Data subject
Also known as: data principal, identifiable person, individual, individual rights holder, person the data is about
A data subject is the identifiable person whom personal data relates to. Customers, employees, patients, applicants, website visitors and children can all be data subjects. The term refers to a living individual, not to the organisation holding the information. Their rights and how they may exercise them depend on the applicable jurisdiction.
Term explanation
At a glance
A data subject is the person at the centre of a personal-data record or activity. The term helps distinguish the individual from the organisations using or handling their information.
A person does not need to be named in a record to be a data subject. If they can be identified directly or indirectly from the information and available context, the information may relate to them. One activity can involve several categories of data subjects, such as customers, employees, emergency contacts and people appearing in security footage.
In plain language
Individuals can be data subjects in their personal, professional and public lives. A company director is a data subject where information concerns them as an identifiable individual. An employee is a data subject in an HR system. A sole trader’s business contact details may also relate to them personally.
An organisation itself is generally not a data subject, although records about an organisation may contain information about identifiable people. This distinction should be checked under the applicable law rather than assumed from the document title.
Why it matters
Privacy frameworks commonly give data subjects rights to receive information about processing, access their data, correct inaccuracies and raise concerns. Other rights—such as objection, deletion, restriction, portability or protection in automated decision-making—vary in wording, scope and exceptions.
A rights request does not need legal terminology. “Please send me the information you hold about me” may be an access request even if the person never says “data subject”. Staff should know how to recognise and route such requests.
Children and people who cannot exercise rights personally may be represented by a parent, guardian or other authorised person under the relevant rules. Identity and authority should be verified proportionately without collecting excessive new information.
A practical example
A school uses a learning platform. Pupils are data subjects because their names, work, progress and activity are recorded. Parents may also be data subjects where the platform holds their contact details. Teachers are data subjects in relation to their accounts and usage logs. The school should map each group rather than describing everyone simply as “users”.
General principles
Additional principles will be added during editorial review.
Practical next steps
Describe data-subject categories in processing records, notices, impact assessments and incident plans. Provide accessible contact routes. Record requests and deadlines, verify identity proportionately, search relevant systems and explain any lawful refusal or limitation. Design information for the real audience.
Related terms: personal data; identifiable person; controller; privacy notice; data-subject rights; child; consent
Jurisdiction guidance
Select more lenses from the Hub landing page to compare across jurisdictions.
No jurisdiction-specific guidance is published for this lens yet.
Related terms
- Data controller — controller
- Personal data and personal information — personal data
- Privacy notice — privacy notice
Sources & citations
Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.
- ACT — Cyber and Data Protection Act (Chapter 12 07) (ACT)
ACT · primary · Read in the Legal Library
- CDPG 4 of 2024 — The Right to Consent (CDPG-4-2024)
CDPG-4-2024 · cites · Read in the Legal Library
Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.