Categories and Approximate Number of Data Subjects
This refers to the way an organisation groups the individuals whose personal data it processes (for example, employees, customers, or children) and an estimate of how many people fall within each group. It is typically recorded so that an organisation can describe, at a glance, who is affected by its data processing. The figure is generally an approximation rather than an exact headcount.
A 'category of data subjects' is a grouping or classification of identified or identifiable natural persons whose personal data is processed, defined by reference to a shared characteristic or relationship to the organisation (such as employees, customers, or children, the latter generally being individuals under 18 in the UK context). Recording the categories and an approximate number of data subjects is a data-mapping and documentation practice associated with records of processing and processor arrangements; practitioners should verify the precise obligations and any exemptions against the current text of the applicable GDPR articles, as the exact scope of what must be documented can vary by role (controller or processor) and by national implementing law. This concept applies to personal data of living natural persons and does not extend to anonymous data, and the granularity of categorisation used is subject to assessment based on the nature and complexity of the processing.
Why it matters
Recording the categories and approximate number of data subjects gives an organisation a clear picture of who is affected by its processing activities. Different groups of individuals carry different risk profiles and, in some cases, different legal considerations. For example, processing data about children (generally individuals under 18 in the UK context) typically warrants heightened care, and employee records may include special category data that requires an additional condition under Article 9 alongside a lawful basis under Article 6. Knowing which categories are in play helps an organisation apply the right protections to the right people rather than treating all processing as uniform.
The approximate number of data subjects matters because it helps convey the scale of processing and can inform risk assessments and prioritisation. A processing activity affecting a large population may merit closer scrutiny than one touching a handful of individuals. Because the figure is generally an estimate rather than an exact headcount, it should be understood as an indicator of magnitude to support decision-making, not as a precise metric. Practitioners should note that the granularity of categorisation used is subject to assessment based on the nature and complexity of the processing.
This documentation is closely tied to records of processing and to processor arrangements. Maintaining accurate, current categories supports an organisation's ability to describe its processing to regulators, to individuals, and internally. Because the precise obligations and any exemptions can vary by role (controller or processor) and by national implementing law, organisations should verify what they are required to document against the current text of the applicable GDPR articles rather than relying on a fixed template.
Who it's relevant to
Inside Categories and Approximate Number of Data Subjects
Common questions
Answers to the questions practitioners most commonly ask about Categories and Approximate Number of Data Subjects.