Communication to Data Subjects
Communication to data subjects refers to the information an organization provides to the individuals whose personal data it processes, such as notices about how their data is used or messages responding to their requests. It is one of the main ways organizations meet their transparency and fairness responsibilities toward people. The specific form, timing, and content of such communication depend on the applicable law and the circumstances involved.
Communication to data subjects is the practice of conveying required or requested information to identified or identifiable natural persons regarding the processing of their personal data. In data protection frameworks such as the EU GDPR and UK GDPR, related obligations generally fall on the data controller, which determines the purposes and means of processing, rather than on the data processor acting on the controller's instructions. Depending on the applicable regime and context, this can encompass transparency information provided at or around the point of collection, responses to the exercise of data subject rights, and notifications about certain events. Where a legal instrument sets expectations, communications are typically required to be intelligible, in clear and plain language, and accessible, though the precise standards, triggers, timelines, and exemptions differ by jurisdiction and are not uniform across the EU GDPR, UK GDPR, CCPA and CPRA, or HIPAA. This entry defines the concept at a general level and does not specify the substantive content of any particular notice, the mechanics of individual data subject rights, breach notification triggers or thresholds, cross-border transfer disclosures, retention rules, or enforcement consequences; those are governed by the relevant instrument and implementation context. Note also that accountability under governance frameworks generally requires demonstrable evidence that appropriate communications were made, not merely a stated intent to inform.
Why it matters
Communication to data subjects sits at the heart of the transparency and fairness principles that underpin most modern data protection regimes. Individuals cannot meaningfully exercise their rights, form expectations about how their personal data is handled, or hold an organization to account if they are not told what is happening to their data in language they can understand. In frameworks such as the EU GDPR and UK GDPR, communication obligations generally rest with the data controller, and clear, intelligible, and accessible communication is one of the primary mechanisms by which a controller demonstrates that it is processing data lawfully and fairly.
Beyond enabling individual rights, communication is a component of accountability. Under governance frameworks, accountability typically requires demonstrable evidence that appropriate communications were actually made, not merely an internal intention or policy stating that individuals will be informed. Poorly worded, buried, or absent communications can undermine the fairness of processing even where a valid lawful basis exists, because a lawful basis and adequate transparency are distinct requirements that must both be satisfied. Organizations that treat notices as a one-time drafting exercise, rather than as ongoing, evidenced practice, expose themselves to challenge.
Because the precise standards, triggers, timelines, and exemptions differ across the EU GDPR, UK GDPR, CCPA and CPRA, and HIPAA, communication that is adequate under one regime is not automatically adequate under another. Multi-jurisdictional organizations therefore cannot rely on a single template or assumption of uniformity; they must map their communication practices to each applicable instrument and context.
Who it's relevant to
Inside Communication to Data Subjects
Common questions
Answers to the questions practitioners most commonly ask about Communication to Data Subjects.