Description of Categories of Data Subjects
A category of data subjects is a grouping or class of individuals whose personal data an organisation processes, described by a shared characteristic rather than by naming each person. Common examples include employees, customers, patients, and children. Organisations use these categories to describe, at a summary level, whose personal data is involved in a given processing activity or agreement.
A 'category of data subjects' is a classification of natural persons whose personal data is processed, defined by reference to a common attribute or relationship to the organisation (for example, employees, prospective employees, customers, website users, patients, or children). The term is used in GDPR record-keeping and contractual contexts to describe groupings of individuals at a class level rather than identifying particular individuals. In records of processing activities, a controller's record under Article 30(1) is generally required to include a description of the categories of data subjects (alongside categories of personal data); by contrast, a processor's record under Article 30(2) is framed around the categories of processing carried out on behalf of each controller and does not itself impose an equivalent obligation to record categories of data subjects. Categories of data subjects are also commonly specified in the subject-matter details of a data processing agreement under Article 28. Readers should verify the precise wording and article references against the current official text, as scope and drafting practice can vary and, for the UK, the position falls under the UK GDPR.
Why it matters
Describing the categories of data subjects is a foundational step in mapping and documenting processing activities. When an organisation can articulate whose personal data it handles, for example employees, customers, patients, or children, it becomes far easier to identify the risks, rights, and legal conditions that attach to each group. Some categories, such as children, carry heightened expectations and may call for additional safeguards, and describing them explicitly helps ensure those considerations are not overlooked in a records of processing activities exercise or in a data processing agreement.
The precision of these descriptions also affects accountability. A controller's record of processing activities under Article 30(1) is generally expected to include a description of the categories of data subjects alongside the categories of personal data. By contrast, a processor's record under Article 30(2) is framed around the categories of processing carried out on behalf of each controller and does not impose an equivalent obligation to record categories of data subjects. Conflating these two obligations is a common source of error, and readers should verify the precise requirements against the current official text.
At a practical level, clear categories support downstream compliance work: they help scope data subject rights requests, inform data protection impact assessments where processing is likely to result in high risk, and clarify the subject-matter of processing when negotiating Article 28 contracts. Because drafting practice varies and the UK position falls under the UK GDPR, organisations should treat category descriptions as a living part of their documentation rather than a one-off entry.
Who it's relevant to
Inside Description of Categories of Data Subjects
Common questions
Answers to the questions practitioners most commonly ask about Description of Categories of Data Subjects.