Data Subject
A data subject is a living person who can be identified from personal data, such as their name, address, telephone number, or other identifying information. They are the individual whose data is being collected or handled by an organisation. Under data protection law, data subjects are granted certain rights over their personal data.
A data subject is an identified or identifiable living individual to whom personal data relates, being one of the principal actors recognised under the GDPR alongside controllers and processors. Identifiability may arise directly (for example, from a name) or indirectly, from data such as location details or other identifiers. Note that the GDPR generally concerns the personal data of living natural persons and does not, as a rule, extend to deceased persons or legal entities; the position on deceased persons in particular may vary under member state and UK national implementing law, so the reader should verify against the applicable law. Data subjects are afforded a set of rights over their personal data under the Regulation, the precise scope and conditions of which should be checked against the current official text.
Why it matters
The data subject is one of the three principal actors recognised under the GDPR, alongside the controller and the processor, and the concept sits at the centre of the Regulation's protective purpose. Because the GDPR generally concerns the personal data of living, identified or identifiable natural persons, correctly identifying who qualifies as a data subject determines whether a given processing activity falls within scope at all. Where data cannot be linked to an identifiable individual, the protections attaching to data subjects typically do not apply, so this classification is often the first analytical step in any compliance assessment.
Data subjects are afforded a set of rights over their personal data under the Regulation. Before data is collected, a data subject generally has the right to know how it will be collected, processed, and stored, and for what purposes. This means organisations cannot treat individuals merely as passive sources of data; they carry obligations toward them that shape lawful processing. The precise scope and conditions of these rights should be checked against the current official text, as they operate subject to various conditions and exemptions.
The boundaries of the concept also carry real practical consequences. Identifiability can arise directly, for example from a name, or indirectly, from data such as location details or other identifiers. The GDPR does not, as a rule, extend to deceased persons or legal entities, but the position on deceased persons in particular may vary under member state and UK national implementing law. Readers should verify the applicable national position rather than assume a uniform rule across jurisdictions.
Who it's relevant to
Inside Data Subject
Common questions
Answers to the questions practitioners most commonly ask about Data Subject.