces in policies and procedures referenced by contracts, such as a Data Protection Policy or a Data Breach Notification Procedure, which set out how a party must respond if Personal Information is compromised. Industries such as healthcare, finance, and technology tend to include especially detailed definitions given the sensitivity and volume of data they handle.
Beyond core commercial contracts, the term appears in ancillary documents like impact assessments, consent notices, and internal governance frameworks, all of which rely on a consistent understanding of what counts as Personal Information.
Why the Exact Wording Matters
The precise wording of a Personal Information definition determines the practical scope of a party's obligations. A narrow definition may exclude data types that later prove sensitive, leaving gaps in protection, while an overly broad definition may impose unnecessary compliance burdens on data that carries little risk. Ambiguous wording can also create disputes during a data breach, when parties must quickly determine whether the compromised data falls within the contract's protections.
Exact wording also affects how obligations interact with other clauses, such as indemnification, liability caps, and audit rights. If a breach involves data that sits at the margin of the definition, the parties' rights and remedies may become uncertain, potentially requiring costly negotiation or litigation to resolve. For example, a mismatch between a contract's definition and requirements described in resources like this guide to drafting a DPA with vendors handling personal data can leave compliance gaps unaddressed.
Drafting Considerations
When drafting or reviewing a Personal Information clause, parties should ensure the definition is specific enough to provide certainty but flexible enough to account for evolving data types and technologies. It is often useful to include illustrative examples alongside general categories, and to clarify whether the definition covers information in any format, including paper records and electronic data.
Drafters should also confirm consistency between the definition used in the main agreement and any related documents, such as a Data Protection Addendum, to avoid conflicting obligations. Consideration should be given to how the definition interacts with retention, deletion, and cross-border transfer provisions, since these obligations typically hinge on whether data qualifies as Personal Information.
Finally, parties should revisit the definition periodically, particularly when business operations expand into new industries or jurisdictions, to ensure it remains aligned with current practices and the law governing the contract.
Relevant Circumstances
- Onboarding new employees
- Engagement with third-party service providers
- Formulating new partnerships and collaborations
- Implementation of data protection strategies
- Drafting of company privacy policies