Recipient
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.A person or body to which personal data are disclosed (Art 4(9) GDPR).
Overview
19 sources · Jul 23, 2026Legal Framework
The concept of "recipient" is embedded throughout the GDPR's transparency and accountability architecture. While Article 4(9) defines a recipient as a natural or legal person, public authority, agency, or other body to which personal data are disclosed, the operational obligations attach at several points. Controllers must identify recipients when providing information to data subjects, whether the data was collected directly or indirectly.
Under Article 14(1)(e), where personal data have not been obtained from the data subject, the controller must provide:
"the recipients or categories of recipients of the personal data, if any"
— GDPR Art. 14(1)(e)
Similarly, the right of access under Article 15(1)(c) requires controllers to disclose:
"the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations"
— GDPR Art. 15(1)(c)
Where a recipient is located in a third country, Article 46 imposes additional obligations: the controller must ensure appropriate safeguards are in place—such as standard contractual clauses, binding corporate rules, or other approved mechanisms—and that enforceable data subject rights and effective legal remedies are available.
Key Developments
The Court of Justice's ruling in Schrems II confirmed that transfers to recipients in third countries require not just formal safeguards but substantive protection. The Court affirmed that supervisory authorities possess the power to suspend data flows to recipients in third countries where safeguards prove inadequate, underscoring the real-world consequences of improper recipient identification.
In Bara, the CJEU addressed the information obligation where data are shared between public administrative bodies. The Court held:
"the requirement of fair processing of personal data laid down in Article 6 of Directive 95/46 requires a public administrative body to inform the data subjects of the transfer of those data to another public administrative body for the purpose of their processing by the latter in its capacity as recipient of those data."
— Bara ¶34
This establishes that even inter-agency transfers constitute disclosures to recipients, triggering transparency obligations.
The EDPB's breach notification guidance further illustrates the practical stakes. Where data are accidentally transmitted to an unauthorized recipient, the controller should take active mitigation steps:
"If an email is sent to an incorrect/unauthorised recipient, it is recommended that the data controller should Bcc a follow up email to the unintended recipients apologising, instructing that the offending email should be deleted, and advising recipients that they do not have the right to further use the email addresses identified to them."
— EDPB Guidelines 01/2021 §117
Practical Guidance
Map all recipients before processing begins. Article 14(1)(e) and Article 15(1)(c) require disclosure of recipients or categories of recipients. Maintain an up-to-date record of every body to whom data are disclosed, including processors, sub-processors, and third-party recipients.
Distinguish recipient categories from named recipients. Where naming specific recipients is impractical, identify categories with sufficient specificity that data subjects can understand who will access their data. Vague categories like "trusted partners" will not satisfy the transparency standard articulated in Bara.
Flag third-country recipients explicitly. Article 14(1)(f) requires controllers to inform data subjects when transfers to recipients in third countries or international organisations are intended, including the existence or absence of an adequacy decision and reference to appropriate safeguards under Article 46.
Implement breach response protocols for misdirected disclosures. As the EDPB guidance demonstrates, unauthorized recipient access triggers Article 33 and potentially Article 34 obligations. Pre-establish procedures for contacting unintended recipients, requesting deletion, and assessing risk to data subjects.
Document inter-organizational data sharing. The Bara ruling confirms that transfers between public bodies—or analogous intra-group or partner transfers—constitute disclosures to recipients requiring transparency, even where the recipient is itself a controller for its own subsequent processing purposes.
why this is here
to each recipient to whom the personal data have been disclosed
The provision directly involves recipients as the addressees of the communication, relevant to defining their role.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
publication on a website of data naming those beneficiaries and indicating the precise amounts received
The publication makes data available to third parties, touching the concept of disclosure to recipients, but not central.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026