Skip to main content
Category: Breach and Risk Assessment

Communication to Data Subjects

Also known as: Communication with the Data Subject, Data Subject Communication, Notification to Data Subjects
Simply put

Communication to data subjects refers to the information an organization provides to the individuals whose personal data it processes, such as notices about how their data is used or messages responding to their requests. It is one of the main ways organizations meet their transparency and fairness responsibilities toward people. The specific form, timing, and content of such communication depend on the applicable law and the circumstances involved.

Formal definition

Communication to data subjects is the practice of conveying required or requested information to identified or identifiable natural persons regarding the processing of their personal data. In data protection frameworks such as the EU GDPR and UK GDPR, related obligations generally fall on the data controller, which determines the purposes and means of processing, rather than on the data processor acting on the controller's instructions. Depending on the applicable regime and context, this can encompass transparency information provided at or around the point of collection, responses to the exercise of data subject rights, and notifications about certain events. Where a legal instrument sets expectations, communications are typically required to be intelligible, in clear and plain language, and accessible, though the precise standards, triggers, timelines, and exemptions differ by jurisdiction and are not uniform across the EU GDPR, UK GDPR, CCPA and CPRA, or HIPAA. This entry defines the concept at a general level and does not specify the substantive content of any particular notice, the mechanics of individual data subject rights, breach notification triggers or thresholds, cross-border transfer disclosures, retention rules, or enforcement consequences; those are governed by the relevant instrument and implementation context. Note also that accountability under governance frameworks generally requires demonstrable evidence that appropriate communications were made, not merely a stated intent to inform.

Why it matters

Communication to data subjects sits at the heart of the transparency and fairness principles that underpin most modern data protection regimes. Individuals cannot meaningfully exercise their rights, form expectations about how their personal data is handled, or hold an organization to account if they are not told what is happening to their data in language they can understand. In frameworks such as the EU GDPR and UK GDPR, communication obligations generally rest with the data controller, and clear, intelligible, and accessible communication is one of the primary mechanisms by which a controller demonstrates that it is processing data lawfully and fairly.

Beyond enabling individual rights, communication is a component of accountability. Under governance frameworks, accountability typically requires demonstrable evidence that appropriate communications were actually made, not merely an internal intention or policy stating that individuals will be informed. Poorly worded, buried, or absent communications can undermine the fairness of processing even where a valid lawful basis exists, because a lawful basis and adequate transparency are distinct requirements that must both be satisfied. Organizations that treat notices as a one-time drafting exercise, rather than as ongoing, evidenced practice, expose themselves to challenge.

Because the precise standards, triggers, timelines, and exemptions differ across the EU GDPR, UK GDPR, CCPA and CPRA, and HIPAA, communication that is adequate under one regime is not automatically adequate under another. Multi-jurisdictional organizations therefore cannot rely on a single template or assumption of uniformity; they must map their communication practices to each applicable instrument and context.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads oversee whether communications to individuals meet the applicable transparency and fairness standards and are supported by demonstrable evidence. They should be alert to the fact that requirements differ across the EU GDPR, UK GDPR, CCPA and CPRA, and HIPAA, so a communication adequate under one regime may not satisfy another.
Data Controllers
As the party that determines the purposes and means of processing, the controller generally bears the obligation to communicate with data subjects. This responsibility is not discharged simply by instructing a processor; the controller must ensure communications are intelligible, accessible, and appropriately documented.
Privacy Engineers and Product Teams
Those who design collection points, consent flows, and rights-request handling implement the mechanisms through which communication reaches individuals. They should ensure notices and responses are delivered in clear, plain language at the appropriate moments, recognizing that a lawful basis and adequate communication are separate requirements that must both be met.
Legal and Compliance Professionals
Legal and compliance teams map communication practices against the specific instrument that applies to each processing activity and jurisdiction. They advise on whether the form, timing, and content of communications align with regime-specific triggers, timelines, and exemptions, which this general definition does not itself specify.
Information Governance Leads
Governance leads are concerned with maintaining and evidencing the accountability record around communications. Because governance frameworks generally require demonstrable proof that appropriate communications were made, they focus on retaining and organizing that evidence rather than relying on stated intent alone.

Inside Communication to Data Subjects

Breach Notification to Data Subjects
Under the EU GDPR, where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, the data controller is generally required to communicate the breach to affected data subjects. This obligation is distinct from, and in addition to, any obligation to notify the relevant supervisory authority. The UK GDPR contains a broadly comparable requirement, while other regimes such as the CCPA/CPRA and HIPAA impose their own separate breach communication rules that differ in triggers and content.
Transparency and Information Provided at Collection
Communication to data subjects also encompasses the information a controller must provide about processing, typically covering the identity of the controller, the purposes and lawful basis of processing, and the rights available to individuals. This is a controller obligation; a processor generally acts on the controller's instructions and does not independently discharge these transparency duties.
Clear and Plain Language
Communications directed at data subjects should generally be concise, transparent, intelligible, and expressed in clear and plain language, particularly where they are addressed to children or vulnerable groups. The aim is that the recipient can understand the nature of the event or processing and any action they may need to take.
Content of a Breach Communication
Where a breach must be communicated, the message typically describes the nature of the breach, the likely consequences, and the measures taken or proposed to address it, along with a point of contact for further information. The precise required content depends on the applicable regime.
Conditions Excusing Direct Communication
Some regimes permit a controller to forgo direct communication in certain circumstances, for example where appropriate protective measures rendering the data unintelligible had been applied, where subsequent measures ensure the high risk is no longer likely to materialize, or where direct communication would involve disproportionate effort (in which case a public communication or similar measure may be used instead). Availability and exact wording of these conditions vary by jurisdiction.
Accountability and Evidence
The controller bears accountability for demonstrating that any decision to communicate, or not to communicate, was justified. Under governance and accountability frameworks this generally requires documented reasoning and evidence rather than a stated intention alone.

Common questions

Answers to the questions practitioners most commonly ask about Communication to Data Subjects.

Is a data breach notification to a supervisory authority the same as communicating a breach to affected data subjects?
No. These are generally distinct obligations under regimes such as the EU GDPR and UK GDPR. Notifying a supervisory authority and communicating to affected individuals are separate triggers with different thresholds, and one may apply without the other depending on the assessed risk to individuals. Treating them as interchangeable is a common error. This answer does not cover the specific timing or content requirements, which vary by regime and circumstance.
Does communicating with data subjects always require obtaining their consent first?
No. Communication to data subjects is generally an obligation the controller performs to fulfil transparency, breach notification, or rights-response duties, and it should not be confused with consent as a lawful basis for processing. Consent is only one of several lawful bases, and the duty to inform or communicate with individuals typically exists independently of whichever lawful basis applies. Whether a given communication is required, and on what basis, depends on jurisdiction and context.
Which party is responsible for communicating with data subjects, the controller or the processor?
In most regimes such as the EU GDPR and UK GDPR, the controller generally bears the obligation to communicate with data subjects, as the controller determines the purposes and means of processing and is accountable for transparency and rights handling. A processor typically communicates through or on behalf of the controller under contractual terms rather than acting on its own account. Specific allocation of tasks should be confirmed in the controller-processor arrangement and against the applicable regime.
How should a communication to data subjects be worded to meet transparency expectations?
Transparency principles in regimes such as the EU GDPR and UK GDPR generally call for information provided to individuals to be concise, intelligible, and in clear and plain language, and easily accessible. Beyond wording, controllers should be able to demonstrate that the communication was made, since accountability under governance and data protection frameworks generally requires evidence rather than stated intent. This answer does not prescribe mandatory content elements, which differ by communication type and regime.
When a communication concerns a personal data breach, what does the individual generally need to be told?
Where a breach communication to affected individuals is required, regimes such as the EU GDPR and UK GDPR generally expect it to describe the nature of the incident in clear terms and provide practical information that helps the individual protect themselves. It typically also identifies a point of contact for further information. Whether such communication is required at all depends on the assessed level of risk to individuals, and this answer does not cover the exemptions or thresholds that determine that assessment.
How can an organization demonstrate that it communicated with data subjects when required?
Accountability generally requires demonstrable evidence rather than an assertion that communication occurred. In practice organizations retain records of what was communicated, to whom, when, and through which channel, and align this with their broader governance documentation. This is a governance and record-keeping matter distinct from security controls, and it does not by itself guarantee compliance, which depends on the adequacy, timing, and content of the communication in context.

Common misconceptions

Any personal data breach must always be communicated to affected individuals.
Communication to data subjects is generally triggered only where the breach is likely to result in a high risk to individuals' rights and freedoms. A separate, lower threshold may apply to notifying a supervisory authority. The precise triggers differ across the EU GDPR, UK GDPR, CCPA/CPRA, and HIPAA, so the obligation is not universal or automatic.
Encrypting or tokenizing the affected data automatically removes any duty to communicate.
Some regimes allow direct communication to be avoided where protective measures rendered the data unintelligible to unauthorized parties, but this is a conditional exemption assessed case by case, not a guarantee. Encryption or tokenization does not make data non-personal, and the controller must still be able to demonstrate that the high risk is genuinely mitigated.
The data processor is responsible for communicating breaches to data subjects.
Communication to data subjects is generally a controller obligation. A processor typically must inform the controller of a breach without undue delay, but the decision to communicate to affected individuals, and the accountability for it, rests with the controller.

Best practices

Assess and document the likelihood of high risk to individuals for each breach, so the decision to communicate or not is defensible and supported by evidence rather than stated intent.
Prepare and periodically test communication templates that describe the nature of the event, likely consequences, mitigating measures, and a contact point, in clear and plain language suited to the audience.
Map the specific requirements of each regime you are subject to (for example EU GDPR, UK GDPR, CCPA/CPRA, HIPAA) rather than assuming a single communication standard covers all obligations.
Coordinate data subject communication with, but keep it distinct from, any separate supervisory authority notification obligation, tracking the different thresholds and timelines that apply.
Where relying on an exemption from direct communication, record the specific condition invoked and the supporting evidence, and consider whether a public or alternative communication is required instead.
Retain documentation of the reasoning, timing, and content of communications to demonstrate accountability, and confirm processor contracts require prompt notification to the controller.