Skip to content

Privacy Hub · plain-language reference

← Privacy Hub

Data subject

Also known as: data principal, identifiable person, individual, individual rights holder, person the data is about

A data subject is the identifiable person whom personal data relates to. Customers, employees, patients, applicants, website visitors and children can all be data subjects. The term refers to a living individual, not to the organisation holding the information. Their rights and how they may exercise them depend on the applicable jurisdiction.

ZW_CDPA
EU_GDPR
GB_UK_GDPR
v2 · published 31 Jul 2026

Term explanation

At a glance

A data subject is the person at the centre of a personal-data record or activity. The term helps distinguish the individual from the organisations using or handling their information.

A person does not need to be named in a record to be a data subject. If they can be identified directly or indirectly from the information and available context, the information may relate to them. One activity can involve several categories of data subjects, such as customers, employees, emergency contacts and people appearing in security footage.

In plain language

Individuals can be data subjects in their personal, professional and public lives. A company director is a data subject where information concerns them as an identifiable individual. An employee is a data subject in an HR system. A sole trader’s business contact details may also relate to them personally.

An organisation itself is generally not a data subject, although records about an organisation may contain information about identifiable people. This distinction should be checked under the applicable law rather than assumed from the document title.

Why it matters

Privacy frameworks commonly give data subjects rights to receive information about processing, access their data, correct inaccuracies and raise concerns. Other rights—such as objection, deletion, restriction, portability or protection in automated decision-making—vary in wording, scope and exceptions.

A rights request does not need legal terminology. “Please send me the information you hold about me” may be an access request even if the person never says “data subject”. Staff should know how to recognise and route such requests.

Children and people who cannot exercise rights personally may be represented by a parent, guardian or other authorised person under the relevant rules. Identity and authority should be verified proportionately without collecting excessive new information.

A practical example

A school uses a learning platform. Pupils are data subjects because their names, work, progress and activity are recorded. Parents may also be data subjects where the platform holds their contact details. Teachers are data subjects in relation to their accounts and usage logs. The school should map each group rather than describing everyone simply as “users”.

General principles

Additional principles will be added during editorial review.

Practical next steps

Describe data-subject categories in processing records, notices, impact assessments and incident plans. Provide accessible contact routes. Record requests and deadlines, verify identity proportionately, search relevant systems and explain any lawful refusal or limitation. Design information for the real audience.

Related terms: personal data; identifiable person; controller; privacy notice; data-subject rights; child; consent

Jurisdiction guidance

Select more lenses from the Hub landing page to compare across jurisdictions.

GLOBAL
Global baseline

No jurisdiction-specific guidance is published for this lens yet.

Sources & citations

Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.


Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.