Skip to main content
Category: Controller & Processor Roles

Third Party

Simply put

A third party is generally a person or organization outside of the main parties in a given relationship, such as those not directly involved in a contract or transaction but who still has some connection to it. In everyday and legal usage the term simply marks someone as being external to the core participants. Note that the evidence provided describes only these general and non-GDPR meanings, and does not supply the specialized GDPR definition of 'third party'.

Formal definition

In general legal usage, a third party is a person who is not a party to a contract or transaction but nonetheless has some involvement in it, and who typically has no direct legal rights in the matter (per the general legal dictionary evidence). In common commercial usage it may also refer to a company or individual outside an organization that provides goods, services, or activities to it. Important limitation: under the GDPR, 'third party' is a defined term with a specific meaning that distinguishes it from the controller, processor, data subject, and persons authorized to process data under the controller's or processor's direct authority; however, that GDPR-specific definition is not contained in the evidence supplied here and should be confirmed against the current official text of the Regulation before being relied upon in a compliance context.

Why it matters

The term 'third party' carries significant weight in data protection because it marks the boundary between the actors directly responsible for and involved in a processing relationship and those outside it. In general legal usage, a third party is someone who is not a party to a contract or transaction but nonetheless has some involvement in it, and who typically has no direct legal rights in the matter. In common commercial usage, it often refers to a company or individual outside an organization that provides goods, services, or activities to that organization. Understanding who sits inside versus outside the core relationship shapes how responsibilities, disclosures, and legal rights are allocated.

A critical limitation applies here: under the GDPR, 'third party' is a defined term with a specific meaning that distinguishes it from the controller, the processor, the data subject, and persons authorized to process data under the direct authority of the controller or processor. That GDPR-specific definition is not contained in the evidence supplied and should be confirmed against the current official text of the Regulation before being relied upon in a compliance context. Practitioners should be careful not to treat the everyday or general-legal meaning as interchangeable with the Regulation's technical definition, because the two can diverge in ways that materially affect obligations.

Because the boundary of who counts as a third party can determine whether a disclosure is an internal processing activity or an external transfer, getting the classification right is important for compliance analysis. Where uncertainty exists over whether a given actor is a third party for GDPR purposes, that classification should be assessed against the Regulation's own definitions and current regulatory guidance rather than assumed from commercial or colloquial usage.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads need to distinguish between actors inside the core processing relationship and those external to it. Because the general commercial meaning of 'third party', an outside company or individual providing goods or services, does not necessarily match the GDPR-defined term, they should confirm classifications against the current official text of the Regulation before recording them in compliance documentation.
Lawyers and Contract Drafters
In general legal usage, a third party is a person who is not a party to a contract or transaction but has some involvement, typically without direct legal rights in the matter. Lawyers drafting or reviewing agreements should be alert to the fact that this general meaning differs from the specialized GDPR definition, which is not supplied in the evidence here and should be checked against the Regulation before being relied upon.
Procurement and Vendor Management Teams
Teams engaging outside companies or individuals that provide goods, services, or activities to the organization commonly use 'third party' in its commercial sense. They should recognize that this usage is not automatically the same as the GDPR's defined role and coordinate with legal or data protection colleagues to establish the correct classification for any given supplier.

Inside Third Party

Definition under GDPR
A third party is defined in Article 4(10) GDPR as a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
Exclusion of internal actors
The concept expressly excludes the data subject, the controller, the processor, and staff or others acting under the direct authority of the controller or processor. Employees processing data as part of their duties are generally not third parties in relation to their employing organisation.
Relationship to disclosure and recipients
A third party may become a recipient (Article 4(9)) where personal data is disclosed to it, though not every recipient is a third party. The distinction matters when documenting to whom data is transferred and on what basis.
Interaction with legal bases
Where personal data is shared with a third party, the sharing typically requires an appropriate Article 6 legal basis, and an additional Article 9 condition where special category data is involved. Legitimate interests of a third party is one recognised basis, subject to a balancing assessment.
Scope boundary
The concept operates within the GDPR's material scope, which concerns personal data of living individuals. Sharing of anonymous data, or generally data of legal entities, falls outside this framework, though national implementing law and member state derogations may vary the position.

Common questions

Answers to the questions practitioners most commonly ask about Third Party.

Is a processor considered a third party under the GDPR?
Generally no. The GDPR defines a third party as an entity other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data. A processor acting on a controller's documented instructions is therefore typically excluded from the third party category in relation to that processing. The distinction matters because the relationship between a controller and its processor is governed by a data processing arrangement rather than treated as a disclosure to a third party. Note that classification can depend on the specific role an entity plays in a given processing operation, so the same organisation may be a processor in one context and a third party in another; assess this on the facts.
Does sharing personal data with a third party always require the data subject's consent?
No. Consent is only one of the several lawful bases available, and disclosure to a third party can be based on any applicable Article 6 basis, such as contract, legal obligation, or legitimate interests, subject to assessment. Treating consent as a universal requirement is a common misconception. Where the data involves special category data, an additional condition under Article 9 is also needed. The appropriate basis depends on the purpose and context of the sharing, and transparency obligations regarding recipients or categories of recipients typically apply regardless of the basis chosen. You should document your reasoning and verify the position against the current official text and any applicable national implementing law.
How should we identify third parties in our records of processing and privacy notices?
In most cases you should map, for each processing activity, who receives the personal data and in what role, distinguishing third parties from processors and from persons acting under your direct authority. Transparency requirements generally call for informing individuals of the recipients or categories of recipients of their personal data, so your privacy notice should reflect this at an appropriate level of detail. Where you rely on categories rather than named entities, be prepared to explain that choice. Keep this mapping current, as roles can change over time; review it against the current official text for the precise scope of the information obligations.
What contractual arrangements are appropriate when disclosing data to a third party?
The appropriate instrument depends on the recipient's role. Where the recipient acts as a processor on your behalf, a data processing agreement addressing the required processing terms is generally needed. Where the recipient is a separate controller receiving data as a third party, a controller-to-controller arrangement or data sharing agreement is more typical, allocating respective responsibilities. Do not conflate these instruments, as they serve different roles. If the disclosure involves a transfer outside the relevant jurisdiction, an additional transfer mechanism may be required. Confirm the correct role classification before selecting the arrangement, and tailor terms to the facts.
Do international transfer rules apply when the third party is located outside the EU or UK?
In many cases, yes. Disclosing personal data to a third party in another country can constitute a restricted transfer, which typically requires an appropriate transfer tool unless an adequacy decision covers the destination. Available mechanisms and any need for supplementary measures should be assessed on the facts. Because adequacy decisions, transfer tools, and supplementary measures evolve, and because the EU and UK positions can diverge, you should verify the current mechanisms against the applicable official sources rather than relying on a fixed snapshot. Also note that member state or national implementing law can affect the analysis.
How do we assess a lawful basis before disclosing personal data to a third party?
Identify the purpose of the disclosure and select an applicable Article 6 basis for it, documenting your reasoning. If you rely on legitimate interests, a balancing assessment weighing your interests against the individuals' rights and expectations is generally expected. If the data includes special category data, identify an additional Article 9 condition. Consider whether onward disclosure is compatible with the purposes for which the data was originally collected, and whether transparency and, where relevant, transfer obligations are met. Because outcomes are context and risk dependent, treat each disclosure as its own assessment and verify requirements against the current official text.

Common misconceptions

A processor acting for the controller is a third party.
The GDPR definition in Article 4(10) expressly excludes the processor. A processor engaged by a controller is generally not a third party in that relationship, and their processing is typically governed by a Data Processing Agreement under Article 28 rather than treated as a third-party disclosure.
Every third party that receives data is a 'recipient', and the terms are interchangeable.
The two concepts are distinct. A recipient (Article 4(9)) is any party to whom data is disclosed, which can include third parties but also others; not every recipient is a third party, and being a third party does not by itself determine the applicable legal basis or safeguards.
Sharing personal data with a third party always requires consent.
Consent is only one of the Article 6 legal bases. Sharing with a third party may instead rely on contract, legal obligation, vital interests, public task, or the legitimate interests of the controller or a third party, subject to assessment; special category data additionally requires an Article 9 condition.

Best practices

Map and document each third party to whom personal data is disclosed, distinguishing them from processors acting under your direct authority, and record the corresponding relationship type.
Identify and record the specific Article 6 legal basis for each third-party disclosure, and confirm an additional Article 9 condition where special category data is involved.
Where relying on the legitimate interests of a controller or third party, carry out and retain a documented balancing assessment before sharing.
Review contractual arrangements to ensure the correct instrument is used, using an Article 28 Data Processing Agreement for processors rather than treating them as third-party recipients.
Reflect third-party disclosures accurately in transparency information provided to data subjects, describing recipients or categories of recipients.
Verify the current position on any cross-border sharing against the official GDPR text and applicable national implementing law, since transfer tools and member state derogations can vary and evolve.