Skip to main content
Category: Controller & Processor Roles

Recipient

Simply put

Under data protection law, a recipient is any person, organisation, or body to whom personal data is disclosed. This can include third parties as well as people within the same organisation, and it does not always mean the data is being sold or transferred abroad. The evidence available here does not include the specific legal definition, so the description below should be verified against the current official text of the GDPR.

Formal definition

In general data protection terminology, a 'recipient' denotes a natural or legal person, public authority, agency, or other body to which personal data are disclosed, whether or not that party is a third party. The concept is distinct from a 'third party' and does not by itself determine the party's role as controller or processor. The evidence packet provided contains only general-language and technology-context definitions of 'recipient' and does not supply the GDPR's statutory definition or associated article number; practitioners should confirm the precise wording, article reference, and any exclusions (for example, public authorities receiving data in the course of a particular inquiry) against the current official GDPR text and relevant regulator guidance before relying on it.

Why it matters

The concept of a recipient matters because data protection law places obligations on controllers to be transparent about who receives personal data. Under transparency and information requirements, individuals are generally entitled to know the recipients or categories of recipients of their personal data, which makes accurate identification of recipients a practical necessity for privacy notices, records of processing, and responses to data subject access requests. Getting this wrong can undermine transparency obligations even where the underlying processing is otherwise lawful.

The term is also significant because it is broad and frequently misunderstood. A recipient is any party to whom personal data is disclosed, which can include parties inside the same organisation as well as external ones, and disclosure to a recipient does not by itself mean the data is being sold or sent to another country. The evidence available here does not include the statutory definition, so the precise scope, article reference, and any exclusions should be verified against the current official GDPR text before relying on this concept in a compliance program.

Because 'recipient' does not itself fix a party's role, treating every recipient as a controller, a processor, or a third party can lead to mischaracterisation of relationships and contractual obligations. Practitioners should assess each recipient's role separately rather than assuming that receiving data determines it.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads need to identify recipients or categories of recipients accurately for privacy notices, records of processing, and access request responses. Because the concept is broad and can include internal recipients, they should map disclosures carefully and verify the precise statutory definition and any exclusions against the current official GDPR text before relying on it.
Privacy and Data Protection Lawyers
Lawyers advising on data flows should distinguish 'recipient' from related concepts such as 'third party', and should not assume that receiving data determines whether a party is a controller or a processor. The role of each recipient must be assessed separately, and the article reference and wording should be confirmed against the current official text and regulator guidance.
Engineers and Systems Designers
Engineers building data-sharing and disclosure functions should recognise that any party or system on the receiving end of personal data may be a recipient, including internal systems and teams. This informs logging, transparency, and configuration of who can receive data, subject to legal confirmation of scope.

Inside Recipient

Definition under the GDPR
A recipient is generally defined as a natural or legal person, public authority, agency, or other body to which personal data is disclosed, whether a third party or not. This means a recipient can include entities within the same organisational grouping or others who are not third parties.
Distinction from third party
The concept of recipient is broader than that of third party. A recipient may be a third party, but it need not be; for example, a processor acting on behalf of the controller, or another controller receiving data, can each be a recipient depending on the circumstances.
Public authority exception
Public authorities that may receive personal data in the framework of a particular inquiry in accordance with Union or member state law are generally not regarded as recipients, subject to the applicable legal provisions. The precise treatment can be affected by member state implementing law, so the position should be verified against the current text.
Relevance to transparency obligations
The identity of recipients, or the categories of recipients, of personal data is typically among the information provided to data subjects and recorded in transparency and accountability documentation, subject to the applicable disclosure requirements.
Recipients versus categories of recipients
In practice, information may be provided about specific recipients or about categories of recipients. There is recognised discussion, including in regulatory guidance and case law, about when naming specific recipients rather than categories is expected; practitioners should check current guidance as approaches can diverge between regulators.

Common questions

Answers to the questions practitioners most commonly ask about Recipient.

Is a recipient the same thing as a third party under the GDPR?
No. The two terms are defined separately in Article 4. A recipient is any natural or legal person, public authority, agency, or other body to which personal data are disclosed, whether or not they are a third party. This means that recipients can include controllers, processors, and other entities within the same organisational structure, whereas a third party is generally someone other than the data subject, controller, processor, and persons authorised to process the data under their direct authority. In short, all third parties who receive data are recipients, but not all recipients are third parties.
Are public authorities that receive personal data always classed as recipients?
Not in every case. The GDPR generally provides that public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients. Whether this exclusion applies depends on the legal basis and context of the disclosure, so it should be assessed against the specific circumstances and the applicable national implementing law, which can vary between Member States.
How should recipients be described in a privacy notice or record of processing?
The GDPR requires that data subjects be informed of the recipients or categories of recipients of their personal data. Controllers may therefore either name specific recipients or describe them by category (for example, categories such as service providers or professional advisers). The choice can depend on transparency expectations and regulator guidance, which has at times encouraged naming actual recipients where feasible; the appropriate level of detail should be assessed case by case, and practice may differ between supervisory authorities.
Does disclosing personal data to a recipient require its own legal basis?
Disclosure of personal data is a form of processing and therefore generally needs an Article 6 legal basis, and an additional Article 9 condition where special category data are involved. Identifying an entity as a recipient does not by itself establish lawfulness; the controller should confirm that the disclosure is covered by an appropriate basis and, where relevant, by an appropriate arrangement such as a data processing agreement under Article 28 where the recipient acts as a processor.
If a recipient is located outside the EEA, what additional considerations apply?
Where a recipient is in a third country, the disclosure may constitute an international transfer, which is subject to the transfer rules in addition to the general processing requirements. This may require reliance on a transfer tool such as an adequacy decision, standard contractual clauses, or binding corporate rules, together with any supplementary measures identified through assessment. Because adequacy decisions and transfer mechanisms evolve, the current position should be verified against the applicable official sources at the time of transfer.
How can an organisation keep track of recipients for accountability purposes?
Recipients or categories of recipients typically need to be reflected in the record of processing activities and in transparency information provided to data subjects. Maintaining an up-to-date inventory of who receives personal data, in what role (for example as a separate controller or as a processor), and under what arrangement can support accountability and help respond to data subject requests. The appropriate level of detail should be assessed in light of the organisation's processing and the guidance of the relevant supervisory authority.

Common misconceptions

A recipient is the same thing as a third party.
The two concepts are distinct. A recipient is defined more broadly and can include parties who are not third parties, such as a processor acting for the controller. Not every recipient is a third party, and treating the terms as interchangeable can lead to errors in mapping data flows and drafting transparency notices.
A recipient is always a separate organisation outside the controller's group.
A recipient can include entities to which data is disclosed regardless of whether they sit inside or outside a particular organisational grouping, subject to the definition. The determining factor is disclosure of personal data, not corporate separateness.
Public authorities that receive personal data are always recipients.
Public authorities that may receive data in the framework of a particular inquiry under Union or member state law are generally not regarded as recipients, subject to the applicable legal provisions. This treatment can be affected by national implementing law and should be verified against the current text.

Best practices

Map your data flows to identify each recipient of personal data, distinguishing recipients that are processors, other controllers, or entities within your organisational grouping, rather than assuming all recipients are external third parties.
When drafting transparency notices, decide deliberately between naming specific recipients and describing categories of recipients, and check current regulatory guidance and case law, as expectations can diverge between regulators.
Assess whether any bodies receiving data qualify for the public authority exception under the applicable Union or member state law, and document the basis for that assessment, verifying the position against the current text.
Maintain records of recipients and categories of recipients within your accountability documentation so that disclosures can be substantiated when required.
Review and update recipient records when data flows, service providers, or organisational arrangements change, since the set of recipients is not static.
Where uncertainty exists about whether an entity is a recipient or how much detail to disclose, seek qualified legal input and note the recognised divergence rather than treating one interpretation as settled law.