# CJEU, judgment of 12 January 2023, C-154/21, RW/Österreichische Post

Access to information on the recipients of personal data under Article 15(1)(c) GDPR: in principle an obligation to name the specific recipients; limitation to categories only by way of exception.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.40-eugh-c-154-21-oesterreichische-post
> Sprache: en



## 1 Overview [#1-overview]

In 2019, RW requested Österreichische Post to provide him with access under Article 15(1)(c) GDPR to information as to the recipients to whom his personal data had been disclosed. Österreichische Post initially named only categories of recipients. The Austrian Supreme Court (OGH) referred to the CJEU the question whether the choice between "recipients" and "categories of recipients" lies with the controller or with the data subject.

## 2 Headnotes [#2-headnotes]

Article 15(1)(c) GDPR is to be interpreted as meaning that the data subject is in principle entitled to be informed of the **identity of the specific recipients** to whom his or her data have been or will be disclosed ([CJEU, judgment of 12 January 2023, C-154/21, RW, para. 46](https://curia.europa.eu/juris/document/document.jsf?docid=268781\&doclang=DE)).

The limitation to **categories** of recipients is a narrowly defined exception. It comes into consideration only where (a) the identity of the recipients is not yet ascertainable or (b) the controller demonstrates that the request for access is manifestly unfounded or excessive within the meaning of Article 12(5) GDPR (para. 48).

The CJEU relies on the **principle of transparency** (Article 5(1)(a) GDPR) and on Recital 63: only knowledge of the specific recipients enables the data subject to exercise his or her further rights under the GDPR (in particular rectification, erasure and restriction) effectively against all those involved.

## 3 Significance [#3-significance]

The decision effectively shifts the choice between specific recipients and categories of recipients to the data subject: as soon as the data subject asks for the specific recipients, the controller must name them. The limitation to categories becomes the exception.

Consequences for documentation practice:

* **Record of processing activities (Article 30 GDPR).** The provision requires only categories of recipients, and nothing has changed in that respect. However, anyone who also uses the record as a tool of their data protection management system should additionally capture the specific recipients, so as to be able to answer requests for access quickly (see [records of processing activities](/docs/dsgvo-hub/einzelthemen/1.3.7-verzeichnis-von-verarbeitungstaetigkeiten)).
* **Privacy notices.** The proactive information obligations under Articles 13 and 14 GDPR continue to permit categories of recipients; the strictness of Article 15(c) does not carry over one to one.

<Cards>
  <Card title="Records of processing activities (Article 30 GDPR)" href="/docs/dsgvo-hub/einzelthemen/1.3.7-verzeichnis-von-verarbeitungstaetigkeiten" description="Information on recipients in the record and in the right of access." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.