Skip to main content
Category: Data Classification & Identifiers

Traffic Data

Simply put

Traffic data is information that is generated and processed when a communication travels across an electronic communications network, such as data needed to route a message or to bill for a service. It relates to the handling of a communication rather than necessarily its content. In the privacy context, this term is specific to electronic communications regulation and is distinct from unrelated uses of the phrase 'traffic data' in fields such as road transport or general network monitoring.

Formal definition

Under the UK's Privacy and Electronic Communications Regulations (PECR), and as described in ICO guidance, traffic data is any data processed for the purpose of the conveyance of a communication on an electronic communications network, or for the billing in respect of that communication. The evidence provided quotes the ICO definition only partially, so practitioners should verify the complete and current statutory definition and its interaction with the underlying legislation directly against the official text. This concept is confined to the electronic communications context and should not be conflated with the general networking sense of 'network traffic' or with transport-sector traffic datasets, which appear in the evidence but are not relevant to the PECR meaning. Where traffic data relates to an identifiable individual it may also constitute personal data and attract obligations under the applicable data protection framework, though the precise interplay between PECR and the UK GDPR is subject to assessment on the facts.

Why it matters

Traffic data sits at the intersection of electronic communications regulation and data protection, and getting the category right matters because it determines which rulebook applies. Under the UK's Privacy and Electronic Communications Regulations (PECR), data processed for the purpose of conveying a communication across an electronic communications network, or for billing in respect of that communication, is treated as a distinct category with its own handling requirements. Where the same data also relates to an identifiable individual, it may constitute personal data as well, meaning obligations under the applicable data protection framework can apply alongside PECR. The precise interplay between the two regimes is not automatic and should be assessed on the facts.

A common practical risk is category confusion. The phrase 'traffic data' is used in unrelated fields, including general network monitoring and the transport sector, and treating any of these as interchangeable can lead an organisation to apply the wrong legal analysis. For PECR purposes, the term is confined to the electronic communications context; general 'network traffic' in an IT security sense or transport-sector traffic datasets fall outside this meaning even though they share the label.

Because the evidence available quotes the ICO definition only in part, practitioners should treat any summary as a starting point rather than a complete statement of the law. The full statutory definition, and how it interacts with the underlying legislation, should be verified directly against the current official text before it is relied on in a compliance program.

Who it's relevant to

Electronic communications service providers
Organisations that convey communications across electronic communications networks generate and process traffic data in the ordinary course of routing and billing. They are typically the primary audience for the PECR-specific rules on traffic data and should verify their handling practices against the complete statutory definition and current ICO guidance.
Data protection officers and compliance leads
Where traffic data relates to an identifiable individual, it may also constitute personal data, so DPOs and compliance teams may need to consider both PECR and the applicable data protection framework. The interaction between the two regimes is subject to assessment on the facts and should not be assumed to be identical in every case.
Privacy lawyers advising on scope and categorisation
Lawyers advising clients should be alert to the risk of conflating the PECR sense of traffic data with the general networking sense of 'network traffic' or with transport-sector traffic datasets, which are not relevant to the PECR meaning. Precise categorisation drives which obligations apply.
Engineers and network operations teams
Technical teams that design routing, logging, and billing systems handle data that may fall within the traffic data definition. Understanding the distinction between operational 'network traffic' monitoring and the regulated concept of traffic data helps ensure that data handling is aligned with legal requirements rather than only technical objectives.

Inside Traffic Data

Definition and legal source
Traffic data is a term derived primarily from the ePrivacy framework (the ePrivacy Directive and its national implementations) rather than from the core GDPR text. It generally refers to data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing of such communications. Readers should verify the precise wording against the current national implementing law, as terminology and scope can vary between member states.
Illustrative categories
Traffic data typically includes information such as the routing, duration, timing, and volume of a communication, and details about the network or protocol used to convey it. The exact categories treated as traffic data depend on the applicable national law and the nature of the communications service, so the boundaries should be assessed case by case.
Relationship to personal data
Where traffic data relates to an identified or identifiable individual, it generally also constitutes personal data and the GDPR applies alongside the ePrivacy rules. Traffic data that has been genuinely anonymised so that no individual is identifiable falls outside the GDPR, subject to assessment of whether re-identification remains possible.
Interaction with the ePrivacy framework and GDPR
The ePrivacy rules operate as more specific provisions (lex specialis) in relation to certain electronic communications, while the GDPR provides the general baseline. The interplay is subject to ongoing legislative reform and regulator guidance, and the position may differ where a proposed ePrivacy Regulation or national derogations apply. The reader should verify the current status.
Distinction from content and metadata terminology
Traffic data is generally distinguished from the content of a communication. Some regulators and instruments use overlapping terms such as metadata or communications data; these are not always coextensive with traffic data, and the applicable definition should be taken from the relevant instrument.

Common questions

Answers to the questions practitioners most commonly ask about Traffic Data.

Is traffic data the same as the content of a communication?
No. Traffic data generally refers to data processed for the purpose of the conveyance of a communication on an electronic communications network or for its billing, rather than the substantive content of that communication. The distinction matters because different rules and safeguards can apply to metadata about a communication versus what was actually said or written. Because the precise treatment sits at the intersection of the GDPR and the ePrivacy regime, and national implementations vary, you should verify the applicable definitions against the current official texts and any relevant regulator guidance.
Does traffic data fall outside privacy rules because it is not personal data?
Not as a general assumption. Traffic data can constitute personal data where it relates to an identified or identifiable individual, in which case the GDPR typically applies alongside the sector-specific ePrivacy rules. Whether a given data set is personal data depends on identifiability in the specific context, and truly anonymous data would fall outside the GDPR. Treating all traffic data as non-personal by default is a common misconception; the correct position is context-dependent and should be assessed case by case.
What legal basis or condition typically applies to processing traffic data?
The applicable basis depends on the purpose and the interaction between the ePrivacy regime and the GDPR. Processing may rely on grounds connected to providing or billing the communications service, on consent, or on another applicable basis, subject to assessment. Consent is not a universal requirement, but certain further uses may require it. Where any special category data under Article 9 is involved, an additional condition would be needed. Because the position can vary by member state implementation and pending reform of the ePrivacy framework, confirm the specific basis against current law and guidance.
How long can traffic data generally be retained?
Retention should generally be limited to what is necessary for the identified purpose, such as conveyance of the communication or billing, after which the data should typically be erased or anonymised unless another lawful basis for continued retention applies. National implementing law and sector-specific rules can set or vary retention periods, and this area has been subject to significant case law and divergence between jurisdictions. You should verify the applicable retention parameters against the current official texts and competent regulator guidance rather than relying on a fixed figure.
What should be documented when processing traffic data?
In most cases it is prudent to document the categories of traffic data processed, the purposes, the legal basis or condition relied on, retention periods, and any onward disclosures. Where processing is likely to result in a high risk to individuals, a Data Protection Impact Assessment under Article 35 may be appropriate, and where a processor is engaged, a Data Processing Agreement under Article 28 is generally required. The exact documentation expectations depend on the context and applicable national rules, so confirm against current requirements.
How does traffic data processing interact with international transfers?
Where traffic data that is personal data is transferred outside the relevant jurisdiction, an appropriate transfer mechanism is generally needed, such as reliance on an adequacy decision or a transfer tool, potentially with supplementary measures following a transfer risk assessment. These mechanisms and adequacy positions evolve over time and differ between the EU GDPR and UK GDPR regimes, so any specific arrangement should be checked against the current official position rather than treated as fixed.

Common misconceptions

Traffic data is a defined term in the GDPR.
The concept derives principally from the ePrivacy framework and its national implementations rather than from the GDPR text. The GDPR generally applies in parallel where the traffic data relates to an identifiable individual, but the definition itself should be located in the applicable ePrivacy instrument or national law.
Processing traffic data always requires consent.
Consent is one possible basis, but processing may in some cases rely on other grounds, such as necessity for conveying the communication or for billing, subject to the specific conditions in the applicable ePrivacy rules and, where the GDPR applies, an appropriate Article 6 basis. The correct basis depends on the purpose and the relevant national law, and should be assessed rather than assumed.
Traffic data is not personal data because it excludes the content of communications.
Traffic data can be highly revealing and, where it relates to an identified or identifiable individual, generally constitutes personal data subject to the GDPR even though it is distinct from message content. Only genuinely anonymised traffic data falls outside the GDPR, subject to assessment of re-identification risk.

Best practices

Identify the applicable legal source for traffic data in each jurisdiction, checking the relevant national ePrivacy implementation alongside the GDPR, and verify the current wording against the official text because member state positions can diverge.
Assess and document the correct legal basis and any ePrivacy-specific conditions for each processing purpose (for example conveyance versus billing), rather than defaulting to consent for all traffic data processing.
Determine whether the traffic data relates to an identifiable individual, and where it does, apply GDPR obligations in parallel with the ePrivacy rules, treating the two frameworks as complementary.
Where you rely on anonymisation to take traffic data outside the GDPR, evaluate and record whether re-identification remains reasonably possible, and treat the analysis as an ongoing assessment rather than a one-off conclusion.
Monitor developments in the ePrivacy framework, including any proposed reforms and updated regulator guidance, since the interplay with the GDPR and the treatment of traffic data continue to evolve.
Map which categories of data your services treat as traffic data, distinguishing them clearly from communication content and from broader metadata terminology, and align internal definitions with the applicable instrument.