An individual whose personal data is collected, held, or processed, particularly relevant in the context of data protection laws like GDPR.
Any identifiable person (customer, employee, patient) whose data rights - access, correction, deletion, portability - must be honored under privacy regulations. Data-subject governance includes workflows to validate identity, process data-subject requests within statutory timeframes, and maintain audit logs of all actions taken on an individual’s data.
After a user requests “right to be forgotten” under GDPR, a telecom provider’s privacy team verifies the user’s identity, deletes all associated call-detail records and billing data, and logs the deletion. They confirm compliance within the mandated one-month timeframe, documenting the process for regulatory audits.




