Sending personal dataPersonal dataAny information relating to an identified or identifiable person: names, IDs, location, online identifiers, and combinations that single someone out. to another organisation is processing. It needs a lawful basis in its own right, and the basis that justified collecting the data does not automatically travel with it.
The five questions to answer before sharing
Answer these in writing, once, for each recurring disclosure — not per email:
- What is the purpose of this disclosure? Stated narrowly enough to test.
- What is the lawful basis for it? Not for the original collection — for this act.
- Is the disclosure necessary for that purpose, and is all of the data necessary?
- Is the recipient a controller or a processor? This decides whether you need a processing contract or whether they take on their own responsibilities.
- Have we told people this happens? Recipients or categories of recipient must be in the privacy notice, and disclosed on request in a subject access response.
If you cannot answer question 2 without using the words “we always have”, you do not yet have an answer. See the legitimate interests assessment.
Controller or processor — and why it is not a formality
A processor acts on your instructions and for your purposes. You need a contract meeting the Article 28 requirements, and you remain responsible.
A controller-to-controller disclosure is different: the recipient decides its own purposes and takes on its own obligations, including telling the individual what it now holds. Organisations frequently share data controllerControllerDecides why and how personal data is processed. Carries most of the duties — and the fines.-to-controller while behaving as though it were a processorProcessorProcesses on the controller’s instructions — cloud hosts, payroll bureaus — with its own security and breach duties. arrangement — no contract, no notice, no accountability at either end.
The practical test is who decides why. An organisation that receives data and then uses it to make its own decisions is a controller, whatever the paperwork says.
Sector arrangements and shared claims processes
Routine inter-organisation sharing — settling claims, allocating liability, reconciling accounts — is common and often legitimate. What makes it lawful is the assessment, not the convention.
Two failure modes recur:
- Sharing on an assumption. Data is passed to another organisation because someone believes they were involved. If the belief is wrong, the purpose the disclosure served did not exist, and both the necessity and the balance collapse. The error is not a separate minor issue — it removes the foundation of the basis.
- Sharing more than the process needs. Where the question is “which of us bears this cost”, the answer often requires a reference number and a date, not an identity. Test the data against the question actually being asked.
When rectification meets disclosure
If you corrected data that you had already sent elsewhere, you must communicate the rectification to each recipient unless that proves impossible or involves disproportionate effort — and tell the individual who the recipients were if they ask.
This is the connective tissue between two complaints that usually arrive together: the data was wrong, and the wrong version went to a third party. Fixing your own record does not finish the job. See rectification in practice.
Is an unauthorised disclosure a breach?
Frequently, yes. A personal data breach includes unauthorised disclosure of personal data — it is not confined to security incidents in the hacking sense. Sending data to an organisation that had no basis to receive it is capable of meeting the definition, and the assessment should be run properly rather than dismissed because nothing was attacked. See when to report yourself.
For the person who has discovered an unexpected disclosure
Ask for these, specifically:
- The recipients, by name rather than category, and the date of each disclosure.
- The lawful basis relied on for the disclosure itself.
- The assessment, if it was legitimate interestsLegitimate interestsUpdate: DUAA 2025 introduced a \, and the date it was carried out.
- What data was sent — the fields, not a summary.
- Whether the recipient was a controller or processor, and the contract if a processor.
- What has happened to the data since, including whether the recipient has been told to delete it.
A subject access request will usually surface the disclosure itself. These questions are what turn “this happened” into “this happened without a basis”, which is the complaint that actually goes somewhere.