Glossary
2026-07-27 00:00 Glossary

Data Subject: Legal Definition and Meaning

A data subject is any living natural person who can be identified, directly or indirectly, through personal data held or processed by another party. The concept sits at the centre of modern privacy law and determines who holds enforceable rights over personal information. For businesses operating across borders, correctly identifying who qualifies as a data subject - and what obligations that status triggers - is a foundational compliance requirement.

This guide explains the legal definition of a data subject, the rights attached to that status, how the concept applies in different business contexts, and the practical consequences of misidentifying or overlooking data subjects in commercial operations.

What a data subject is: the core legal definition

A data subject is a natural person - a human being, as opposed to a legal entity such as a company or trust - whose personal data is being collected, stored, used, transferred or otherwise processed. The definition is deliberately broad. It covers any individual who can be identified, not only by name, but by reference to an identifier such as an identification number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.

The European Union';s General Data Protection Regulation, commonly known as the GDPR, provides the most widely cited statutory definition of a data subject. Under Recital 26 and Article 4(1) of the GDPR, the key test is identifiability: if a reasonable effort could link a piece of data to a specific living person, that person is a data subject. The word "reasonable" is important - it excludes purely theoretical or disproportionately costly identification methods, but it does not require that identification be easy or immediate.

Several points follow from this definition:

  • Only living individuals qualify. Deceased persons are generally excluded, though some national laws extend limited protections posthumously.
  • Legal entities - corporations, partnerships, foundations - are not data subjects, even if data about them is processed.
  • Employees, customers, website visitors, contractors and job applicants can all be data subjects simultaneously, depending on which data is held about them.
  • Pseudonymised data - data where direct identifiers have been replaced by codes - may still relate to a data subject if re-identification is reasonably possible.

The practical implication is that almost every business, regardless of size or sector, processes personal data about data subjects as a routine matter of operation.

How identifiability determines data subject status

The concept of identifiability is the operational heart of the data subject definition. A person is identifiable when they can be singled out from a group, even without knowing their name. Courts and regulators across multiple jurisdictions have consistently held that identifiability must be assessed in context, taking into account all means reasonably likely to be used by the controller or by any third party.

Dynamic IP addresses, for example, have been found by the Court of Justice of the European Union to constitute personal data in cases where the internet service provider could link the address to a specific subscriber. This illustrates a critical nuance: data that appears anonymous to one party may still relate to an identifiable data subject when combined with information held by another party.

Indirect identifiability arises frequently in commercial settings. A dataset containing job title, employer, department and approximate age may not name anyone, but in a small organisation it may point unambiguously to one individual. In such cases, that individual is a data subject, and the organisation processing the dataset must treat it accordingly.

A common mistake made by businesses entering new markets is to assume that aggregated or lightly anonymised data falls outside privacy law entirely. In practice, regulators apply a contextual test. If there is a realistic pathway to identification - through combination with other datasets, through technical means available to the controller, or through information accessible to third parties - the data subject concept applies and the full suite of legal obligations is engaged.

Rights attached to data subject status

Being a data subject is not a passive classification. It carries a set of enforceable legal rights that organisations must be prepared to honour. The specific rights vary by jurisdiction, but the framework established by the GDPR has become a reference point for privacy legislation globally, including laws modelled on it in the United Kingdom, Brazil, Japan, South Korea, Canada and many other countries.

The principal rights typically associated with data subject status include:

  • The right to be informed about how personal data is collected and used, usually through a privacy notice.
  • The right of access, meaning the right to obtain a copy of personal data held about the individual and information about how it is processed.
  • The right to rectification of inaccurate or incomplete personal data.
  • The right to erasure, sometimes called the right to be forgotten, allowing individuals to request deletion of their data in defined circumstances.
  • The right to restrict processing, which limits what a controller can do with data while a dispute is resolved.

Beyond these core rights, many frameworks also recognise a right to data portability - allowing individuals to receive their data in a machine-readable format and transfer it to another service provider - and a right to object to processing carried out on certain legal bases, including direct marketing and profiling.

For businesses, these rights translate into operational obligations. Organisations must have processes in place to receive, verify and respond to requests from data subjects within statutory timeframes. Under the GDPR, for instance, controllers must respond to access requests within one month, with a possible extension of two further months for complex or numerous requests. Failure to respond, or responding inadequately, can result in regulatory complaints and enforcement action.

If your organisation is uncertain whether its current processes adequately handle data subject requests, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.

Data subjects in different business contexts

The data subject concept applies across a wide range of commercial relationships, and its implications differ depending on the nature of the processing activity.

In an employment context, every employee is a data subject with respect to the HR data their employer holds. This includes payroll records, performance appraisals, disciplinary files, health information, and data generated by workplace monitoring systems. Employers must have a lawful basis for each category of processing, provide employees with appropriate privacy information, and respond to any exercise of data subject rights. Many jurisdictions impose additional restrictions on processing sensitive categories of employee data, such as health or trade union membership information.

In a customer relationship, individuals who purchase goods or services, register for an account, or subscribe to a newsletter are data subjects. Their contact details, purchase history, browsing behaviour and payment information are all personal data. Businesses must be able to demonstrate a lawful basis for collecting and using this data - typically consent, contract performance, or legitimate interests - and must honour any requests to access, correct or delete it.

In a business-to-business setting, the position is more nuanced. A company is not itself a data subject, but the individual employees or representatives of that company whose contact details are processed - names, email addresses, phone numbers - are data subjects in their own right. This is a point frequently overlooked by organisations that assume B2B data falls entirely outside privacy law.

Website operators face a particularly broad data subject population. Any visitor whose device generates an IP address, or whose behaviour is tracked through cookies or analytics tools, may qualify as a data subject if that data is retained and could be linked to an identifiable individual. This is why cookie consent mechanisms and privacy policies have become standard features of commercial websites operating in privacy-regulated markets.

A practical scenario illustrates the stakes. A software company based in one country sells a subscription product to businesses across Europe. Its customers are legal entities, but the individuals who use the software - employees of those businesses - are data subjects. The software company processes their names, email addresses, usage logs and potentially location data. It must therefore comply with applicable privacy law with respect to each of those individuals, not merely with respect to its corporate customers.

The data subject in the broader privacy law framework

The data subject does not exist in isolation. Privacy law structures the relationship between three principal actors: the data subject, the data controller, and the data processor. Understanding how a data subject fits into this framework is essential for any organisation designing a compliance programme.

A data controller is the natural or legal person, public authority, agency or other body that determines the purposes and means of processing personal data. A data processor is a party that processes personal data on behalf of the controller. The data subject is the individual whose data is at stake. These roles can overlap in complex arrangements - a company may be a controller with respect to its customers and a processor with respect to data it handles on behalf of a client.

The GDPR and equivalent legislation impose obligations primarily on controllers and processors, but those obligations exist specifically to protect data subjects. The lawful basis requirements, the data minimisation principle, the purpose limitation principle, and the storage limitation principle are all mechanisms designed to ensure that processing serves a legitimate purpose and does not unduly infringe on the rights and freedoms of data subjects.

Several other legal instruments are relevant to the data subject concept beyond the GDPR. The Council of Europe';s Convention 108+, the updated international treaty on data protection, uses a substantially similar definition. The California Consumer Privacy Act in the United States uses the term "consumer" rather than "data subject" but covers similar ground. Brazil';s Lei Geral de Proteção de Dados Pessoais, known as the LGPD, explicitly adopts the data subject terminology and mirrors many GDPR provisions. Organisations operating globally must map their data subject populations against each applicable legal framework.

A second practical scenario: a multinational retailer collects personal data from customers in the European Union, the United Kingdom, Brazil and California. Each customer is a data subject under at least one, and potentially several, overlapping legal regimes. The retailer must identify which law applies to each data subject, what rights that law grants, and what obligations it imposes on the retailer as controller. This mapping exercise is not optional - it is a prerequisite for lawful operation.

Practical compliance obligations triggered by data subject relationships

Recognising who your data subjects are is the first step. The second is building the operational infrastructure to meet the obligations that recognition creates.

The starting point is a data inventory or record of processing activities. Under Article 30 of the GDPR, most controllers are required to maintain written records of their processing activities, including the categories of data subjects affected. This record serves as the foundation for all other compliance work - it identifies where data subjects are present, what data is held about them, and on what legal basis it is processed.

Privacy notices must be provided to data subjects at or before the point of data collection. These notices must explain, in plain language, who is collecting the data, for what purpose, on what legal basis, how long it will be retained, and what rights the data subject can exercise. Regulators have consistently criticised notices that are excessively long, written in legal jargon, or buried in terms and conditions.

Consent, where it is the chosen legal basis, must be freely given, specific, informed and unambiguous. Pre-ticked boxes, bundled consent and consent obtained as a condition of service where processing is not strictly necessary for that service are all problematic. Data subjects must be able to withdraw consent as easily as they gave it.

Data subject access requests, often abbreviated as DSARs, require particular attention. Organisations must have a clear internal process for receiving requests, verifying the identity of the requester, locating all relevant data, and compiling a response within the statutory deadline. Many organisations underestimate the operational burden of DSARs, particularly where data is held across multiple systems, legacy databases or third-party processors.

Data breach notification obligations also connect directly to data subjects. Where a breach is likely to result in a high risk to the rights and freedoms of data subjects, controllers are generally required to notify the affected individuals without undue delay. This requires the organisation to be able to identify which data subjects are affected, what data was compromised, and what harm might result.

For organisations building or reviewing their data subject management framework, contact info@vlolawfirm.com. We can assist with documents, filings and compliance programme design.

Frequently asked questions

Is a company or legal entity ever a data subject?

No. Under virtually all major privacy frameworks, including the GDPR, the LGPD and the UK Data Protection Act, only natural persons - human beings - can be data subjects. A corporation, partnership or other legal entity does not qualify, even if data about it is collected and processed. However, this distinction requires care in practice. When a business processes data about the individual employees or representatives of a corporate client - their names, email addresses or phone numbers - those individuals are data subjects in their own right, even though the corporate client is not. Organisations that assume all B2B data falls outside privacy law often discover this distinction during regulatory audits or when responding to individual access requests.

How quickly must an organisation respond to a data subject';s request, and what does it cost to comply?

Response timelines are set by the applicable law. Under the GDPR and UK GDPR, the standard deadline is one calendar month from receipt of the request, extendable by two further months where the request is complex or numerous, provided the requester is notified of the extension within the first month. Most privacy laws modelled on the GDPR follow similar timelines, though some jurisdictions set shorter or longer periods. In terms of cost, organisations generally cannot charge a fee for handling data subject requests unless they are manifestly unfounded or excessive. The real cost is internal - staff time, system searches and legal review. Organisations with well-designed data inventories and response procedures handle requests far more efficiently than those without.

What happens if an organisation fails to recognise or respond to a data subject';s rights?

The consequences operate on several levels. Regulatory authorities can investigate complaints from data subjects and impose corrective measures, including orders to comply, temporary bans on processing, and administrative fines. Under the GDPR, fines for serious infringements can reach significant percentages of global annual turnover, though regulators also issue warnings and reprimands for less severe cases. Beyond regulatory action, data subjects in many jurisdictions have the right to seek compensation through courts for material or non-material damage caused by unlawful processing. Reputational damage is a further practical risk, particularly where a failure to honour data subject rights becomes publicly known. Organisations that invest in proactive compliance generally face lower enforcement risk than those that treat privacy obligations as a secondary concern.

Conclusion

The data subject is the central figure in privacy law - the individual whose rights, interests and personal information the entire regulatory framework is designed to protect. For businesses, correctly identifying data subjects, understanding the rights they hold, and building operational processes to honour those rights is not optional. It is a legal requirement with real enforcement consequences.

VLO Law Firms advises international clients on data subject compliance, privacy law obligations and personal data governance. We can assist with data inventories, privacy notice drafting, data subject request procedures and cross-border compliance mapping. To request a consultation, contact: info@vlolawfirm.com