Privacy
Identifiability does not require a face
A photo can identify a person through marks, setting, metadata or linkage to an account, so 'no face' does not settle the question.
Guides on Privacy: Who could see it, how, and what each path costs to close, Soft delete, backups, caches and logs, Sometimes, and the policy clause that says so is easy to miss
Yes, a body photo without a face can be personal data, because marks, setting, metadata or a linked account can identify the person. "No face, no problem" is the assumption most people make before uploading, and it is not how identifiability works; any one of those channels can change the answer.
What "identifiable" actually means
Privacy frameworks generally define personal data by whether a person can be identified, directly or indirectly, by someone with a reasonable means of doing so - not by whether the image itself contains a face. The UK regulator's guidance on indirect identification tells organisations to consider "all of the means that any party is reasonably likely to use to identify that individual." That "indirectly" is doing most of the work here. A photo that is anonymous on its own can stop being anonymous the moment it is combined with something else: a username, an IP address, a payment record, or a second photo that does show a face. Identifiability is a property of the photo plus its context, not of the photo in isolation.
The channels that do not need a face
The ICO's list of identifiers explicitly includes factors "specific to the physical, physiological" identity of a person, not just names and faces. A tattoo, a scar, a birthmark or a distinctive piercing is as individual as a face in the sense that matters - it can be matched against another photo where the same mark appears alongside identifying information. Reverse image search finds near-duplicates of a specific photo well, and a distinctive mark makes an image easier to recognise as a duplicate even when cropped or reframed. The setting counts too: a bedroom with a visible poster, a mirror that reflects a room, a window with a recognisable view outside it, all narrow down who and where, sometimes to one household. Metadata carries its own set of channels - device identifiers, timestamps, and in the worst case a GPS coordinate precise enough to locate a specific room, none of which requires anyone to look at the image at all.
The channel most people forget: the account
None of the above may apply, and the photo can still be personal data through the account it sits in. A body photo attached to an email address, a payment record or a login session is identified the moment that account is identified, regardless of what is or is not visible in the frame. Paying for a service links whatever was uploaded to a name, and that link exists in the payment processor's records independent of the image content. An "anonymous" upload with no account attached is a different and generally lower-risk case, though an IP address and a timestamp are already a meaningful pair on their own.
Why this framing matters more than a checklist
There is no fixed list of features that makes a photo personal data and no list that clears it, because the test is about what a realistic party could do with the image and whatever else they hold, not about a single visible attribute. That is a genuinely different question from "does this contain a face," and it is the reason a service that strips faces but keeps everything else has not actually solved the underlying problem, only the most visible piece of it. Two specific pieces are worth treating on their own: what happens when a face is partially in frame, and whether obscuring rather than removing a feature actually works, which is a narrower and more mechanical question than identifiability in general.
What this changes about uploading
None of this is legal advice, and jurisdictions differ on where the line sits and what obligations follow from crossing it. What is consistent across most frameworks is the shape of the test: context expands what counts, and a photo evaluated purely on its own visible content will usually undercount the risk. Rate Cock treats uploaded photos under that assumption in its privacy documentation rather than only asking whether a face is visible, which is the more defensible default for a site handling intimate images. The measurement side of this question is handled differently again, since Measure My Cock is working with a number rather than a retained photo, which removes several of these channels outright. Comparing how different tools describe what counts as identifying is exactly the kind of side-by-side reading Penis Rater's tool coverage is built to make faster than reading each policy cold. A human reviewer changes the calculus again, since a person remembers what they saw rather than storing it as data at all, which is a different kind of exposure that Rate Penis's etiquette guidance addresses on its own terms.