Recipient
Under data protection law, a recipient is any person, organisation, or body to whom personal data is disclosed. This can include third parties as well as people within the same organisation, and it does not always mean the data is being sold or transferred abroad. The evidence available here does not include the specific legal definition, so the description below should be verified against the current official text of the GDPR.
In general data protection terminology, a 'recipient' denotes a natural or legal person, public authority, agency, or other body to which personal data are disclosed, whether or not that party is a third party. The concept is distinct from a 'third party' and does not by itself determine the party's role as controller or processor. The evidence packet provided contains only general-language and technology-context definitions of 'recipient' and does not supply the GDPR's statutory definition or associated article number; practitioners should confirm the precise wording, article reference, and any exclusions (for example, public authorities receiving data in the course of a particular inquiry) against the current official GDPR text and relevant regulator guidance before relying on it.
Why it matters
The concept of a recipient matters because data protection law places obligations on controllers to be transparent about who receives personal data. Under transparency and information requirements, individuals are generally entitled to know the recipients or categories of recipients of their personal data, which makes accurate identification of recipients a practical necessity for privacy notices, records of processing, and responses to data subject access requests. Getting this wrong can undermine transparency obligations even where the underlying processing is otherwise lawful.
The term is also significant because it is broad and frequently misunderstood. A recipient is any party to whom personal data is disclosed, which can include parties inside the same organisation as well as external ones, and disclosure to a recipient does not by itself mean the data is being sold or sent to another country. The evidence available here does not include the statutory definition, so the precise scope, article reference, and any exclusions should be verified against the current official GDPR text before relying on this concept in a compliance program.
Because 'recipient' does not itself fix a party's role, treating every recipient as a controller, a processor, or a third party can lead to mischaracterisation of relationships and contractual obligations. Practitioners should assess each recipient's role separately rather than assuming that receiving data determines it.
Who it's relevant to
Inside Recipient
Common questions
Answers to the questions practitioners most commonly ask about Recipient.