What is a data subject?

Who is a "data subject" under the GDPR? This article explains who qualifies for protection, why legal persons and deceased individuals are generally excluded, and how the GDPR regulates the processing of personal data regardless of any relationship between the individual and the controller.

What is a data subject?
ChatGPT modified from - Film star Helen Twelvetrees, Rutland Gates, Bellevue Hill, Sydney, early 1936 / photograph by Sam Hood — State library of New Shout Wales’ Photostream

Under GDPR, a data subject is the individual to whom the personal data relates.

GDPR does not require the individuals to reside in any particular jurisdiction and does not extend protections to the information of legal persons (although Member State implementations of GDPR may do so).

Dead individuals are not natural persons and therefore their information is not subject to GDPR (although the information on dead individuals may also refer to living persons, in which case it can come under the scope of data protection law).

The extent to which data protection rules may apply before birthdepends on the general position of the specific legal systems about the protection of rights of the unborn in general which should be considered together with the idea that the purpose of data protection rules is to protect the individual.

Unlike privacy law, the GDPR does not depend on the nature of the relationship between the data subject and the individual or organization that holds the data (in GDPR lingo, the controller or the processor.) Its rules apply regardless of whether the parties have a contractual, fiduciary, confidential, or any other preexisting relationship. Instead of justifying imposing obligations due to the private nature of the information or the confidentiality in the relationship, the GDPR regulates the processing of personal data itself. It imposes obligations on controllers and processors whenever they collect, use, disclose, store, or otherwise process personal data. Accordingly, concepts such as "breach of confidence" are not the foundational to the GDPR. Rather, confidentiality is one of several obligations imposed by the Regulation as part of the broader duty to ensure the security and integrity of personal data.

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe