Laws · GDPR ·art-4-par-10 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
‘third party’ means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
How it connects
Cited by
- Guidelines 9/2022 on personal data breach notification under GDPR
- Guidelines 3/2019 on processing of personal data through video devices
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications
- VB v Natsionalna agentsia za prihodite
All 17
- Can the GPC standard eliminate consent banners in the EU?
- Generative AI and data protection
- SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR
- Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR
- Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications
- IP v Quirin Privatbank AG
- Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA
- Garante per la protezione dei dati personali (Italy) - 10254256
- DSB (Austria) - 2025-0.950.759
- DSB (Austria) - 2025-1.049.138
- DSB: No processor access violation under Art. 15 GDPR when controller deleted data
- BVwG - W292 2298015-1
Related across sources
C-46/23 Budapest Főváros IV. Kerület Újpest Önkormányzat Polgármesteri Hivatala v Nemzeti Adatvédelmi és Információszabadság Hatóság In a preliminary ruling requested by the Budapest High Court, the Court of Justice interpreted whether Article 58(2)(d) and (g) of the GDPR permits a national supervisory… CJEU ·Fifth Chamber Mar 14, 2024 Right to be Forgotten Personal Data Right to Restriction
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Supervision
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
C-604/22 IAB Europe v Gegevensbeschermingsautoriteit In Case C-604/22, the Court of Justice of the European Union ruled on a preliminary reference from the Brussels Court of Appeal in proceedings between IAB Europe and the Belgian… CJEU ·Fourth Chamber Mar 7, 2024 IP Address Controllers Personal Data
C-272/19 VQ v Land Hessen In a preliminary ruling requested by the Verwaltungsgericht Wiesbaden in proceedings between VQ and Land Hessen, the CJEU addressed whether the GDPR applies to the processing of… CJEU ·Third Chamber Jul 9, 2020 Material scope (GDPR) Right of Access Personal Data