Join our Newsletter — 33% off our NHI Course

Identity Of The Data

The identity of the data is the link between a record and the person or data subject it belongs to. In privacy operations, that context determines whether information is sensitive, which regulations apply, and how an organisation should respond to access, deletion, or breach notification requests.

What identity of the data means in privacy operations

Identity of the data is not just a label, it is the link that makes a record attributable to a specific person or data subject. That link determines whether the record is personal data, how it should be handled, and which obligations apply across access, deletion, correction, retention, and breach response.

In practice, identity is what turns an otherwise anonymous or ambiguous record into regulated information. The same dataset can move between low-risk and high-impact handling depending on whether the organisation can reliably connect it to a person, household, customer, employee, or other data subject.

Data identity sits at the centre of privacy classification because it affects both sensitivity and context. A record that can be tied to a person may trigger access controls, lawful-basis analysis, cross-border restrictions, or special handling under privacy policy, while the same record without that link may be treated differently.

The practical challenge is that identity is often assembled from multiple fields, systems, or indirect identifiers rather than one obvious attribute. That means organisations need to think about re-identification risk, not only about whether a single field names someone directly.

Where this link is weak or inconsistent, classification becomes unreliable. One team may treat a record as anonymous while another can readily re-identify it, creating gaps in governance, disclosure decisions, and incident handling.

How identity shapes access, deletion, and breach response

Once a record is tied to a data subject, operational obligations change. Subject access requests, deletion requests, rectification requests, and notifications about exposure all depend on being able to find the right records and prove they belong to the right person.

This is why identity resolution, indexing, and record linkage are privacy control points, not just data-management conveniences. If the organisation cannot confidently connect records to the correct individual, it may miss required disclosures, over-delete unrelated data, or fail to respond within expected timelines.

For security and privacy teams, the identity link also affects incident scoping. A breach involving a record that can be linked back to a person is generally more consequential than a purely operational dataset, because it changes what was exposed and how the event must be assessed.

Guidance on identity-related governance and lifecycle control is often discussed in broader identity programmes such as the Identity Security Programme Guide and the Ultimate Guide to NHIs, regulatory and audit perspectives, which are useful when record ownership, governance, and auditability intersect.

Common failure modes and edge cases

The most common failure is assuming that removing a name makes a record anonymous. In reality, direct identifiers, quasi-identifiers, and contextual clues can still allow a person to be singled out or re-identified when datasets are joined.

Another edge case is identity drift, where the record still points to a person but the reference is stale, duplicated, or reassigned. That can cause incorrect disclosures, wrong deletions, or false confidence that a record belongs to the right subject.

Identity can also be ambiguous in shared, household, delegated, or organisational contexts. In those cases the organisation must decide whether the record belongs to one person, several people, or a role-based account of activity, because the answer changes how privacy requests and controls should be applied.

For a deeper treatment of how identity context affects record ownership and governance across the lifecycle, see the NHI Lifecycle Management Guide, which maps how ownership, discovery, and offboarding reduce drift and orphaned records.

Risk and Threat Considerations

When identity of the data is weak, organisations can misclassify sensitive records, mishandle subject requests, or disclose more than intended during an incident response. The risk is not only privacy non-compliance, but also operational error caused by treating linkable data as if it were anonymous.

Failure mechanism: Records are stored, shared, or transformed in ways that preserve re-identification paths, while the organisation loses track of which records remain attributable to a person.

Impact: Data subjects may be wrongly exposed, omitted from rights requests, or mishandled during breach notification, deletion, or retention workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST Privacy Framework set the technical controls, while GDPR defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-3 — Access Enforcement Identity-linked records need enforced access boundaries based on data subject context.
AU-6 — Audit Record Review, Analysis, and Reporting Identity attribution and record linkage depend on reviewable evidence trails for privacy operations.
MP-6 — Media Sanitization Identity-bearing records require controlled disposal when subject records are deleted or retired.
Recommendation — Apply AC-3 to restrict access to records whose identity link changes handling obligations. Use AU-6 to review identity-linked record access and disclosure activity. Apply MP-6 to sanitize identity-linked data when retention or deletion obligations require removal.
GDPR Data subject rights and privacy-by-design obligations Identity of the data determines whether GDPR subject rights, access, deletion and breach duties apply.
Recommendation — Use GDPR to govern records that can be linked to an identifiable natural person.
NIST SP 800-63 Digital Identity Guidelines Identity resolution and assurance inform when a record can be safely tied to a person.
Recommendation — Use 800-63 concepts to strengthen identity proofing where record linkage must be reliable.
NIST Privacy Framework Govern-P Identify-P Communicate-P Protect-P Identity of the data is a privacy classification and lifecycle concern addressed by the Privacy Framework.
Recommendation — Use the Privacy Framework to manage identity-linked records across governance and protection.