Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Compliance, Standards and Contracts

What Is a Data Subject Under UK GDPR?

By the Assured Cyber Protection team · Updated 2026 · Reviewed

A data subject is the living individual that a piece of personal data is about. If your business holds a customer’s name, a staff member’s payroll record or a website visitor’s IP address, each of those people is a data subject under UK GDPR, and the law exists mainly to protect them. Getting this definition right matters, because almost every duty you have as a business, and every cyber insurance claim that follows a breach, is framed around the rights of data subjects.

The legal definition

Under UK GDPR, a data subject is an identified or identifiable living individual to whom personal data relates. Break that down:

  • Living. The rules apply to living people only. Information about someone who has died is not personal data under UK GDPR, though other duties of confidentiality can still apply.
  • Individual. A data subject is always a natural person, never a company. Data about a limited company is not personal data, although a named contact at that company is a data subject.
  • Identified or identifiable. The person does not have to be named. If they can be singled out directly or indirectly, for example by an online identifier, a customer number, or a combination of details that points to one person, they are identifiable and the data counts.

This definition was carried over from the EU GDPR into UK law and has not been rewritten. The Data (Use and Access) Act 2025 amends UK GDPR and the Data Protection Act 2018 rather than replacing them, so the core meaning of “data subject” is the same as it has been since 2018.

Data subject, controller and processor

These three terms are easy to muddle, and cyber insurers and auditors will expect you to know which one you are.

  • The data subject is the person the data is about.
  • The controller is the organisation that decides why and how the data is processed. Most businesses are controllers of their own customer and staff data.
  • The processor acts on the controller’s instructions, such as a payroll bureau or a cloud email provider.

One business can be a controller for some data and a data subject in another relationship, for example its own director whose personal details sit in a supplier’s records. For how these roles map onto UK enforcement, see who enforces GDPR in the UK.

The rights a data subject holds

UK GDPR gives data subjects a set of rights that your business must be ready to honour, usually within one month:

  • The right to be informed about how their data is used.
  • The right of access (the data subject access request, or DSAR).
  • The right to rectification of inaccurate data.
  • The right to erasure, often called the right to be forgotten.
  • The right to restrict processing.
  • The right to data portability.
  • The right to object to certain processing.
  • Rights relating to automated decision-making and profiling.

Not every right applies in every situation, and some have exemptions, but you must be able to recognise a request and respond to it. These rights sit alongside the wider principles of data protection that govern how you handle the data in the first place.

What the 2025 DUAA changed

The Data (Use and Access) Act 2025 keeps the definition of a data subject but adjusts how you handle their requests. Most notably it writes a “reasonable and proportionate” standard into law for subject access requests, confirming that you are expected to make reasonable efforts to find the requested data rather than an exhaustive, unlimited search. It also begins reshaping the Information Commissioner’s Office into a new body, the Information Commission. If you have documented DSAR procedures, review them against the updated rules. You can read the regulator’s own summary on the ICO website.

Why this matters for cyber security and insurance

Data subjects are at the centre of what a breach actually costs. When personal data is exposed, it is the affected data subjects who must be notified, who may claim compensation, and whose numbers drive the size of any Information Commissioner’s Office fine. A cyber insurance policy responds to that exposure, so insurers ask how much personal data you hold and how many data subjects a single incident could affect. Knowing exactly who your data subjects are, and where their data sits, is the first step in both compliance and getting the cover priced correctly. For grounding on the wider framework, see our overview of UK GDPR and the Data Protection Act 2018.

Frequently asked questions

Is a data subject always a person? Yes. A data subject is always a living individual, never an organisation. Information about a company is not personal data, but a named employee, director or sole trader within that company is a data subject in their own right.

Can a business be a data subject? A business itself cannot, because it is not a natural person. However, the individuals connected to a business, such as its owners, staff or customers, are all data subjects, and their personal data held by another organisation is protected in the usual way.

Are employees data subjects? Yes. Staff are data subjects in relation to the personal data their employer holds about them, including HR files, payroll and monitoring records. Employees have the same rights over that data, including the right to make a subject access request, as customers do.

What is the difference between a data subject and a data controller? The data subject is the person the data is about. The data controller is the organisation that decides why and how that data is processed. The controller owes duties to the data subject, including keeping the data secure and honouring the individual’s rights.

Does UK GDPR still use the term data subject after the DUAA? Yes. The Data (Use and Access) Act 2025 amends UK GDPR rather than replacing it, and the term data subject remains in use with the same core meaning. The main practical change is a clearer “reasonable and proportionate” standard for handling subject access requests.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.