Skip to content
Topic Contested in court

Recipient

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

A person or body to which personal data are disclosed (Art 4(9) GDPR).

181 linked items 26 Laws59 Case Law31 Guidance52 Enforcement6 News

Overview

19 sources · Jul 23, 2026

Legal Framework

The concept of "recipient" is embedded throughout the GDPR's transparency and accountability architecture. While Article 4(9) defines a recipient as a natural or legal person, public authority, agency, or other body to which personal data are disclosed, the operational obligations attach at several points. Controllers must identify recipients when providing information to data subjects, whether the data was collected directly or indirectly.

Under Article 14(1)(e), where personal data have not been obtained from the data subject, the controller must provide:

"the recipients or categories of recipients of the personal data, if any"
— GDPR Art. 14(1)(e)

Similarly, the right of access under Article 15(1)(c) requires controllers to disclose:

"the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations"
GDPR Art. 15(1)(c)

Where a recipient is located in a third country, Article 46 imposes additional obligations: the controller must ensure appropriate safeguards are in place—such as standard contractual clauses, binding corporate rules, or other approved mechanisms—and that enforceable data subject rights and effective legal remedies are available.

Key Developments

The Court of Justice's ruling in Schrems II confirmed that transfers to recipients in third countries require not just formal safeguards but substantive protection. The Court affirmed that supervisory authorities possess the power to suspend data flows to recipients in third countries where safeguards prove inadequate, underscoring the real-world consequences of improper recipient identification.

In Bara, the CJEU addressed the information obligation where data are shared between public administrative bodies. The Court held:

"the requirement of fair processing of personal data laid down in Article 6 of Directive 95/46 requires a public administrative body to inform the data subjects of the transfer of those data to another public administrative body for the purpose of their processing by the latter in its capacity as recipient of those data."
Bara ¶34

This establishes that even inter-agency transfers constitute disclosures to recipients, triggering transparency obligations.

The EDPB's breach notification guidance further illustrates the practical stakes. Where data are accidentally transmitted to an unauthorized recipient, the controller should take active mitigation steps:

"If an email is sent to an incorrect/unauthorised recipient, it is recommended that the data controller should Bcc a follow up email to the unintended recipients apologising, instructing that the offending email should be deleted, and advising recipients that they do not have the right to further use the email addresses identified to them."
EDPB Guidelines 01/2021 §117

Practical Guidance

  • Map all recipients before processing begins. Article 14(1)(e) and Article 15(1)(c) require disclosure of recipients or categories of recipients. Maintain an up-to-date record of every body to whom data are disclosed, including processors, sub-processors, and third-party recipients.

  • Distinguish recipient categories from named recipients. Where naming specific recipients is impractical, identify categories with sufficient specificity that data subjects can understand who will access their data. Vague categories like "trusted partners" will not satisfy the transparency standard articulated in Bara.

  • Flag third-country recipients explicitly. Article 14(1)(f) requires controllers to inform data subjects when transfers to recipients in third countries or international organisations are intended, including the existence or absence of an adequacy decision and reference to appropriate safeguards under Article 46.

  • Implement breach response protocols for misdirected disclosures. As the EDPB guidance demonstrates, unauthorized recipient access triggers Article 33 and potentially Article 34 obligations. Pre-establish procedures for contacting unintended recipients, requesting deletion, and assessing risk to data subjects.

  • Document inter-organizational data sharing. The Bara ruling confirms that transfers between public bodies—or analogous intra-group or partner transfers—constitute disclosures to recipients requiring transparency, even where the recipient is itself a controller for its own subsequent processing purposes.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 26
rec 37 Recital 37 — specific recipient identification information orders DSA Oct 2022 art 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing GDPR Apr 2016 Recipient is the target of notification
why this is here
to each recipient to whom the personal data have been disclosed

The provision directly involves recipients as the addressees of the communication, relevant to defining their role.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

rec 34 Recital 34 — national authority orders against illegal content DSA Oct 2022 rec 121 Recital 121 — intermediary service provider liability for damages DSA Oct 2022 rec 68 Recital 68 — online advertising transparency requirements DSA Oct 2022 rec 70 Recital 70 — online platform recommender system transparency DSA Oct 2022 rec 71 Recital 71 — protection of minors online DSA Oct 2022 art 53 Right to lodge a complaint DSA Oct 2022 rec 5 Recital 5 — scope covering intermediary service providers DSA Oct 2022 rec 14 Recital 14 — dissemination to public concept scope DSA Oct 2022 rec 80 Recital 80 — systemic risk categories illegal content DSA Oct 2022 rec 18 Recital 18 — Active role liability exemption exclusion DSA Oct 2022 rec 20 Recital 20 — collaboration in illegal activities exclusion DSA Oct 2022 rec 23 Recital 23 — service provider control liability exemption exception DSA Oct 2022 rec 58 Recital 58 — internal complaint handling systems DSA Oct 2022 rec 56 Recital 56 — hosting service criminal threat reporting obligation DSA Oct 2022 rec 55 Recital 55 — restrictions visibility monetisation statement reasons DSA Oct 2022 rec 54 Recital 54 — hosting service content restriction notification obligations DSA Oct 2022 rec 43 Recital 43 — single point of contact for recipients DSA Oct 2022 rec 39 Recital 39 — redress mechanisms and content restoration orders DSA Oct 2022 Show 6 more →
Case Law 59
¶6 Article 2 of that directive provides: ‘For the purposes of this Directive: (a) “personal data” shall mean any information relating to an identified or… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶14 Under Paragraph 113b of the TKG: ‘(1) Operators to which Paragraph 113a(1) applies shall retain data in national territory as follows: 1. for 10 weeks… Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH ¶77 In the first place, as regards the extent of the data retained, it is apparent from the order for reference that, in the context of the provision of t… Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH ¶15 IP addresses are series of digits assigned to networked computers to facilitate their communication over the internet. When a website is accessed, the… Patrick Breyer v Bundesrepublik Deutschland 154/21 RW v Österreichische Post AG Court of Justice of the European Union Jan 2023 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 582/14 Patrick Breyer v Bundesrepublik Deutschland CJEU Oct 2016 CJEU VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”) CJEU Nov 2010 Disclosure to third parties via publication
why this is here
publication on a website of data naming those beneficiaries and indicating the precise amounts received

The publication makes data available to third parties, touching the concept of disclosure to recipients, but not central.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

175/20 SIA 'SS' v Valsts ieņēmumu dienests Court of Justice of the European Union Feb 2022 557/20 Single Resolution Board v European Data Protection Supervisor General Court Apr 2023 203/22 CK v Magistrat der Stadt Wien Court of Justice of the European Union Feb 2025 German Supreme Court BGH - VI ZR 375/2 German Supreme Court May 2026 473/12 Judgment of the Court (Third Chamber), 7 November 2013.#Institut professionnel des agents immobiliers (IPI) v Geoffrey Englebert and Others.#Request for a preliminary ruling from the Cour constitutionnelle (Belgium).#Processing of personal data — Directive 95/46/EC — Articles 10 and 11 — Obligation to inform — Article 13(1)(d) and (g) — Exceptions — Scope of exceptions — Private detectives acting for the supervisory body of a regulated profession — Directive 2002/58/EC — Article 15(1).#Case C‑47 Court of Justice of the European Union Nov 2013 740/22 Endemol Shine Finland Oy Court of Justice of the European Union Mar 2024 17/22 HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG and Ökorenta Neue Energien Ökostabil IV geschlossene Investment GmbH & Co. KG v Müller Rechtsanwaltsgesellschaft mbH and Others Court of Justice of the European Union Sep 2024 318/24 GC - T-318/24 Gereral Court Dec 2025 348/23 Zalando SE v European Commission General Court Sep 2025 CJEU CLIENT EARTH ET AL. V. EFSA, 16.7.2015 (“CLIENT EARTH”) CJEU Jul 2015 367/23 Amazon EU Sàrl, venant aux droits de Amazon Services Europe Sàrl v European Commission General Court Nov 2025 487/21 Österreichische Datenschutzbehörde v CRIF CJEU Oct 2023 757/22 Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V Court of Justice of the European Union Jul 2024 416/23 Österreichische Datenschutzbehörde v F R Court of Justice of the European Union Jan 2025 654/23 Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Court of Justice of the European Union Nov 2025 CJEU SERGEJS BUIVIDS v. THE AUGSTĀKĀ TIESA CJEU Feb 2019 Show 39 more →
Guidance 31
012023 on article 37 law enforcement directive Guidelines 01/2023 on Article 37 Law Enforcement Directive EDPB Jun 2024 22019 on the processing of personal data under article 61b gdpr in Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects EDPB Oct 2019 29 working party guidelines on transparency under regulation 2016679 Article 29 Working Party - Guidelines on transparency under Regulation 2016/679 EDPB Apr 2018 guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 us data privacy framework faq european individuals 0 EU-US Data Privacy Framework FAQ for European individuals - version 2.0 EDPB Jan 2026 guidelines 202402 article48 v2 Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 asked questions on the judgment of the court of justice of the Frequently Asked Questions on the judgment of the Court of Justice of the European Union in Case C-311/18 - Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems EDPB Jul 2020 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 document setting forth cooperation procedure EDPB Document setting forth a Cooperation Procedure for the Authorisation of Contractual Clauses under Article 46(3)(a) GDPR and for the Adoption of Standard Contractual Clauses under Article 46(2)(d) GDPR EDPB Jan 2026 us data privacy framework faq for european individuals EU-US Data Privacy Framework FAQ for European individuals EDPB Jul 2024 us data privacy framework faq european businesses 0 EU-U.S. Data Privacy Framework F.A.Q. for European businesses - version 2.0 EDPB Jan 2026 guidelines on transparency Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) EDPB Nov 2025 012021 on the adequacy referential under the law Recommendations 01/2021 on the adequacy referential under the Law Enforcement Directive EDPB Feb 2021 us data privacy framework faq for european businesses EU-US Data Privacy Framework FAQ for European businesses EDPB Jul 2024 opinion 202507 epo adequacydecision Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation EDPB May 2025 complaint form and template acknowledgement of receipt Template Complaint form and Template Acknowledgement of receipt EDPB Jun 2023 opinion 202527 united kingdom adequacy led Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom EDPB Oct 2025 Show 11 more →
Enforcement 52
NAIH (Hungary) NAIH (Hungary) - NAIH-4462-5-2026 NAIH (Hungary) Apr 2026 CNIL (France) CNIL (France) - SAN-2022-011 CNIL (France) Jul 2026 Garante per la protezione dei dati personali (Italy) Garante fines Lusha Systems Inc. over unauthorized B2B contact database Garante per la protezione dei dati personali (Italy) Jul 2026 AEPD (Spain) AEPD (Spain) - PS/00421/2020 AEPD (Spain) Jul 2026 ICO (UK) ICO (UK) - KRA Consultancy Ltd ICO (UK) May 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 DSB (Austria) DSB (Austria) - DSB-D550.1284 DSB (Austria) Aug 2026 Datatilsynet (Denmark) Datatilsynet (Denmark) - 2024-432-0039 Datatilsynet (Denmark) Aug 2026 IP (Slovenia) IP (Slovenia) - 0609-41/2026/7 IP (Slovenia) Aug 2026 IP (Slovenia) IP (Slovenia) - 0609-113/2025/9 IP (Slovenia) Sep 2026 UODO (Poland) UODO (Poland) - DKE.561.1.2026 UODO (Poland) Jun 2026 DSB (Austria) Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. DSB (Austria) Aug 2026 IP (Slovenia) IP (Slovenia) - 0609-36/2026/7 IP (Slovenia) Jul 2026 IP (Slovenia) IP (Slovenia) - 0609-42/2026/7 IP (Slovenia) May 2026 Spanish Data Protection Authority (aepd) DHL PARCEL IBERIA, S.L.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Sep 2025 Spanish Data Protection Authority (aepd) DHL PARCEL IBERIA, S.L.: Violation of the general principles of data processing. Spanish Data Protection Authority (aepd) Sep 2025 Spanish Data Protection Authority (aepd) IBERCAJA BANCO, S.A.: Violation of the general principles of data processing. Spanish Data Protection Authority (aepd) Jun 2025 Spanish Data Protection Authority (aepd) IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Jun 2025 Polish National Personal Data Protection Office (UODO) mBank: Insufficient fulfilment of data breach notification obligations Polish National Personal Data Protection Office (UODO) Aug 2024 Italian Data Protection Authority (Garante) Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) Feb 2024 Show 32 more →
News 6
noyb - European Center for Digital Rights noyb takes Swedish tax authority to court for selling people’s personal data noyb - European Center for Digital Rights Apr 2025 noyb - European Center for Digital Rights Update on noyb’s 101 complaints on EU-US data transfers – only one country shines noyb - European Center for Digital Rights Sep 2020 noyb - European Center for Digital Rights Complaint: Amazon doesn’t allow baseline TLS security noyb - European Center for Digital Rights Mar 2020 European Digital Rights Unprecedented appearance by European Commissioner for Home Affairs, innovating on quicksand, and the cabinet vs. online confidentiality European Digital Rights Mar 2023 Future of Privacy Forum What Happened to the Risk-Based Approach to Data Transfers? Future of Privacy Forum Sep 2022 AEPD The Dutch Data Protection Authority is publishing a report on the risk assessment under the GDPR (General Data Protection Regulation). AEPD Oct 2022
Literature 6
Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Dec 2023 Comparative Law Review General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens? Comparative Law Review Feb 2018 Zbornik radova. Aktualnosti građanskog i trgovačkog zakonodavstva i pravne prakse POJAM OSOBNOG PODATKA U TUMAČENJU SUDA EUROPSKE UNIJE Zbornik radova. Aktualnosti građanskog i trgovačkog zakonodavstva i pravne prakse Jul 2026 HR Athens Journal of Law Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation” Athens Journal of Law Jan 2025 International Data Privacy Law The transfer of personal data to third countries under the GDPR: when does a recipient country provide an adequate level of protection? International Data Privacy Law Jul 2018 International Journal of Latest Technology in Engineering Management & Applied Science The Right to Be Forgotten in The Context of Mobile Number Recycling International Journal of Latest Technology in Engineering Management & Applied Science Sep 2025
Tools 1
US Department of Commerce Data Privacy Framework program — participant list US Department of Commerce Jul 2026