GDPR Control vs Data Ownership: Why Personal Data Is Not “Owned”
@towfiqu999999 on Unsplash
There is a persistent misconception that the GDPR gives individuals ownership of their personal data. This framing is misleading and creates expectations organisations often cannot meet. The GDPR regulates control of personal data, not ownership. Questions of ownership are dealt with separately under intellectual property (IP) law. Sometimes, data may attract IP rights, but this is neither automatic nor inherent in the personal data itself.
Ownership and Control: How the GDPR Fits
The GDPR simply does not regulate ownership of personal data, but its protection, control and who is responsible for what when using it.* It balances people’s rights over the data and organisations’ interests when using it through the lawful bases and various assessments.
People have rights over their data which gives them control as regulatory protection, not property rights. If people owned their data, they could sell, licence it, transfer it; however, none of us can demand payments by organisations for them using our personal data. You can only demand that they stop processing it if it’s unlawful.
The Role of IP Law
IP law is very different. IP law protects human creativity and ideas when they are expressed in something tangible, for example a book, this blog, a song, software, database.
You can have different IP depending on what you have created, for example the simple and beautiful copyright or the complex and scientific patent.
IP rights and personal data rights do overlap. A photo of me is my personal data because I am directly identifiable from it, but it is not my copyright unless I took it.** The IP may be my friend’s or the professional photographer’s I paid for headshots for my business website.
IP rights don’t override GDPR obligations and vice versa. They can exist side by side but are materially different. Mixing them confuses people, organisations, and it’s an easy trap to fall into.
Why “Ownership of Personal Data” Fails as an Argument
It does not determine whether there is a lawful basis for processing.
It does not expand, reduce, or otherwise change the scope of data subject rights.
It does not resolve complaints or disputes under data protection law.
It is irrelevant to whether an organisation is acting as a controller or a processor.
It does not establish or protect intellectual property rights, where any exist.
Why the Distinction Matters in Practice
Individuals may expect their data protection rights to allow more control than the GDPR provides.
Compliance teams may make flawed decisions by conflating data protection law with IP law.
Complaints and disputes escalate when organisations cannot clearly explain control versus ownership.
Organisations may fail both to protect their own assets and to meet their regulatory obligations.
What to Say Instead of “Owning Data”
Unfortunately, our choice of words - “I own my personal data” - is what gets us into a pickle. The real source of confusion is often language.
So here is what you can say in different scenarios:
Rights requests: “This is my data and I own it, delete it.”
A key scenario to differentiate between ownership and control.
You can reply with: “It is data relating you because it identifies you, but you don’t own it as property. Nevertheless, we can look into what we can delete.”
Employment and HR systems: “We own staff’s personal data.”
Holding data for a certain purpose is not the same as owning it.
Instead, you can say: “In the HR team we use data responsibly so we can fulfil our function as the employer.”
Customer relationships: “This is our customer’s data, they own it.”
Treat with care, this can be tricky and both GDPR and IP may apply.
Clarify: “Is this personal data the customer has provided to us as the supplier? If so, it doesn’t necessarily belong to them but we should ensure we use their IP lawfully (e.g., have a licence agreement, copyright assignment).
Data controllership and ownership are not the same; sometimes, they overlap. We all create some sort of IP just as much as we leave our personal data in the digital world, so differentiating between the two is beneficial not just to do our jobs well but in our personal lives.
* UK GDPR Article 1(1), recitals 4,6, and all the provisions about what controllers and processors must do.
** Copyright, Designs and Patents Act 1988, section 9