Data subject

The identified or identifiable natural person whom personal data relates to, as defined in GDPR Article 4(1), holding rights such as access, rectification, erasure and objection.

Full guide: Data Security Roles: Owner, Custodian, Controller and Processor for CISSP

A data subject is the individual that personal data is about. GDPR Article 4(1) builds the term into its definition of personal data: information relating to an identified or identifiable natural person. A person is identifiable if they can be identified directly or indirectly, for example by a name, an identification number or an online identifier. Customers, employees and website visitors are all data subjects once an organisation processes information about them.

Chapter III of GDPR gives data subjects rights including access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20) and objection (Article 21), and the data controller must be able to respond, often with help from its data processor. The term is easily confused with the access control subject, the active entity, such as a user or a process, that requests access to an object. A data subject may never touch the system at all. The ISC2 outline lists “users/subjects” together, but a data user works with the data, while the subject is the person it describes.

Exam relevance: a scenario is likely to describe an individual asking for a copy of their records or their erasure. Candidates are expected to identify that person as the data subject and the organisation that decides the processing as the controller.