Data Subject
A data subject is the identified or identifiable living individual whose personal data is being processed. In practice, this is the person the data is about, such as a customer, employee, or website user. This term comes from European data protection law and carries a specific meaning under the EU GDPR and UK GDPR.
Under the EU GDPR, a data subject is the identified or identifiable natural person to whom personal data relates, where personal data means any information relating to that person and identifiability may be established directly or indirectly. The concept is defined within the GDPR's definitions and is the reference point for the rights afforded to individuals under that Regulation, including, among others, the right to be informed, the right of access, and the right to rectification. Scope notes: a data subject is generally understood to be a natural person, not a legal entity, and the term is native to the EU GDPR and mirrored in the UK GDPR; other regimes (for example the CCPA and CPRA, which use 'consumer', or HIPAA, which uses 'individual') frame the equivalent role differently, so treatment is not interchangeable across jurisdictions. This entry defines the actor only; it does not enumerate the full catalogue of data subject rights, the conditions or exemptions governing their exercise, response timelines, or the distinct obligations borne by a controller versus a processor when responding to those rights. The distinction between personal data and special category data, and between a data subject and a data controller or processor, is out of scope here.
Why it matters
The data subject is the reference point around which the entire rights framework of the EU GDPR and UK GDPR is built. Because the Regulation defines a data subject as the identified or identifiable natural person to whom personal data relates, correctly determining who qualifies as a data subject is a prerequisite for knowing whose rights apply and whose data triggers obligations. Getting this wrong at the outset, for example, by treating only direct identifiers as relevant, or by overlooking that individuals can be identifiable indirectly, can cause an organisation to underscope its compliance activities.
The concept also matters because it is jurisdictionally specific. 'Data subject' is native to the EU GDPR and mirrored in the UK GDPR, but equivalent roles are framed differently elsewhere: the CCPA and CPRA use 'consumer' and HIPAA uses 'individual'. Treating these terms as interchangeable is a common expert-level error, because the scope, definitions, and rights attached to each differ by regime. Organisations operating across borders generally need to map how each applicable framework describes the individual before assuming a single set of rights or definitions applies uniformly.
A further practical point is that the data subject is defined as a living natural person, not a legal entity. This distinction shapes which records fall within scope of the Regulation and which do not, and it underpins the individual rights the GDPR affords, including the right to be informed, the right of access, and the right to rectification. This entry identifies the actor only; the full catalogue of rights, the conditions and exemptions governing their exercise, and response timelines are addressed elsewhere.
Who it's relevant to
Inside Data Subject
Common questions
Answers to the questions practitioners most commonly ask about Data Subject.