Skip to main content
Category: Data Classification & Identifiers

Behavioural Data

Also known as: Behavioral Data, User Behavioural Data, Consumer Behaviour Data
Simply put

Behavioural data is information that reflects the actions of an individual, such as what they do when interacting with a website, app, or business across different channels. It can also capture patterns of human behaviour more broadly, for example physical activity, sleep, or dietary habits. In most cases, where behavioural data relates to an identified or identifiable individual, it will be treated as personal data and subject to data protection law.

Formal definition

Behavioural data refers to information generated by and reflecting the observable actions of an individual, typically collected as they interact with digital services and other channels (e.g. clicks, page visits, transactions) or as recorded aspects of human behaviour such as physical activity, sleep patterns, or dietary habits. From a data protection perspective, the classification is context-dependent: where such data relates to an identified or identifiable natural person, it generally falls within the scope of 'personal data' and its processing requires an applicable lawful basis; where it is genuinely anonymous, it will generally fall outside that scope, subject to assessment of re-identification risk. Behavioural data is not a defined term in the GDPR text itself; the evidence here derives from technical and industry sources, so practitioners should assess each dataset against the applicable statutory definitions rather than relying on a generic label. Note that certain behavioural inferences may reveal special category information under Article 9, requiring an additional condition, and this should be evaluated case by case.

Why it matters

Behavioural data sits at the centre of modern digital services, because information reflecting what people do, such as their clicks, page visits, transactions, and interactions across channels, is routinely collected to understand and predict how individuals engage with businesses. Where this data relates to an identified or identifiable individual, it will in most cases be treated as personal data and fall within the scope of data protection law, meaning its collection and use require an applicable lawful basis and appropriate transparency. This distinguishes behavioural data from anonymous information, though whether a dataset is genuinely anonymous requires assessment of re-identification risk rather than reliance on the label alone.

The compliance significance of behavioural data is heightened because patterns of action can reveal more than they first appear. Behavioural inferences may, in some cases, disclose special category information within the meaning of Article 9, for example where activity, sleep, or dietary habits point to health status. Where that occurs, processing generally requires an additional Article 9 condition beyond an Article 6 lawful basis, and this must be evaluated case by case. Because behavioural data is not itself a defined term in the GDPR, practitioners should not assume a fixed regulatory treatment and should instead assess each dataset against the applicable statutory definitions.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to determine when behavioural datasets amount to personal data and, where they do, identify the applicable lawful basis. They should be alert to behavioural inferences that may reveal special category information under Article 9, which would generally require an additional condition, and should assess re-identification risk before treating any dataset as anonymous.
Privacy and Technology Lawyers
Because behavioural data is not a defined term in the GDPR text, lawyers advising on it should map each dataset against the applicable statutory definitions rather than relying on the industry label. Advice should reflect that classification is context-dependent and that member state and UK GDPR positions may differ, so conclusions should be verified against the current applicable law.
Engineers and Product Teams
Those building websites, apps, and analytics pipelines generate behavioural data through the actions people take across channels. They should understand that collecting clicks, visits, and transactions linked to an identifiable individual generally triggers data protection obligations, and that design choices around identifiers and aggregation affect whether data is treated as personal or genuinely anonymous.
Marketing and Analytics Functions
Teams using behavioural data to understand customer actions across channels rely on it for insight, but should recognise that its use is subject to data protection requirements where it relates to identifiable individuals. Consent is not a universal requirement, and the appropriate lawful basis, along with any Article 9 considerations for inferred sensitive information, should be assessed for each use case.

Inside Behavioural Data

Observed activity data
Information generated by monitoring how an individual interacts with a service, device, or environment, such as clicks, page views, navigation paths, scroll depth, dwell time, and purchase or transaction history. Where such data relates to an identified or identifiable natural person, it is personal data within the scope of the GDPR.
Derived and inferred attributes
Characteristics, preferences, or predictions inferred from observed behaviour, for example interest categories, propensity scores, or predicted intent. Inferences about a person generally constitute personal data, and depending on their nature and use they may amount to profiling.
Identifiers and tracking signals
Elements used to link behavioural events to a person or device over time, such as cookie identifiers, device identifiers, and similar online identifiers. These are typically treated as personal data where they can single out an individual, and their use is often subject to national ePrivacy implementing rules in addition to the GDPR.
Context of collection
The circumstances in which behaviour is recorded, including whether the individual is a customer, website visitor, employee, or app user, and whether monitoring is systematic. Context is relevant to identifying the appropriate Article 6 legal basis and to assessing whether a Data Protection Impact Assessment under Article 35 may be required.
Profiling potential
Behavioural data is frequently used to build profiles. Where processing amounts to automated processing to evaluate personal aspects, the profiling concept and, in some cases, provisions on automated decision-making may be engaged. Whether these apply depends on the specific processing and should be assessed case by case.

Common questions

Answers to the questions practitioners most commonly ask about Behavioural Data.

Is behavioural data automatically exempt from the GDPR because it does not include names or direct identifiers?
No. Behavioural data typically constitutes personal data where it relates to an identified or identifiable individual, and identifiability can arise indirectly through online identifiers, device signals, or the combination of data points, even without a name. Whether a given dataset falls outside the GDPR generally depends on whether it is genuinely anonymous, which is a high threshold assessed against the risk of re-identification. Pseudonymised behavioural data remains personal data. The position should be assessed case by case rather than assumed from the absence of direct identifiers.
Does processing behavioural data always require the individual's consent?
Not necessarily. Consent is one of several legal bases under Article 6, and it is not a universal requirement. Depending on the context, other bases such as legitimate interests or contract may be relevant, subject to assessment. However, the collection of behavioural data through cookies or similar technologies on a user's device is generally governed by separate ePrivacy rules, which in many cases require consent for non-essential access to or storage of information on the device. Where behavioural data reveals special category information under Article 9, an additional condition is needed. The correct basis should be determined for each processing activity.
How should we document the legal basis for processing behavioural data?
In most cases, the legal basis should be identified and recorded before processing begins, typically within your records of processing and internal assessments. Where you rely on legitimate interests, a legitimate interests assessment balancing your purposes against the individual's rights and reasonable expectations is generally expected. Where consent applies, retain evidence of a valid, informed, and freely given consent. Because the applicable basis is context dependent and may differ across use cases, document each purpose separately rather than applying a single basis across all behavioural processing.
When might a Data Protection Impact Assessment be needed for behavioural data processing?
A DPIA under Article 35 is generally required where processing is likely to result in a high risk to individuals, and behavioural data used for systematic monitoring, profiling, or tracking can fall within that category, subject to assessment against the criteria and any list published by the relevant supervisory authority. Regulator guidance on when a DPIA is mandatory can vary between member states, so the applicable national list should be checked. Conducting a DPIA before processing, and revisiting it as processing changes, is generally advisable where the risk profile is uncertain.
How do we handle behavioural data collected through third parties such as analytics or advertising vendors?
The roles of each party should be characterised precisely, as this determines the applicable obligations. A vendor acting on your instructions is generally a processor, in which case a data processing agreement under Article 28 is typically required; a vendor determining its own purposes may be a controller or joint controller, which carries different responsibilities. Where behavioural data is disclosed to or received from another party, the basis and transparency information should reflect the actual arrangement. Any transfer of such data outside the relevant jurisdiction should be assessed against the applicable transfer mechanisms, which evolve over time and should be verified against current requirements.
How do transparency and individual rights apply to behavioural data?
Individuals should generally be provided with clear information about how their behavioural data is collected and used, typically at or before the point of collection, in line with the transparency obligations. Individual rights, such as access and objection, can apply to behavioural data where it constitutes personal data, and the availability and scope of a given right depends on the legal basis relied upon and the circumstances. Where profiling or automated decision-making is involved, additional considerations may apply. The practical mechanics of responding to requests should be built into your processes and assessed case by case.

Common misconceptions

Behavioural data is not personal data because it does not include names.
The absence of a direct identifier such as a name does not remove data from scope. Where behavioural data relates to a person who is identified or reasonably identifiable, including through online identifiers, it is generally personal data under the GDPR. Genuinely anonymous data falls outside scope, but a high threshold applies to true anonymisation.
Consent is always required to process behavioural data.
Consent is one of several Article 6 legal bases and is not universally required. Other bases, such as legitimate interests, may be available subject to a balancing assessment. That said, national ePrivacy implementing rules often require consent for storing or accessing information on a user's device, such as certain cookies, which can be a distinct requirement from the Article 6 basis. The correct approach depends on the specific processing and jurisdiction.
Inferences drawn from behaviour are just internal analytics and not regulated personal data.
Inferred or predicted attributes about an identifiable individual generally qualify as personal data and can constitute profiling. If an inference reveals or is used to derive special category data within the meaning of Article 9, an additional Article 9 condition would typically be needed. Treatment can vary and should be assessed against current guidance.

Best practices

Map behavioural data flows to determine whether the data relates to identifiable individuals, distinguishing observed activity, derived inferences, and tracking identifiers, and document the outcome.
Identify and record an appropriate Article 6 legal basis for each processing purpose, and separately assess whether national ePrivacy implementing rules require consent for the placing or reading of device identifiers such as cookies.
Assess whether the behavioural processing amounts to profiling or systematic monitoring and, where indicated, carry out a Data Protection Impact Assessment under Article 35 before processing begins.
Check whether inferences could reveal special category data under Article 9, and, if so, confirm an additional Article 9 condition applies before relying on such data.
Provide clear, layered transparency to individuals about behavioural monitoring, including the purposes, the legal basis relied on, and any profiling, in line with information duties.
Where relying on legitimate interests, complete and retain a balancing assessment, and where relying on consent, ensure it meets the applicable validity standards and can be withdrawn as easily as given, verifying the position against the current official text and regulator guidance.