Structured Data
Structured data is information organized according to a predefined format or schema, which makes it easily readable by both software and people. A common example is data arranged in rows and columns, such as records in a database or spreadsheet, where each field has a defined meaning and relationship to others. This organization stands in contrast to unstructured content such as free-text documents or images.
Structured data refers to data organized according to a predefined schema or data model that defines how individual data elements are typed, formatted, and related to one another, making the data readable and processable by both software and humans. A standardized format enables consistent classification, querying, and interpretation of data elements. Note that whether structured data constitutes personal data, special category data, or non-personal data depends entirely on its content and context, not on its structural form; structuring data does not by itself alter its regulatory status. This entry defines the concept of structured data as a data organization category and does not address lawful bases for processing, retention obligations, cross-border transfer mechanics, or the specific governance controls (such as data quality, lineage, or cataloging) that may apply to structured datasets under any particular regime.
Why it matters
The structural form of data materially affects how governance and privacy obligations can be operationalized, even though it does not change the regulatory status of the data itself. Because structured data is organized according to a predefined schema, it is generally more amenable to consistent classification, querying, and access control than unstructured content. This makes it typically easier for organizations to locate personal data, respond to data subject access requests, apply retention rules, and demonstrate the kind of evidence that accountability frameworks require. Conversely, the ease of querying structured datasets also means that risks such as unauthorized access or excessive linkage can scale quickly if governance controls are weak.
A critical and frequently misunderstood point is that structuring data does not by itself alter whether that data is personal data, special category data, or non-personal data. Whether a structured dataset falls within the scope of a given regime depends entirely on its content and context, not on the fact that it sits neatly in rows and columns. Practitioners should avoid the assumption that structured versus unstructured is a proxy for regulated versus unregulated; both categories can contain personal or sensitive information, and both can be out of scope depending on the specifics.
Because this entry addresses structured data purely as a data organization category, it does not resolve questions of lawful basis, retention, cross-border transfer, or the specific governance controls that may apply. Those determinations must be made separately, based on the content of the dataset and the applicable jurisdiction and instrument, rather than inferred from structural form alone.
Who it's relevant to
Inside Structured Data
Common questions
Answers to the questions practitioners most commonly ask about Structured Data.