Data User
A data user is a person or organization that uses data as an input for their work or further processing, rather than owning or being responsible for the source dataset. In a governance context, they consume data that others collect, steward, or maintain. This is a governance role and should not be confused with a data subject, who is the individual the personal data is about.
In data governance frameworks, a data user is a role assigned to any individual or organizational unit that accesses and processes data as an input for further activity, without necessarily holding accountability for the data's origin, quality controls, or lifecycle management. The role is defined by consumption of data rather than ownership or stewardship, and access is commonly bounded by policy and, where data is sourced externally, by contractual instruments such as a Data Use Agreement (DUA). This role should be distinguished from data protection law concepts: a data user is not the same as a data subject (the identifiable individual to whom personal data relates), nor is it a defined controller or processor role under the EU GDPR or UK GDPR. Where a data user processes personal data, the applicable controller and processor obligations attach based on the actual processing relationship rather than the governance label, and accountability under governance frameworks requires demonstrable evidence of appropriate access, use, and controls. This entry does not address lawful bases for processing, cross-border transfer mechanics, retention requirements, or the specific terms that a DUA should contain.
Why it matters
The data user role matters because it separates the act of consuming data from accountability for that data's origin, quality, and lifecycle. In governance terms, distinguishing a data user from a data owner or data steward clarifies who is responsible for collecting, maintaining, and assuring the reliability of a dataset versus who merely draws on it as an input for further work. Without this separation, organizations risk assuming that whoever uses data also governs it, which can leave stewardship gaps and unclear responsibility for data quality controls.
The role also matters because the governance label does not by itself determine data protection obligations. A data user is not the same as a data subject, who is the identifiable individual the personal data is about, nor is it a defined controller or processor role under the EU GDPR or UK GDPR. Where a data user processes personal data, controller and processor obligations attach based on the actual processing relationship rather than on the internal governance title. Treating the two vocabularies as interchangeable can lead teams to overlook obligations that arise from the substance of the processing.
Because accountability under governance frameworks requires demonstrable evidence of appropriate access, use, and controls rather than stated intent alone, the data user role is a practical anchor for demonstrating that access to data is bounded, purposeful, and documented. Where data is sourced externally, contractual instruments such as a Data Use Agreement typically define the permitted scope of use, reinforcing that consumption is not unconstrained.
Who it's relevant to
Inside Data User
Common questions
Answers to the questions practitioners most commonly ask about Data User.