Third Party
A third party is generally a person or organization outside of the main parties in a given relationship, such as those not directly involved in a contract or transaction but who still has some connection to it. In everyday and legal usage the term simply marks someone as being external to the core participants. Note that the evidence provided describes only these general and non-GDPR meanings, and does not supply the specialized GDPR definition of 'third party'.
In general legal usage, a third party is a person who is not a party to a contract or transaction but nonetheless has some involvement in it, and who typically has no direct legal rights in the matter (per the general legal dictionary evidence). In common commercial usage it may also refer to a company or individual outside an organization that provides goods, services, or activities to it. Important limitation: under the GDPR, 'third party' is a defined term with a specific meaning that distinguishes it from the controller, processor, data subject, and persons authorized to process data under the controller's or processor's direct authority; however, that GDPR-specific definition is not contained in the evidence supplied here and should be confirmed against the current official text of the Regulation before being relied upon in a compliance context.
Why it matters
The term 'third party' carries significant weight in data protection because it marks the boundary between the actors directly responsible for and involved in a processing relationship and those outside it. In general legal usage, a third party is someone who is not a party to a contract or transaction but nonetheless has some involvement in it, and who typically has no direct legal rights in the matter. In common commercial usage, it often refers to a company or individual outside an organization that provides goods, services, or activities to that organization. Understanding who sits inside versus outside the core relationship shapes how responsibilities, disclosures, and legal rights are allocated.
A critical limitation applies here: under the GDPR, 'third party' is a defined term with a specific meaning that distinguishes it from the controller, the processor, the data subject, and persons authorized to process data under the direct authority of the controller or processor. That GDPR-specific definition is not contained in the evidence supplied and should be confirmed against the current official text of the Regulation before being relied upon in a compliance context. Practitioners should be careful not to treat the everyday or general-legal meaning as interchangeable with the Regulation's technical definition, because the two can diverge in ways that materially affect obligations.
Because the boundary of who counts as a third party can determine whether a disclosure is an internal processing activity or an external transfer, getting the classification right is important for compliance analysis. Where uncertainty exists over whether a given actor is a third party for GDPR purposes, that classification should be assessed against the Regulation's own definitions and current regulatory guidance rather than assumed from commercial or colloquial usage.
Who it's relevant to
Inside Third Party
Common questions
Answers to the questions practitioners most commonly ask about Third Party.