Skip to main content
Category: Impact Assessments & Documentation

Categories of Recipients

Also known as: Recipients or Categories of Recipients
Simply put

Categories of recipients refers to the groups or types of people and organisations that a controller shares personal data with, described by class rather than always by name. Organisations generally have to tell individuals who receives their data, either by identifying specific recipients or by describing the categories they fall into. This information is typically included in a privacy notice and may also need to be disclosed when someone makes a data subject access request.

Formal definition

Under the UK GDPR and EU GDPR, controllers must inform data subjects of 'the recipients or categories of recipients of the personal data, if any' as part of the transparency obligations when personal data is collected (Articles 13 and 14). A 'recipient' is broadly understood to include any party to whom personal data is disclosed, which can encompass other controllers, processors, and, per ICO guidance, anyone that processes the data. Controllers may satisfy this requirement by naming specific recipients or by describing them at the level of categories, and these details are also typically maintained in records of processing activities. The Court of Justice of the European Union has held that, in response to a data subject access request, a data subject is generally entitled to be told the identity of the actual recipients rather than only the categories, subject to the circumstances of the case; practitioners should verify the precise scope and any national or regulatory divergence against current official texts and guidance. This entry addresses the transparency and disclosure concept and does not cover the separate rules governing international transfers or the distinct roles of controller and processor.

Why it matters

Transparency about who receives personal data is a foundational element of the UK GDPR and EU GDPR information obligations. Individuals cannot meaningfully exercise their rights, assess risks to their data, or hold organisations accountable if they do not know who their information is being shared with. By requiring controllers to disclose the recipients or categories of recipients (Articles 13 and 14), the Regulation aims to reduce the information asymmetry between organisations and the people whose data they process. Failing to provide this information, or describing recipients in vague or misleading terms, can undermine the lawfulness of processing and expose an organisation to regulatory scrutiny.

The practical stakes have increased following case law from the Court of Justice of the European Union, which held that a data subject responding to an access request is generally entitled to be told the identity of the actual recipients rather than only the categories, subject to the circumstances of the case. This means the level of detail sufficient in an upfront privacy notice may not always satisfy a data subject access request, and organisations should not assume that describing recipients only by class will discharge their obligations in every situation. Practitioners should verify the precise scope of this ruling and any national or regulatory divergence against current official texts and guidance.

Because 'recipient' is understood broadly to include other controllers, processors, and, per ICO guidance, anyone that processes the data, keeping an accurate account of recipients supports several overlapping compliance functions at once. It feeds the transparency information given to individuals, informs how the organisation responds to access requests, and aligns with the records of processing activities that controllers typically maintain. Getting this wrong tends to create compounding problems across all three areas.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads are typically responsible for ensuring that privacy notices accurately describe the recipients or categories of recipients and that these are kept consistent with the records of processing activities. They should also consider how the organisation will respond when an access request calls for the identity of actual recipients rather than only categories, and monitor for regulatory divergence on that point.
Legal and Compliance Teams
Legal and compliance teams advise on how much detail is required in transparency information and access request responses, and on where category-level descriptions are sufficient versus where naming specific recipients may be expected. They should track evolving case law, including the CJEU position on disclosing actual recipients, and verify its scope against current official texts and guidance.
Engineers and Data Architects
Those building and maintaining systems that share personal data help identify who actually receives data, including other controllers, processors, and any party that processes the data. Accurate data-flow mapping supports both the transparency information given to individuals and the organisation's ability to identify actual recipients when required.
Individuals Exercising Their Rights
People whose personal data is processed rely on this information to understand who their data is shared with and to decide whether to seek further detail. Under CJEU case law, an individual making an access request is generally entitled to be told the identity of the actual recipients, subject to the circumstances of the case.

Inside Categories of Recipients

Recipient
Under the GDPR, a recipient is generally any natural or legal person, public authority, agency, or other body to which personal data is disclosed, whether a third party or not. The concept is broader than 'third party' and can include entities within the same corporate group. Practitioners should verify the precise definition against the current official text of the Regulation.
Category of recipients
Rather than naming each individual recipient, controllers may in some cases describe recipients by category (for example, by type of organisation or function they perform). Whether categories alone suffice, or specific named recipients are required, is subject to assessment and can depend on regulator expectations and the transparency obligations owed to data subjects.
Processors as recipients
Processors that receive personal data on the controller's behalf can fall within the notion of recipients. Their relationship with the controller is typically governed by a data processing agreement (Article 28). Note that a processor's role is distinct from that of a controller, and the two should not be conflated.
Transparency function
Information about recipients or categories of recipients typically forms part of the information provided to data subjects and may appear in records of processing activities. It supports the individual's ability to understand and exercise their rights. The exact placement and detail required should be confirmed against applicable provisions and guidance.
Relationship to international transfers
Where recipients are located outside the EEA, additional considerations concerning transfer mechanisms and safeguards may apply. Adequacy decisions, transfer tools, and supplementary measures evolve over time and should not be treated as a fixed position.

Common questions

Answers to the questions practitioners most commonly ask about Categories of Recipients.

Does listing 'categories of recipients' instead of naming each specific recipient reduce transparency obligations?
Not exactly. The GDPR transparency provisions generally allow a controller to disclose either the recipients or the categories of recipients. Using categories is a permitted approach rather than a reduction of obligations, but the categories must still be meaningful enough to give individuals a genuine understanding of who receives their data. Regulators and case law have indicated that where a data subject requests specific recipient identities, controllers may in many cases need to name them unless an exception applies, so relying on categories is not a blanket way to avoid identifying recipients. You should verify the current position against the applicable GDPR text and relevant guidance, as regulator interpretation can vary.
Are 'recipients' the same thing as 'third parties' under the GDPR?
No, though the terms overlap and are often confused. Under the GDPR definitions, a recipient is broadly any natural or legal person, public authority, agency, or other body to which personal data is disclosed, which can include processors and other entities within your own organisation. A third party is a narrower concept that generally excludes the data subject, the controller, the processor, and persons authorised to process data under their direct authority. A recipient may therefore be a third party, but not every recipient is a third party. Public authorities receiving data in the context of a particular inquiry are, in most cases, not treated as recipients for these purposes.
How specific do the categories of recipients need to be in a privacy notice?
The categories should typically be specific enough to be genuinely informative to the data subject, rather than so generic that they convey little. Grouping by function or type, for example describing IT hosting providers, payment processors, or regulatory authorities, is a common approach. The appropriate level of granularity is a matter of assessment and depends on the context, the sensitivity of the data, and the expectations of the individuals concerned. Where categories are too broad to be meaningful, transparency requirements may not be satisfied, so review the framing against applicable guidance.
Should categories of recipients in a privacy notice match those in the record of processing activities?
It is generally good practice for these to be consistent, since discrepancies can undermine both transparency and accountability. The record of processing activities and the information provided to data subjects serve different functions, so the level of detail may legitimately differ, but the underlying facts about who receives the data should align. Where they diverge, you should be able to explain why. Treat consistency across documentation as a matter of internal governance and verify the specific documentation requirements against the current text.
How should categories of recipients be handled when personal data is transferred outside the EEA?
Where recipients are located outside the EEA, the transparency information typically needs to address not only the categories of recipients but also the fact of the international transfer and the relevant transfer mechanism or safeguard relied upon. Transfer tools, adequacy decisions, and any supplementary measures evolve over time, so the mechanism cited should reflect the current position rather than a fixed snapshot. Identifying the category of recipient and the destination together helps individuals understand where their data goes and under what protections, subject to assessment of the specific transfer.
How do you keep categories of recipients accurate as vendors and data flows change?
Maintaining accuracy generally requires periodic review of your data flows and the entities receiving personal data, so that new categories of recipients are added and obsolete ones removed. Linking recipient categories to vendor onboarding, procurement, and change management processes can help ensure that documentation and privacy notices stay current. Because the appropriate categories depend on actual processing arrangements, this is an ongoing accountability exercise rather than a one-time task, and the frequency of review should be proportionate to the risk and rate of change in your processing.

Common misconceptions

Listing only broad 'categories of recipients' is always sufficient and avoids naming specific recipients.
Whether categories alone are adequate, or whether specific named recipients should be disclosed, is subject to assessment and can depend on the transparency owed to data subjects and on regulator expectations. There can be divergence in how supervisory authorities approach this, so the safer position depends on context.
A recipient is the same thing as a third party.
The concept of recipient is generally broader than 'third party' and can include entities to which data is disclosed even within the same organisation or group, as well as processors acting on the controller's behalf. These terms should be distinguished rather than used interchangeably.
Naming a recipient in a privacy notice satisfies all obligations connected to that disclosure.
Identifying recipients is a transparency element, but it does not by itself establish a lawful basis for the disclosure, satisfy processor contracting requirements (typically an Article 28 agreement), or address any international transfer safeguards that may be needed. These are separate, additional considerations.

Best practices

Maintain an up-to-date inventory mapping each processing activity to its recipients or categories of recipients, and review it periodically as relationships change.
When deciding between naming specific recipients and describing categories, assess the transparency owed to data subjects and document the reasoning, taking account of potential divergence between supervisory authorities.
Distinguish clearly in documentation between processors (typically governed by an Article 28 agreement) and other recipients, and avoid conflating recipient status with third-party status.
Ensure recipient information disclosed to data subjects is consistent with the records of processing activities and with the underlying data flows.
Where recipients are located outside the EEA, separately assess whether transfer mechanisms and safeguards are required, and treat that assessment as subject to change over time.
Verify any specific article references, definitions, and disclosure expectations against the current official text of the applicable GDPR or UK GDPR and relevant regulator guidance before relying on them.