Categories of Recipients
Categories of recipients refers to the groups or types of people and organisations that a controller shares personal data with, described by class rather than always by name. Organisations generally have to tell individuals who receives their data, either by identifying specific recipients or by describing the categories they fall into. This information is typically included in a privacy notice and may also need to be disclosed when someone makes a data subject access request.
Under the UK GDPR and EU GDPR, controllers must inform data subjects of 'the recipients or categories of recipients of the personal data, if any' as part of the transparency obligations when personal data is collected (Articles 13 and 14). A 'recipient' is broadly understood to include any party to whom personal data is disclosed, which can encompass other controllers, processors, and, per ICO guidance, anyone that processes the data. Controllers may satisfy this requirement by naming specific recipients or by describing them at the level of categories, and these details are also typically maintained in records of processing activities. The Court of Justice of the European Union has held that, in response to a data subject access request, a data subject is generally entitled to be told the identity of the actual recipients rather than only the categories, subject to the circumstances of the case; practitioners should verify the precise scope and any national or regulatory divergence against current official texts and guidance. This entry addresses the transparency and disclosure concept and does not cover the separate rules governing international transfers or the distinct roles of controller and processor.
Why it matters
Transparency about who receives personal data is a foundational element of the UK GDPR and EU GDPR information obligations. Individuals cannot meaningfully exercise their rights, assess risks to their data, or hold organisations accountable if they do not know who their information is being shared with. By requiring controllers to disclose the recipients or categories of recipients (Articles 13 and 14), the Regulation aims to reduce the information asymmetry between organisations and the people whose data they process. Failing to provide this information, or describing recipients in vague or misleading terms, can undermine the lawfulness of processing and expose an organisation to regulatory scrutiny.
The practical stakes have increased following case law from the Court of Justice of the European Union, which held that a data subject responding to an access request is generally entitled to be told the identity of the actual recipients rather than only the categories, subject to the circumstances of the case. This means the level of detail sufficient in an upfront privacy notice may not always satisfy a data subject access request, and organisations should not assume that describing recipients only by class will discharge their obligations in every situation. Practitioners should verify the precise scope of this ruling and any national or regulatory divergence against current official texts and guidance.
Because 'recipient' is understood broadly to include other controllers, processors, and, per ICO guidance, anyone that processes the data, keeping an accurate account of recipients supports several overlapping compliance functions at once. It feeds the transparency information given to individuals, informs how the organisation responds to access requests, and aligns with the records of processing activities that controllers typically maintain. Getting this wrong tends to create compounding problems across all three areas.
Who it's relevant to
Inside Categories of Recipients
Common questions
Answers to the questions practitioners most commonly ask about Categories of Recipients.