Traffic Data
Traffic data is information that is generated and processed when a communication travels across an electronic communications network, such as data needed to route a message or to bill for a service. It relates to the handling of a communication rather than necessarily its content. In the privacy context, this term is specific to electronic communications regulation and is distinct from unrelated uses of the phrase 'traffic data' in fields such as road transport or general network monitoring.
Under the UK's Privacy and Electronic Communications Regulations (PECR), and as described in ICO guidance, traffic data is any data processed for the purpose of the conveyance of a communication on an electronic communications network, or for the billing in respect of that communication. The evidence provided quotes the ICO definition only partially, so practitioners should verify the complete and current statutory definition and its interaction with the underlying legislation directly against the official text. This concept is confined to the electronic communications context and should not be conflated with the general networking sense of 'network traffic' or with transport-sector traffic datasets, which appear in the evidence but are not relevant to the PECR meaning. Where traffic data relates to an identifiable individual it may also constitute personal data and attract obligations under the applicable data protection framework, though the precise interplay between PECR and the UK GDPR is subject to assessment on the facts.
Why it matters
Traffic data sits at the intersection of electronic communications regulation and data protection, and getting the category right matters because it determines which rulebook applies. Under the UK's Privacy and Electronic Communications Regulations (PECR), data processed for the purpose of conveying a communication across an electronic communications network, or for billing in respect of that communication, is treated as a distinct category with its own handling requirements. Where the same data also relates to an identifiable individual, it may constitute personal data as well, meaning obligations under the applicable data protection framework can apply alongside PECR. The precise interplay between the two regimes is not automatic and should be assessed on the facts.
A common practical risk is category confusion. The phrase 'traffic data' is used in unrelated fields, including general network monitoring and the transport sector, and treating any of these as interchangeable can lead an organisation to apply the wrong legal analysis. For PECR purposes, the term is confined to the electronic communications context; general 'network traffic' in an IT security sense or transport-sector traffic datasets fall outside this meaning even though they share the label.
Because the evidence available quotes the ICO definition only in part, practitioners should treat any summary as a starting point rather than a complete statement of the law. The full statutory definition, and how it interacts with the underlying legislation, should be verified directly against the current official text before it is relied on in a compliance program.
Who it's relevant to
Inside Traffic Data
Common questions
Answers to the questions practitioners most commonly ask about Traffic Data.