Recipient (Article 4(9) GDPR)
A recipient is any natural or legal person, public authority, agency or another body to which personal data are disclosed, whether that body is a third party or not.
The concept of the recipient is one of the central foundational terms of the GDPR. It is deliberately broad and covers every body to which personal data are disclosed, including bodies within the same organization. Whether a disclosure is permissible is not determined by the concept of the recipient itself, but by the general requirements for the lawfulness of processing.
Key takeaways
- A recipient is any body to which personal data are disclosed, whether or not it is a third party (Article 4(9) first sentence GDPR).
- Processors and employees acting under the direct authority of the controller are also recipients.
- Public authorities that receive data within the framework of a particular inquiry are expressly not regarded as recipients (Article 4(9) second sentence GDPR).
- A disclosure to a recipient is only permissible insofar as purpose limitation and necessity are preserved, not already where a disclosure is merely useful.
- Under the right of access, the specific recipients must in principle be named; a limitation to categories is permissible only by way of exception (CJEU, judgment of 12 January 2023, C-154/21).
1. Overview
Article 4(9) GDPR defines a recipient as any natural or legal person, public authority, agency or another body to which personal data are disclosed, whether that body is a third party or not. The provision contains an exception for certain public authorities in its second sentence.
The concept is tied to the act of disclosure. Disclosure means any communication, transmission, making available or other form of making accessible, as contained in the concept of processing under Article 4(2) GDPR. What is decisive is that another body obtains, or is able to obtain, access to the data.
The broad scope of the term is intentional: the GDPR refers to recipients in numerous places (Article 13(1)(e), Article 14(1)(e), Article 15(1)(c), Article 19, Article 30(1)(d) GDPR) and attaches information, documentation and notification obligations to that concept. These obligations apply regardless of whether the receiving body is, in organizational terms, a third party or belongs to the same organization.
2. Scope of the concept
2.1 Recipient and third party
There is an overlapping relationship between the recipient and the third party: every third party to which data are disclosed is at the same time a recipient. Conversely, not every recipient is a third party. Bodies that receive data but are not regarded as third parties are nevertheless recipients.
The data subject itself is not a recipient. Where the controller provides the data subject with information under Article 15 GDPR, this does not constitute a disclosure to a recipient within the meaning of Article 4(9) GDPR.
2.2 The processor as a recipient
The processor processes personal data on behalf of and on the instructions of the controller. It is not a third party within the meaning of Article 4(10) GDPR, but it is indeed a recipient within the meaning of Article 4(9) GDPR. The same applies to persons who act under the direct authority of the controller or the processor and have access to personal data, such as employees who use certain systems or access data.
Where an employee accesses personal data of their own accord and without authorization, they are no longer acting under the direct authority of the controller. In such a case the person accessing the data without authorization may themselves be regarded as a recipient, which triggers data protection and, where applicable, criminal consequences.
2.3 Comparison table
The following overview contrasts the most important constellations:
| Constellation | Recipient (Article 4(9))? | Third party (Article 4(10))? |
|---|---|---|
| External service provider without a data processing agreement | Yes | Yes |
| Processor (with a data processing agreement) | Yes | No |
| Own employees acting with authorization | Yes | No |
| Own employee, unauthorized access | Possibly yes | Possibly yes |
| Public authority acting under a particular inquiry | No (second sentence) | No |
| The data subject itself | No | No |
3. Public authorities acting under a particular inquiry
Article 4(9) second sentence GDPR expressly excludes public authorities from the concept of the recipient where they receive personal data within the framework of a particular inquiry in accordance with Union or Member State law. The transmission of data then does not follow the general disclosure regime, but is subject to the data protection rules applicable to the public authority in question.
Recital 31 GDPR explains the background to this rule: it covers, in particular, tax and customs authorities, financial investigation units and financial market supervisory authorities. Data should be transmitted to such bodies only on a written, reasoned and occasional request; the transmission should not concern entire filing systems or lead to the interconnection of filing systems (Recital 31 GDPR, https://dsgvo-gesetz.de/erwaegungsgruende/nr-31/).
The privileged treatment does not apply to any and every request for data by a public authority, but only to requests within the framework of a specific, statutorily defined inquiry. The exception is not applicable to general supervisory or monitoring activity without a specific inquiry.
4. Categories of recipients
In addition to the term "recipient", the GDPR regularly uses the term "categories of recipients". This refers to the abstract grouping of recipients of the same kind, such as all department heads of a company, all statutory health insurance funds or all commissioned IT service providers.
The record of processing activities under Article 30(1)(d) GDPR expressly requires only the indication of the categories of recipients, not the naming of each individual recipient. This abstract approach takes account of the fact that, in ongoing operations, recipients may change without this triggering an obligation to update the record.
The proactive information obligations under Article 13(1)(e) and Article 14(1)(e) GDPR likewise allow the indication of categories. The position is different in the case of the reactive obligation to provide access (on this, see 5. below).
5. Recipients under the right of access
The right of access under Article 15(1)(c) GDPR obliges the controller to provide information about the recipients or categories of recipients to whom the personal data have been or will be disclosed.
The CJEU has clarified that the data subject is in principle entitled to be told the specific recipients. A limitation to categories of recipients is permissible only by way of exception: where the identity of the recipients is not yet ascertainable, or where the request for access is manifestly unfounded or excessive within the meaning of Article 12(5) GDPR (CJEU, judgment of 12 January 2023, C-154/21, RW v Österreichische Post, paras. 46, 48).
The CJEU bases this on the principle of transparency under Article 5(1)(a) GDPR: only knowledge of the specific recipients enables the data subject to effectively exercise its further rights, in particular to rectification, erasure and restriction of processing, vis-a-vis all parties involved. The right of access relates in this respect to disclosures that have actually taken place; disclosures that are still outstanding and merely planned may be described in categories.
For practice, it follows that anyone who wishes to answer requests for access quickly and completely should record, in the internal data protection management system, not only the categories of recipients but also the specific recipients, even though the record of processing activities under Article 30 GDPR requires only categories.
6. Disclosure to recipients and purpose limitation
The fact that a body is a recipient says nothing about whether the disclosure is permissible. Every disclosure to a recipient is a processing operation and must be based on a legal basis.
Purpose limitation is of particular importance here: personnel data, for example, may be disclosed to superiors only insofar as this is necessary for the employment relationship; a disclosure solely because it appears useful or practical is not sufficient. Necessity and proportionality, not mere usefulness, are the yardstick.
Under Article 19 GDPR, the controller must, in addition, inform all recipients to which personal data have been disclosed of any rectification, erasure or restriction of processing, unless this proves impossible or involves disproportionate effort. On request by the data subject, the controller must inform it about which recipients have been notified.
Third party (Article 4(10) GDPR)
Distinction between recipient and third party.
Processor (Article 4(8) GDPR)
The processor as a special case of the recipient.
Processing (Article 4(2) GDPR)
Disclosure and transmission as forms of processing.
CJEU C-154/21 Österreichische Post
Right of access: specific recipients rather than categories as the rule.
Article 4(9) GDPR
Legal definition of the recipient in the statutory text.
Recital 31 GDPR
Public authorities acting under a particular inquiry as non-recipients.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Processor (Article 4(8) GDPR)
A processor is any body that processes personal data on behalf of the controller. The GDPR establishes the processor's own obligations and independent liability.
Third Party (Article 4(10) GDPR)
Who qualifies as a third party within the meaning of the GDPR, why there is no group privilege, and how third parties are distinguished from employees, processors, and branches.