Skip to main content
Category: Controller & Processor Roles

Point of Contact for Data Subjects

Also known as: Contact Point for Data Subjects, Data Subject Contact Point
Simply put

A point of contact for data subjects is the person or function within an organisation that individuals can approach with questions or comments about how their personal data is processed. In practice, this role is often carried out by the Data Protection Officer (DPO) where one has been appointed. It gives individuals a clear route to raise privacy concerns and exercise their rights.

Formal definition

The point of contact for data subjects refers to the function of receiving and handling communications from individuals concerning the processing of their personal data and their rights under data protection law. Where an organisation has designated a Data Protection Officer, guidance from the ICO and other sources indicates that acting as a contact point for data subjects is among the DPO's tasks, alongside monitoring internal compliance and advising on Data Protection Impact Assessments (DPIAs). The DPO also typically serves as a contact point for the relevant supervisory authority. Where no DPO is appointed, an organisation should still generally provide accessible means for data subjects to raise queries and exercise their rights, though the specific arrangements may vary by organisation and jurisdiction; readers should verify the applicable requirements, including any distinctions between the EU GDPR and the UK GDPR, against the current official text and regulator guidance.

Why it matters

A clear point of contact for data subjects operationalises individual rights. Data protection law grants individuals a range of rights over their personal data, but those rights are only meaningful if people know who to approach and how. Providing an accessible route for questions, comments, and requests reduces the risk that individuals struggle to reach the organisation, which in turn can prevent complaints from escalating to a supervisory authority.

From a governance and accountability perspective, a defined contact point supports demonstrable compliance. Where an organisation has appointed a Data Protection Officer, ICO guidance indicates that acting as a contact point for data subjects is among the DPO's tasks, alongside monitoring internal compliance and advising on Data Protection Impact Assessments. Guidance from sources such as gdpr.eu similarly describes the DPO receiving comments and questions from data subjects about the processing of their personal data. Concentrating this function in a known role helps ensure that queries are routed to someone with appropriate expertise and are handled consistently.

Where no DPO is appointed, an organisation should still generally provide accessible means for individuals to raise queries and exercise their rights, though the specific arrangements may vary by organisation and jurisdiction. Because requirements can differ between the EU GDPR and the UK GDPR, and member state or national implementing law may vary the position, readers should verify the applicable obligations against the current official text and regulator guidance rather than assuming a single uniform approach applies.

Who it's relevant to

Data Protection Officers
Where a DPO has been appointed, acting as a contact point for data subjects is, according to ICO guidance, among their tasks. DPOs need to be reachable by individuals and to handle comments and questions about the processing of personal data, in addition to serving as a contact point for the relevant supervisory authority.
Compliance and privacy leads
Those responsible for accountability and governance should ensure the organisation offers an accessible route for individuals to raise privacy concerns and exercise their rights, whether or not a DPO is appointed. They should confirm the applicable requirements, including any differences between the EU GDPR and the UK GDPR, against current official text and regulator guidance.
Data subjects
Individuals benefit from a clear, identifiable route to ask questions or raise concerns about how their personal data is processed and to exercise their rights. Where a DPO exists, that person is often the designated point of contact.
Engineers and product teams
Teams building customer-facing systems and internal processes may need to implement and surface accessible channels through which individuals can reach the contact point, ensuring requests are routed appropriately for handling.

Inside Point of Contact for Data Subjects

Designated contact information
The details a controller or processor makes available so that data subjects can reach the organisation regarding the processing of their personal data, typically including a postal address, email address, or web form. The GDPR's transparency provisions (generally Articles 13 and 14) require the identity and contact details of the controller to be provided.
Data Protection Officer contact point
Where a Data Protection Officer (DPO) has been appointed, their contact details must be communicated to data subjects and, in most cases, published. Under the GDPR the DPO acts as a contact point for data subjects on matters relating to the processing of their data and the exercise of their rights (see the provisions on the DPO's tasks, generally Article 38 and Article 39). Note that appointment of a DPO is only mandatory in certain circumstances, so this contact point does not always exist.
Representative in the Union (where applicable)
For controllers or processors not established in the EU but subject to the GDPR under its territorial scope, a representative in the Union may need to be designated to serve as an additional point of contact for data subjects and supervisory authorities. This is context-dependent and subject to the exemptions in the relevant provisions; readers should verify applicability against the current official text.
Channel for exercising data subject rights
A functional route through which individuals can make requests such as access, rectification, erasure, restriction, portability, and objection. The point of contact is generally the practical mechanism through which these requests are received and routed, though it is distinct from the substantive rights themselves.

Common questions

Answers to the questions practitioners most commonly ask about Point of Contact for Data Subjects.

Is the point of contact for data subjects the same as the Data Protection Officer (DPO)?
No, these are distinct concepts and should not be conflated. A DPO is a specific role with tasks and an independent position described in the GDPR, and is only mandatory in certain circumstances. A point of contact for data subjects is more general: it is the channel or person through which individuals can reach the organisation to raise queries or exercise their rights. Where a DPO has been appointed, the DPO's contact details typically serve as one such point of contact, but an organisation without a DPO still needs to provide a way for data subjects to contact it. The two should be documented separately, and the availability of a point of contact does not by itself satisfy any obligation to designate a DPO.
Does providing a point of contact mean the organisation is acting as a controller for that processing?
Not necessarily. The role an organisation plays (controller or processor) is determined by whether it decides the purposes and means of the processing, not by whether it offers a contact channel. A processor may still provide a contact point for practical or contractual reasons, but requests from data subjects seeking to exercise their rights are generally directed to, and answered by, the controller. Where a processor receives such a request, it typically forwards it to the relevant controller in line with its Article 28 arrangements rather than responding on its own authority. The existence of a point of contact should not be read as a statement about who is legally responsible for the processing.
How should we make the point of contact known to data subjects?
In most cases the contact details are communicated through the information provided to individuals about the processing, such as a privacy notice, and may be reinforced at points where data is collected. It is generally advisable to offer accessible and clearly signposted channels, and to keep the details current. Where a DPO exists, their contact details are typically published as well. The specific placement and format can depend on your context, so review against the current official text and any applicable regulatory guidance.
What channels should the point of contact offer?
There is no single prescribed channel. Organisations commonly offer more than one option, such as an email address, a web form, or a postal address, so that individuals can choose a method that suits them. It is generally good practice to ensure the channel is monitored, that requests are routed to the team responsible for handling them, and that individuals are not required to use an unduly burdensome method. The appropriate mix depends on the size of the organisation, the nature of the processing, and accessibility considerations.
How do we handle a data subject request that arrives through the point of contact?
Requests received through the contact channel are typically triaged, identity is verified where appropriate, and the request is routed to the function responsible for responding. Where the organisation acts as a processor, the request is generally forwarded to the relevant controller. Timeframes and the substance of any response are governed by the applicable rights provisions and should be assessed case by case. You should confirm the current procedural requirements and any deadlines against the official text and relevant guidance rather than relying on a fixed rule of thumb.
Should the point of contact be documented internally, and how?
It is generally advisable to document who is responsible for the contact channel, how requests are logged and escalated, and how records are retained, so that the process is consistent and demonstrable. This documentation typically sits alongside broader records of processing and rights-handling procedures. The level of detail appropriate for your organisation depends on the scale and risk of your processing, so tailor it to your context and review it periodically.

Common misconceptions

The point of contact for data subjects must always be a Data Protection Officer.
A DPO is only required in certain circumstances defined by the GDPR, and where none is appointed the controller must still provide contact details for enquiries and rights requests. A general contact point (for example a dedicated mailbox or team) can serve this function; the DPO and the point of contact are related but not synonymous roles.
The Union representative and the DPO are interchangeable roles.
These are distinct instruments. A representative in the Union addresses the situation of controllers or processors established outside the EU that fall within the GDPR's territorial scope, whereas a DPO is an advisory and monitoring function that may be required regardless of establishment. An organisation may need one, both, or neither depending on its circumstances.
Providing a point of contact means every enquiry must result in the action the individual requests.
The point of contact is the channel for receiving communications and rights requests; it does not by itself determine the outcome. Whether a request is granted depends on the applicable legal basis, exemptions, and a case-by-case assessment, which can vary and may be subject to national implementing law and regulator guidance.

Best practices

Publish clear, current contact details in privacy notices and, where a DPO or Union representative exists, ensure their details are stated as required by the applicable transparency provisions.
Confirm whether your organisation is required to appoint a DPO or designate a representative in the Union, rather than assuming either is mandatory, and document the basis for your conclusion.
Maintain a monitored, resilient channel (such as a dedicated mailbox or web form) so that data subject communications and rights requests are captured and not lost, and define internal routing to the responsible function.
Keep the point of contact distinct in your documentation from the substantive assessment of rights requests, so staff understand that receipt of a request does not predetermine its outcome.
Review and update contact details and published roles periodically, including after organisational changes, and verify wording against the current official text of the applicable GDPR or UK GDPR provisions.
Where national implementing law or regulator guidance affects how contact points or requests are handled, account for possible divergence between member states rather than relying on a single jurisdiction's approach.