# Third Party (Article 4(10) GDPR)

Who qualifies as a third party within the meaning of the GDPR, why there is no group privilege, and how third parties are distinguished from employees, processors, and branches.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/begriffe-und-definitionen/1.2.10-dritter
> Sprache: en



Under Article 4(10) GDPR, a third party is any person or body outside the controller's organization. The significance of the term lies in its legal consequence: if the controller passes data to a third party, this constitutes a transmission and thus a processing operation in its own right that requires a legal basis, rather than mere internal use.

<Callout type="info">
  **Key takeaways**

  * A third party is any person or body other than the data subject, the controller, the processor and the persons acting under their direct authority (Article 4(10) GDPR).
  * Passing data to a third party is a transmission and thus a processing operation requiring a legal justification, not internal use.
  * There is no group privilege: every legal person within a corporate group is a third party in relation to the others.
  * Employees who receive data in their official capacity are recipients, not third parties; only outside that capacity or in the event of abusive access do they become third parties.
  * Branches that have no separate legal personality are part of the controller's organization, not third parties.
</Callout>

## 1. Overview [#1-overview]

### 1.1 Legal definition and delimitation by exclusion [#11-legal-definition-and-delimitation-by-exclusion]

Under Article 4(10) GDPR, a third party is a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or processor, are authorized to process the personal data (Article 4(10) GDPR). The term operates by exclusion: a third party is whoever remains once all the other roles have been subtracted. Accordingly, anyone who is not the data subject, the [controller](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.7-verantwortlicher), the [processor](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.8-auftragsverarbeiter) or a person acting under their instructions stands outside the controller's organization and is a third party.

### 1.2 Legal consequence: passing data on is a transmission [#12-legal-consequence-passing-data-on-is-a-transmission]

The practical significance of the term lies in the legal classification of the disclosure of data. If data reaches a third party, a transmission occurs, that is, a sub-form of [processing](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.2-verarbeitung). It requires its own legal basis and is subject to the full requirements of the GDPR. If, by contrast, the data remains within the controller's organization, this constitutes mere internal use in the form of passing the data on, which does not need to be justified as a transmission to a third party.

### 1.3 Relationship to the recipient [#13-relationship-to-the-recipient]

Third party and [recipient](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.9-empfaenger) are not congruent. A recipient is any body to which data is disclosed, regardless of whether it is a third party or not. Every third party that receives data is therefore a recipient; not every recipient, however, is a third party. Employees who access data in their official capacity are recipients within the controller's organization without thereby being third parties.

## 2. Part of the controller's organization or third party [#2-part-of-the-controllers-organization-or-third-party]

The central distinction runs between persons and bodies that belong to the controller's organization and those that stand outside it. Anyone acting within their function for the controller or the processor is not a third party.

| Role                                                   | Classification                        | Rationale                                                    |
| ------------------------------------------------------ | ------------------------------------- | ------------------------------------------------------------ |
| Managing director, management board, supervisory board | Part of the controller's organization | Act in a corporate-body or management capacity               |
| Company physician, in-house officers                   | Part of the controller's organization | Act within their in-house function                           |
| Head of a public authority or agency                   | Part of the controller's organization | Act in a management capacity for the body                    |
| Employees in their official capacity                   | Recipient, not third party            | Access under the direct authority of the controller          |
| Employees outside their function                       | Third party                           | Act as a private individual, not for the body                |
| Employees in cases of data misuse                      | Third party                           | Unauthorized access not required for their duties            |
| Self-employed commercial agent                         | Third party                           | Independent trader (Section 84 German Commercial Code (HGB)) |

### 2.1 Employees and data misuse [#21-employees-and-data-misuse]

Employees who receive data in their official capacity are not third parties but persons acting under the direct authority of the controller. They become third parties only when they act outside their function, for example as a private individual, or when they access data on their own initiative and without any operational necessity. Such abusive access exceeds the scope of the authorization and thus lies outside the controller's organization.

### 2.2 Self-employed commercial agent [#22-self-employed-commercial-agent]

A self-employed commercial agent remains a third party even when acting for the controller. What matters is their independence as a trader (§ 84 HGB): they do not act under the direct instructions of the controller but as an independent body.

## 3. No group privilege [#3-no-group-privilege]

A widespread misconception concerns the exchange of data within corporate groups. The GDPR recognizes no group privilege: all undertakings within a corporate group or an integrated group (Organschaft) are third parties in relation to one another, because every legal person, such as an AG or GmbH, is an independent controller.

<Callout type="warn">
  Disclosures of data between group companies are transmissions to third parties and each requires its own legal basis. Affiliation under company and tax law does not replace that legal basis.
</Callout>

This is not altered by affiliation under stock corporation law (Section 15 of the German Stock Corporation Act (AktG)), by consolidated financial statements under commercial law, or by a tax group (Section 14 of the German Corporate Income Tax Act (KStG)). These structures link the undertakings economically, in accounting terms, or fiscally, but do not abolish the separate controllership under data protection law. While the GDPR does acknowledge the group of undertakings as a phenomenon and grants it certain concessions, it leaves the separate controllership of the individual companies untouched.

## 4. Public authorities and public bodies [#4-public-authorities-and-public-bodies]

In the public sector a functional concept of the body applies. Every other public authority is a third party, even if it belongs to the same legal entity. Within a single public authority, even functionally separate departments can be third parties in relation to one another if they are subject to different confidentiality regimes.

| Department / body     | Applicable secrecy duty     | Provision                                    |
| --------------------- | --------------------------- | -------------------------------------------- |
| Social welfare office | Social secrecy              | Section 35 German Social Code Book I (SGB I) |
| Tax office            | Tax secrecy                 | Section 30 German Fiscal Code (AO)           |
| Personnel office      | General data protection law | GDPR                                         |

This functional separation means that the departments must be treated as third parties in relation to one another. Municipal enterprises (Eigenbetriebe), too, are third parties in relation to other departments or enterprises. Entrusted private parties (Beliehene), that is, private persons carrying out public-authority tasks, are always third parties in relation to a public body; this applies, for example, to the technical inspection body during the main vehicle inspection or to the lawyer-notary.

## 5. Special case: the branch [#5-special-case-the-branch]

A branch, outlet, or place of business that has no separate legal personality is part of the controller's organization and not a third party. If the main office passes data to such a branch, this constitutes use of data in the form of internal passing-on, not a transmission. This holds until the branch itself becomes a controller, for example because it operates its own personnel management system and decides independently on the processing.

<Callout type="info">
  What matters is legal independence, not physical separation. A separate legal person is a third party even when it belongs to the same corporate group; a dependent outlet remains part of the controller's organization even at a great physical distance.
</Callout>

## 6. Works council and staff council [#6-works-council-and-staff-council]

The classification of the works council and the staff council is disputed. Under the case law of the German Federal Labor Court (BAG), the works council is part of the controller's organization. National law confirms this position: it designates the employer (Section 79a of the German Works Constitution Act (BetrVG)) or, respectively, the agency (Section 69 of the German Federal Staff Representation Act (BPersVG)) as the controller. The disclosure of data to the works council or staff council is therefore governed by the sector-specific rules of works and staff representation law.

The position is different for representative bodies formed at a different level. Group works councils, combined works councils and combined staff councils, as well as main and district staff councils, are always third parties in relation to the individual controller. Trade union shop stewards are representatives of the trade union and are therefore likewise always third parties.

<Cards>
  <Card title="Controller" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.7-verantwortlicher" description="Article 4(7) GDPR: the party that decides on the purposes and means and forms the controller's organization." />

  <Card title="Processor" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.8-auftragsverarbeiter" description="Article 4(8) GDPR: processing on behalf of the controller, not a third party." />

  <Card title="Recipient" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.9-empfaenger" description="Article 4(9) GDPR: delimitation from the third party." />

  <Card title="Processing" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.2-verarbeitung" description="Article 4(2) GDPR: transmission as a form of processing." />

  <Card title="Article 4 GDPR" href="https://dsgvo-gesetz.de/art-4-dsgvo/" description="Definitions, point (10) on the third party." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.