A data subject is one of the three main actors under GDPR . It’s a person whose personal data can be collected. Personal data includes all data that can be used to directly or indirectly identify that person. Data subjects have various rights that they may exercise in respect of Data controller s, including:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (also known as the right to be forgotten) (Art. 17)
  • Right to restrict processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object to processing (Art. 21)

Read more about the data subjects – 4 steps to determine if your tech partner is GDPR-compliant.


  • How to recover lost conversions without adding compliance risk

    Not every visitor who leaves is lost. Some just need a nudge. Funnel Recovery brings them back to the form, booking or application they started, using analytics and data activation tools your compliance team already approved.

  • PHI and PII

    HIPAA violations and fines: What healthcare organizations need to know

    Quick summary HIPAA violations happen when a covered entity or business associate fails to meet the HIPAA Privacy, Security or Breach Notification Rule. Civil penalties range from a few hundred dollars to more than $2 million per violation, set across four tiers based on how much the organization knew.  What this guide covers: HIPAA violation…