WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
CJEU Finds That Companies Must Provide Individuals with the Identity of Data Recipients When Responding to Data Access Requests
Alerts
January 27, 2023

On January 12, 2023, the Court of Justice of the European Union (CJEU) ruled1 that the data subject’s right of access to personal data2 requires controllers to provide the data subject with the identity of the companies that they have shared or will share data with. This is a sharp departure from current market practice since many controllers typically provide the categories of data recipients, and not their actual identity, when responding to data subjects access requests.

Although the CJEU provides for some exceptions to this requirement, this development sets further transparency obligations on companies.

Background

An individual made a General Data Protection Regulation (GDPR) access request to the Austrian postal services (Österreichische Post, or ÖP). In response, ÖP informed the individual that his personal data had been disclosed to customers, mailing list providers, and associations such as charitable organizations, nongovernmental organizations, and political parties. ÖP did not otherwise provide further details regarding the actual identity of each data recipient. The individual subsequently brought proceedings against ÖP before the Austrian courts seeking an order that ÖP must provide the individual with the actual identity of the recipients of his personal data.

The Austrian courts at first instance and on appeal dismissed the individual’s claim on the ground that the wording of Article 15 (1) (c) GDPR (“the recipients or categories of recipient”) gives the controller discretion of informing the data subject about categories of recipients only. As such, the controller does not need to identify by name any specific recipients to whom the personal data have been or will be disclosed.

However, the Austrian Supreme Court sought clarification and made a request for a preliminary ruling to the CJEU as to whether the wording of Article 15(1)(c) GDPR is meant to provide the option to the controller to decide the level of detail that it will provide to the data subject (categories of recipients or actual identity of recipients).

CJEU Ruling

The CJEU held that data subjects have the right to obtain information about the specific recipients to whom their personal data is disclosed. This right cannot, in principle, be restricted to merely categories of recipients at the data controller’s discretion. According to the CJEU, this interpretation ensures transparency towards data subjects and enables them to effectively exercise their rights under the GDPR, such as the right to restriction of processing or the right to object to processing. It also enables individuals to confirm that their data is processed in a lawful manner and that it has been disclosed to authorized recipients. The CJEU further notes that the provided information to the data subject must be “as precise as possible.”3

However, the CJEU’s ruling provides that the right of access may be restricted to “categories of recipients” in certain circumstances:

  • Impossible to disclose specific recipient(s): The CJEU refers to the principle of proportionality and states that the information can be limited to categories of recipients if it is “impossible to disclose the identity of specific recipients.”4 The CJEU does not further expand on the notion of “impossibility.”
  • Access request is unfounded or excessive: The CJEU makes reference to Art 12 (5) (b) GDPR, according to which controllers may refuse to act on an access request where it is “manifestly unfounded or excessive.” However, it is the controller’s responsibility to demonstrate that a request is unfounded or excessive.

Implications and Conclusion

The CJEU’s ruling increases transparency obligations for companies and requires them to engage in a fact-finding mission to inform data subjects as precisely as possible about the specific data recipients. Overall, companies may need to perform a balancing test in light of the principle of proportionality in each access request to determine whether information about specific data recipients must, and can, be provided to data subjects.

Wilson Sonsini Goodrich & Rosati routinely advises clients on GDPR compliance issues, and helps clients manage risks related to the enforcement of global and European data protection laws. For more information, please contact Cédric Burton, Laura De Boel, Maneesha Mithal, Nikolaos Theodorakis, or another member of the firm’s privacy and cybersecurity practice.

Cédric Burton, Nikolaos Theodorakis, and Michael Kern contributed to the preparation of this Alert.


[1]CJEU judgment in case C-154/21, RW v Österreichische Post, January 12, 2023.

[2]Within the meaning of Article 15 GDPR.

[3]CJEU judgment in case C-154/21, RW v Österreichische Post, January 12, 2023, par. 43.

[4]CJEU judgment in case C-154/21, RW v Österreichische Post, January 12, 2023, par. 48.

Contributors

  • Cédric Burton
  • Nikolaos Theodorakis
  • Michael Kern
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.