Skip to main content
Category: Data Subject Rights

Data Subject

Also known as: Data Subjects
Simply put

A data subject is a living person who can be identified from personal data, such as their name, address, telephone number, or other identifying information. They are the individual whose data is being collected or handled by an organisation. Under data protection law, data subjects are granted certain rights over their personal data.

Formal definition

A data subject is an identified or identifiable living individual to whom personal data relates, being one of the principal actors recognised under the GDPR alongside controllers and processors. Identifiability may arise directly (for example, from a name) or indirectly, from data such as location details or other identifiers. Note that the GDPR generally concerns the personal data of living natural persons and does not, as a rule, extend to deceased persons or legal entities; the position on deceased persons in particular may vary under member state and UK national implementing law, so the reader should verify against the applicable law. Data subjects are afforded a set of rights over their personal data under the Regulation, the precise scope and conditions of which should be checked against the current official text.

Why it matters

The data subject is one of the three principal actors recognised under the GDPR, alongside the controller and the processor, and the concept sits at the centre of the Regulation's protective purpose. Because the GDPR generally concerns the personal data of living, identified or identifiable natural persons, correctly identifying who qualifies as a data subject determines whether a given processing activity falls within scope at all. Where data cannot be linked to an identifiable individual, the protections attaching to data subjects typically do not apply, so this classification is often the first analytical step in any compliance assessment.

Data subjects are afforded a set of rights over their personal data under the Regulation. Before data is collected, a data subject generally has the right to know how it will be collected, processed, and stored, and for what purposes. This means organisations cannot treat individuals merely as passive sources of data; they carry obligations toward them that shape lawful processing. The precise scope and conditions of these rights should be checked against the current official text, as they operate subject to various conditions and exemptions.

The boundaries of the concept also carry real practical consequences. Identifiability can arise directly, for example from a name, or indirectly, from data such as location details or other identifiers. The GDPR does not, as a rule, extend to deceased persons or legal entities, but the position on deceased persons in particular may vary under member state and UK national implementing law. Readers should verify the applicable national position rather than assume a uniform rule across jurisdictions.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads rely on the data subject concept to scope processing activities and to determine whether GDPR protections apply. Correctly distinguishing identifiable individuals from data that does not relate to an identifiable person is often the starting point for records of processing, rights handling, and risk assessment. They should also confirm the national position where implementing law may vary, for example in relation to deceased persons.
Controllers and Processors
As the two other principal actors under the GDPR, controllers and processors define their obligations in relation to the data subjects whose personal data they handle. Understanding who qualifies as a data subject, and the rights afforded to them under the Regulation, helps these actors structure lawful collection and processing. The precise scope of those rights and obligations should be verified against the current official text.
Privacy Engineers and Product Teams
Engineers building systems that collect or handle personal data need to recognise when data relates to an identifiable individual, including where identifiability arises indirectly from location details or other identifiers. This informs how data flows are designed and how mechanisms supporting data subject rights are implemented. Whether particular data renders an individual identifiable is a fact-specific assessment.
Legal Advisers and Lawyers
Lawyers advising on data protection matters use the data subject definition to delineate the scope of the Regulation, noting that it generally concerns living natural persons and does not, as a rule, extend to legal entities. Because the treatment of deceased persons and certain other points can diverge under member state and UK national implementing law, advisers should check the applicable jurisdiction rather than assume a uniform outcome.

Inside Data Subject

Data Subject
Under the GDPR, an identified or identifiable natural living person to whom personal data relates. The concept does not extend to anonymous data, and generally does not cover deceased persons or legal entities, though member state law may vary the position for the deceased.
Data Subject Rights
The set of enforceable rights the GDPR grants to individuals in respect of their personal data, which in most cases include access, rectification, erasure, restriction of processing, data portability, objection, and rights relating to automated decision-making. The availability and scope of specific rights depends on the legal basis relied upon and other conditions, and exemptions may apply.
Expectations and Perspective of the Individual
The reasonable expectations a data subject may have about how their personal data is handled. Such expectations can be relevant to assessments such as the legitimate interests balancing test, but they are a factor within an assessment rather than a free-standing legal entitlement.
Consultation of Data Subjects
In certain circumstances, controllers may be expected to seek the views of data subjects or their representatives, for example where a Data Protection Impact Assessment under Article 35 is carried out. Whether and how such consultation occurs is subject to assessment and to regulatory guidance.
Transparency and Information Provision
Information that must generally be provided to data subjects about processing, which supports their ability to form and exercise informed views and to invoke their rights. The precise content and timing depend on whether data is collected directly from the individual or obtained from another source.

Common questions

Answers to the questions practitioners most commonly ask about Data Subject.

Do 'data subject views' create a formal legal category or a specific right under the GDPR?
No. The phrase does not correspond to a defined legal category or a discrete right in the GDPR text. The Regulation confers a set of specific data subject rights (for example, access, rectification, erasure, restriction, portability, and objection), but 'views' as such is not a standalone statutory concept. Where the term is used, it is generally shorthand for the perspective, expectations, or feedback of individuals whose personal data is processed, rather than an enforceable entitlement. Readers should map any practical use of the phrase onto the actual rights and obligations that apply and verify against the current official text.
Does taking account of data subjects' views mean their consent is required, or that their preferences override the controller's legal basis?
Not generally. Considering the views or reasonable expectations of individuals is distinct from obtaining consent under Article 6(1)(a). Consent is only one of several lawful bases, and a controller may rely on another basis (such as contract, legal obligation, or legitimate interests) where applicable. An individual's stated preference does not automatically displace a validly established legal basis, though it can be relevant, for example, to the balancing assessment under legitimate interests or to the exercise of the right to object. Where processing relies on consent, that consent must meet the applicable conditions. The precise interplay is context and risk dependent and should be assessed case by case.
How can an organisation practically gather and record data subject views?
Organisations typically capture individuals' perspectives through mechanisms such as surveys, consultation exercises, complaint and feedback channels, user testing, and engagement carried out as part of a Data Protection Impact Assessment under Article 35, which contemplates seeking the views of data subjects or their representatives where appropriate. It is generally advisable to document what was sought, how it was obtained, and how it informed decisions, so that the exercise supports the accountability principle. The form and depth of engagement should be proportionate to the processing and its risks; approaches vary between organisations and sectors, and no single prescribed method applies.
When is it appropriate to seek data subjects' views as part of a DPIA?
Article 35 indicates that, where appropriate, the controller should seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing. In practice this is typically considered for higher-risk processing where the impact on individuals is significant. If the controller decides not to seek views, or departs from views obtained, documenting the reasoning is generally regarded as good practice for accountability. What is 'appropriate' is a matter of assessment and can attract differing regulator and guidance positions, so the boundary is not fixed.
How should conflicting data subject views be handled when individuals disagree?
There is no single mandated approach. Where individuals express differing preferences, controllers generally weigh the views alongside the applicable legal basis, the purposes of processing, and the risks to the affected individuals, rather than treating any one view as decisive. For processing relying on legitimate interests, divergent expectations can feed into the balancing test; for the right to object, each objection is assessed on its own terms. Recording how competing perspectives were considered supports accountability. The appropriate resolution is context dependent and should be assessed against the specific processing and any relevant guidance.
How can data subject engagement be documented to support accountability?
Documentation typically records what engagement was undertaken, the questions or issues put to individuals, the responses received, and how those responses influenced (or did not influence) decisions about the processing. Where engagement forms part of a DPIA, it is generally incorporated into that record. Maintaining this evidence can help demonstrate compliance with the accountability principle, though there is no prescribed template and the level of detail should be proportionate to the processing and its risks. Organisations should align records with their broader documentation practices and verify requirements against current official guidance.

Common misconceptions

The views or consent of the data subject are always required before their personal data can be processed.
Consent is only one of the Article 6 legal bases, alongside contract, legal obligation, vital interests, public task, and legitimate interests. Processing can be lawful on another basis without the individual's consent, though special category data under Article 9 requires an additional condition, and any processing remains subject to the wider principles and requirements.
A data subject's expressed wishes must be honoured in every case, so their rights are absolute.
Most data subject rights are qualified rather than absolute and are subject to conditions, exemptions, and balancing against other interests. The outcome typically depends on the legal basis, the nature of the data, and applicable derogations that can vary between member states and under the UK GDPR.
Consulting data subjects and running a Data Protection Impact Assessment are the same exercise.
A DPIA under Article 35 is a risk assessment process, whereas seeking data subjects' views is at most one input that may feed into it where appropriate. Neither should be conflated with instruments such as a Data Processing Agreement under Article 28, which governs the controller-processor relationship.

Best practices

Identify and document the applicable Article 6 legal basis (and any Article 9 condition for special category data) before relying on the individual's views or consent, rather than assuming consent is required.
Where consultation of data subjects is appropriate, for example within a DPIA under Article 35, record how their views were sought and how they influenced the assessment.
Assess the reasonable expectations of data subjects as one factor in relevant tests such as legitimate interests, and document the reasoning rather than treating expectations as determinative.
Provide clear, accessible transparency information so individuals can form informed views and exercise their rights, tailoring the content to whether data was collected directly or from another source.
Treat each data subject right as qualified and check for applicable exemptions and conditions, noting that positions may diverge between EU member states and under the UK GDPR.
Verify the current scope of rights and any consultation obligations against the official Regulation text and up-to-date regulatory guidance, as interpretation can evolve.