Skip to main content
Category: Impact Assessments & Documentation

Description of Categories of Data Subjects

Also known as: Categories of Data Subjects, Data Subject Categories, Data Subject Types
Simply put

A category of data subjects is a grouping or class of individuals whose personal data an organisation processes, described by a shared characteristic rather than by naming each person. Common examples include employees, customers, patients, and children. Organisations use these categories to describe, at a summary level, whose personal data is involved in a given processing activity or agreement.

Formal definition

A 'category of data subjects' is a classification of natural persons whose personal data is processed, defined by reference to a common attribute or relationship to the organisation (for example, employees, prospective employees, customers, website users, patients, or children). The term is used in GDPR record-keeping and contractual contexts to describe groupings of individuals at a class level rather than identifying particular individuals. In records of processing activities, a controller's record under Article 30(1) is generally required to include a description of the categories of data subjects (alongside categories of personal data); by contrast, a processor's record under Article 30(2) is framed around the categories of processing carried out on behalf of each controller and does not itself impose an equivalent obligation to record categories of data subjects. Categories of data subjects are also commonly specified in the subject-matter details of a data processing agreement under Article 28. Readers should verify the precise wording and article references against the current official text, as scope and drafting practice can vary and, for the UK, the position falls under the UK GDPR.

Why it matters

Describing the categories of data subjects is a foundational step in mapping and documenting processing activities. When an organisation can articulate whose personal data it handles, for example employees, customers, patients, or children, it becomes far easier to identify the risks, rights, and legal conditions that attach to each group. Some categories, such as children, carry heightened expectations and may call for additional safeguards, and describing them explicitly helps ensure those considerations are not overlooked in a records of processing activities exercise or in a data processing agreement.

The precision of these descriptions also affects accountability. A controller's record of processing activities under Article 30(1) is generally expected to include a description of the categories of data subjects alongside the categories of personal data. By contrast, a processor's record under Article 30(2) is framed around the categories of processing carried out on behalf of each controller and does not impose an equivalent obligation to record categories of data subjects. Conflating these two obligations is a common source of error, and readers should verify the precise requirements against the current official text.

At a practical level, clear categories support downstream compliance work: they help scope data subject rights requests, inform data protection impact assessments where processing is likely to result in high risk, and clarify the subject-matter of processing when negotiating Article 28 contracts. Because drafting practice varies and the UK position falls under the UK GDPR, organisations should treat category descriptions as a living part of their documentation rather than a one-off entry.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance leads rely on well-defined categories of data subjects when building and maintaining records of processing activities and when assessing risks that attach to particular groups, such as children. Clear categories help them scope obligations accurately and avoid conflating the distinct documentation duties that apply to controllers under Article 30(1) and to processors under Article 30(2).
Controllers preparing records of processing activities
Controllers are the parties whose Article 30(1) records generally require a description of the categories of data subjects alongside the categories of personal data. Identifying these categories accurately supports the summary-level, class-based description that this record is intended to provide.
Processors documenting their activities
Processors should note that their Article 30(2) records are framed around the categories of processing carried out on behalf of each controller and do not impose an equivalent obligation to record categories of data subjects. Even so, categories of data subjects often appear in the Article 28 data processing agreement that governs the relationship, so processors may still encounter and rely on these descriptions contractually.
Lawyers drafting data processing agreements
Legal advisers negotiating Article 28 contracts commonly specify categories of data subjects within the subject-matter details of the agreement. Precise categories help define the scope of processing and clarify the relationship between the parties, though drafting granularity varies and should be tailored to the actual processing.
Engineers and data mapping teams
Technical teams that map data flows and processing purposes provide the underlying information from which categories of data subjects are derived. Accurate mapping helps ensure that documented categories reflect the individuals whose personal data is actually processed across systems.

Inside Description of Categories of Data Subjects

Categories of data subjects
Groupings of the individuals whose personal data is processed, described by their relationship to the organization or the processing context rather than by name. Typical examples include employees, customers, prospects, website users, suppliers' contacts, and children. This element appears in a controller's record of processing activities under Article 30(1) GDPR.
Context in Article 30(1) records
For controllers, the record of processing activities must include, among other items, a description of the categories of data subjects alongside the categories of personal data. The two are related but distinct: categories of data subjects describe who the individuals are, while categories of personal data describe what information is held about them.
Distinction from the processor's record
The processor's record of processing activities under Article 30(2) GDPR does not require categories of data subjects. A processor's record must instead describe the categories of processing carried out on behalf of each controller, together with matters such as the controller identity, transfers, and security measures. A processor may nonetheless reference categories of data subjects for its own operational or contractual purposes, but this is not an Article 30(2) requirement.
Level of granularity
The description should be specific enough to give a meaningful picture of who is affected, but is generally framed at a category level rather than identifying individuals. The appropriate granularity depends on the nature and complexity of the processing and is a matter of assessment.
Relationship to other accountability instruments
Descriptions of categories of data subjects also commonly appear in Data Protection Impact Assessments under Article 35 and in Article 28 Data Processing Agreements, where the subject matter and scope of processing are set out. The purpose and legal driver differ across these instruments, so a description drafted for one should be reviewed before reuse in another.

Common questions

Answers to the questions practitioners most commonly ask about Description of Categories of Data Subjects.

Do processors have to record the categories of data subjects in their records of processing activities?
Generally no. Under Article 30(2) GDPR, a processor's record of processing activities is required to contain the categories of processing carried out on behalf of each controller, together with certain other information such as the identity of the controllers and, where applicable, details of transfers. The obligation to document the 'categories of data subjects' sits in Article 30(1), which addresses the controller's record. Processors should therefore not assume this element is mandatory for their own Article 30(2) records. A processor may still capture data subject categories voluntarily, or contractually where a controller requests it, but that is a matter of arrangement rather than an Article 30(2) requirement. Verify the current position against the official text, as national implementing law and regulator guidance can add expectations.
Is 'categories of data subjects' just another way of saying 'categories of personal data'?
No, these are distinct elements of a controller's record under Article 30(1). 'Categories of data subjects' describes the types of individuals whose data is processed, for example employees, customers, or website visitors. 'Categories of personal data' describes the types of information processed about them, for example contact details, payment data, or, subject to Article 9 conditions, special category data. They answer different questions, 'who' versus 'what', and the two are listed separately in the record for that reason. Treating them as interchangeable risks an incomplete record.
How granular should the categories of data subjects be in a controller's record?
There is no single prescribed level of granularity in the GDPR text. In most cases, controllers describe data subjects by functional grouping that meaningfully reflects the processing, such as job applicants, current staff, prospective customers, or minors where relevant. The aim is to give an accurate and useful picture that supports accountability and responses to supervisory authorities, rather than to list individuals. Where a group carries heightened risk, such as children or vulnerable individuals, identifying that category separately is generally advisable. Regulator expectations can differ, so it is sensible to check applicable guidance.
Where does this description fit alongside other records and assessments?
The description of categories of data subjects is an element of the controller's record of processing activities under Article 30(1). It is a distinct instrument from a Data Protection Impact Assessment under Article 35, which is a risk assessment for certain higher-risk processing, and from a Data Processing Agreement under Article 28, which governs the controller-processor relationship. The same category descriptions can usefully inform those other documents, but the record of processing activities, the DPIA, and the Article 28 contract each serve different purposes and should not be conflated.
Should special category data subjects or children be flagged within this field?
The 'categories of data subjects' field identifies who the individuals are, so it can be an appropriate place to note groups such as children or other potentially vulnerable individuals where that reflects the processing. Whether the data itself is special category data under Article 9 is generally captured through the categories of personal data and the lawful basis and Article 9 condition, rather than through the data subject description alone. In practice these elements are read together. Because member state derogations can affect the treatment of certain groups, confirm the position under applicable national law.
How often should the description of categories of data subjects be reviewed?
The GDPR requires the record of processing activities to be kept accurate and up to date rather than reviewed on a fixed statutory cycle. In most cases organisations review these descriptions periodically and, importantly, whenever processing changes, for example when a new category of individuals is brought within a processing activity or an existing category ceases. Tying reviews to change events as well as a regular schedule generally supports the accountability principle. The appropriate frequency is context and risk dependent, so calibrate it to the volatility and sensitivity of the processing.

Common misconceptions

Both controllers and processors must record categories of data subjects in their records of processing activities.
This obligation sits with controllers under Article 30(1). A processor's record under Article 30(2) requires the categories of processing carried out on behalf of each controller, not the categories of data subjects. Conflating the two mischaracterizes the distinct roles.
Categories of data subjects and categories of personal data are the same thing.
They are separate elements. Categories of data subjects identify who the individuals are (for example, employees or customers), while categories of personal data identify the types of information held (for example, contact details or payroll data). Article 30(1) treats them as distinct items.
The description must name or individually identify the people whose data is processed.
The requirement is to describe categories, not to list individuals. A category-level description is generally sufficient and appropriate, with the necessary granularity depending on the processing context.

Best practices

Confirm your role for each processing activity before drafting, because a controller's Article 30(1) record must include categories of data subjects while a processor's Article 30(2) record must instead describe the categories of processing carried out on behalf of each controller.
Keep the description of categories of data subjects separate from the description of categories of personal data, so that who is affected and what is held remain clearly distinguishable.
Choose a level of granularity proportionate to the nature and complexity of the processing, avoiding both over-broad labels that obscure who is affected and unnecessary identification of individuals.
Flag categories that may attract heightened obligations, such as children or individuals whose special category data under Article 9 is processed, and cross-check that an appropriate Article 9 condition is documented where relevant.
Review descriptions before reusing them across accountability instruments, since a description written for a record of processing activities may need adjustment for a DPIA under Article 35 or a DPA under Article 28.
Revisit and update the categories periodically and when processing changes, and verify wording against the current official text of the applicable GDPR or UK GDPR provisions, noting that national implementing law may vary the position.