Article 19 GDPR
Legal Text
The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.
Relevant Recitals
Commentary
When a controller is obliged to rectify, erase or restrict personal data in accordance with Articles 16, 17(1) or 18 GDPR, this only affects the personal data under the control of the controller (i.e. for which the controller determines the purposes and means of the processing - see Article 4(7) GDPR). The GDPR recognises that any ground for rectification, deletion or restriction could also be relevant for any recipients of the data who might not be aware of the issues that led to the rectification, deletion or restriction by the original controller.[1]
Similarly, the usefulness of the data subjects' rights is limited if the personal data has already been transferred to third parties and those parties are not informed about the data subjects exercising their rights.
For example: A retailer collects the incorrect address of the data subject and discloses this information to a postal service provider for the deliverance of a package and to a debt collection agency for the collection of an outstanding debt. If the retailer finally finds out about the incorrectness of the address, it is obvious that also the recipients of the information need to know about the incorrectness.
Article 19 GDPR therefore requires controllers to communicate their exercise to any recipients of personal data subject to rectification, deletion or restriction under Articles 16, 17(1) or 18 GDPR.[2] However, Article 19 GDPR provides also for an exemption of this duty in case the notification of the recipients proves impossible or involves disproportionate effort.
Finally, the data subject can request to be informed about the recipients of such notification.
Shall Communicate ... to Each Recipient
The first sentence of Article 19 GDPR requires the controller to communicate any rectification, erasure or restriction of personal data carried out in accordance with Articles 16, 17(1) or 18 GDPR to all recipients to whom the affected personal data have been disclosed.
Similar to the controller's information obligation in Articles 13 and 14 GDPR, the notification obligation under Article 19 GDPR does not need a prior request by the data subject but has to be performed on the controller's own initiative. This is not the case regarding the information of the data subject about those recipients (see Commentary on the information of the data subject bellow). However, it is commonly understood that the notification obligation under Article 19 GDPR is only applicable in case the data subject requested the rectification, erasure or restriction of the data; in particular, the deletion on the controller's own initiative due to an obligation under Article 17(1) GDPR would not fall under Article 19 GDPR.[3] But such an interpretation is not covered by the wording of the provision and a different handling of this situation makes little sense, e.g. considering the obligation to delete data in case it was unlawfully processed.
For example: A credit information agency processes information about an outstanding debt of a data subject. It turns out that the information was incorrect and the debt did not refer to the data subject. In the meantime the credit information agency disclosed the information to some customers (banks, insurance companies, etc).
It would be unreasonable to apply the credit information agency's notification obligation under Article 19 GDPR only in case the data subject exercised its right of erasure and not in case the controller deleted the information on its own initiative (e.g. after being informed by its data source). Rather, the controller should notify any recipients in both cases.
A recipient of the personal data is any natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not (see Commentary on the definition of recipient in Article 4(9) GDPR). While the provision clearly covers recipients, the CJEU indicated that there can also be an obligation to inform the source from which the controller received that personal data (even if not directly under Article 19 GDPR).[4]
The disclosure can take place by transmission, dissemination or by otherwise making the data available.[5] However, if data has been made public, the applicable notification provision is Article 17(2) GDPR, provided that all requirements set therein are met (see below).[6]
Article 19 GDPR does not establish any specific modalities or time requirements for the notification. However, Article 12 GDPR provides for such modalities and is applicable to Article 19 GDPR. These modalities can therefore be applied to the notification obligation as well.[7] Therefore, the notification should be done immediately and recipients should be notified either “in writing, or by other means, including, where appropriate, by electronic means” (Article 12(1) GDPR).[8]
The controller is only obliged to communicate any rectification, deletion or restriction but is not responsible for any action taken by the recipient. Also the recipient itself is not directly obliged by this provision to perform any rectification, deletion or restriction itself. However, they can be obliged under Article 5(1)(d) and 17(1) GDPR to correct or delete the affected personal data when they are aware it is inaccurate or a ground for deletion applies.[9] In particular, if the recipient processes the affected personal data based on another legal basis under Article 6 GDPR and for another purpose or can use either of the exceptions under Article 17(3) GDPR, the controller might not be under an obligation to rectify or delete the affected personal data.[10]
For example: An employer processes some of the personal data of its employee for insurance purposes and discloses the data to an insurance agency. Shortly after the disclosure to the insurance agency, the controller doesn't need the data anymore for the purposes for which the data was originally collected for. After failing to erase the data on its own, the employee files an erasure request based on Article 17(1)(a) GDPR. The controller notifies the insurance about the erasure of the data. However, the insurance still needs the data for the purposes of providing the insurance and its storage obligations.
The obligation to notify under Article 19 GDPR should not be confused with that under Article 17(2) regarding the "right to be forgotten". Article 17(2) applies when the number of recipients is indeterminate, whereas in the case of Article 19 GDPR, the number is determinate. Also, Article 17(2) GDPR only applies to cases of requests for erasure, while Article 19 includes cases of rectification and restriction of processing, as provided for in Articles 16 and 18 of the GDPR, respectively.
Exemptions from Notification Obligation
The controller is exempted from the notification obligation if the communication proves impossible or involves disproportionate effort. Exceptions to the notification requirement must be interpreted narrowly.[11] Thus, they only apply to communication to recipients, but not to any preparatory measures needed to reach out to them such as compiling a list of all recipients of the data subject's data. The controller bears the burden of proof to show exceptions apply.[12]
Unless this proves impossible
A communication is only impossible if it is factually impossible to determine the recipients, such as when a recipient is not reachable or no longer exists and has no legal successor. Thus, the use of a data protection management system is recommended insofar as it keeps track of each recipient and enables the rapid implementation of the notification obligation after each correction, deletion and restriction of processing.[13] Financial or other practical difficulties are irrelevant, and may only be considered when evaluating disproportionate effort.[14]
Or involves disproportionate effort
The assessment of "disproportionate effort" must be carried out on a case by case basis. The cost for the controller (in terms of money and time) and the recipients need to be weighed against the interests of the data subject. To evaluate the interests of the data subject, consideration should be given to the impact of the processing on their rights and freedoms, the likelihood that the recipients will still be processing the data contrary to the exercise of the data subject's rights, and whether the communication is actually in the interest of the data subject.[15]
Reference can be made to the similar assessment (exemption from the information obligation in case of a disproportionate effort) in Article 14(5)(b) GDPR (see commentary on that provision).
Information Obligation Towards the Data Subject
The second sentence of Article 19 GDPR stipulates that the controller must, if requested by the data subject, inform him or her about those recipients.
It has been debated whether “those recipients” refers to all recipients to whom the personal data have been disclosed, or only those who are actually notified (excluding, therefore, those for which notification proved impossible, or involved a disproportionate effort). In line with the objectives of the GDPR, the latter reading "should in principle be excluded, as the data subject has a special interest in knowing precisely which recipients might hold the data but have not been notified, in order to reach out to them by other means, if appropriate".[16] This understanding is supported by the purpose of Article 19 GDPR, which is to support the exercise of the rights to rectification, erasure, and restriction.[17] Indeed, the data subject can only enforce these if they know the actual recipients of their personal data. Moreover, the EDPB seems to support this interpretation in their Guidelines on the Right of Access.[18] However, the scope of the obligation is subject to some debate.[19] The information given to the data subject should comply with the general requirements set forth in Article 12 GDPR.[20]
This information obligation, the second sentence of Article 19 GDPR, does not provide for the two exemptions provided for in the notification obligation (first sentence of Article 19 GDPR), namely impossibility or disproportionate effort. Therefore, the controller must be able to provide the information to the data subject if so requested. In order to comply with this obligation, the controller has to record the recipients of personal data.
Member State Restrictions
→ See Article 23 GDPR.
Decisions
→ You can find all related decisions in Category:Article 19 GDPR.
References
- ↑ Herbst, in Kühling, Buchner, DS-GVO BDSG, Article 19 GDPR, margin numbers 1 (C.H. Beck 2024, 4th Edition).
- ↑ See Article 4(9) GDPR for the definition of recipient.
- ↑ Dix, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 19 GDPR, margin number 7 (NOMOS 2025, 2nd Edition).
- ↑ CJEU, Case C‑129/21, Proximus, 27 October 2022, margin number 83 (available here).
- ↑ See the definition for "processing" in Article 4(2) GDPR.
- ↑ Dix, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 19 GDPR, margin number 5 (NOMOS 2025, 2nd Edition); see also commentary on Article 17(2) GDPR for the requirements of this provision.
- ↑ So for example Dix, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 19 GDPR, margin numbers 6 and 8 (NOMOS 2025, 2nd Edition).
- ↑ Herbst, in Kühling, Buchner, DS-GVO BDSG, Article 19 GDPR, margin numbers 12 (C.H. Beck 2024, 4th Edition).
- ↑ Herbst, in Kühling, Buchner, DS-GVO BDSG, Article 19 GDPR, margin numbers 1 (C.H. Beck 2024, 4th Edition).
- ↑ Dix, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 19 GDPR, margin number 9 (NOMOS 2025, 2nd Edition).
- ↑ Kamann, Braun, in Ehmann, Selmayr, DS-GVO, Article 19 GDPR, margin number 13 (C.H. Beck 2024, 3rd Edition).
- ↑ Compare Dix, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 19 GDPR, margin number 8 (NOMOS 2025, 2nd Edition).
- ↑ Dix, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 19 GDPR, margin number 7 and 11 (NOMOS 2025, 2nd Edition); Kamann, Braun, in Ehmann, Selmayr, DS-GVO, Article 19 GDPR, margin number 14 (C.H. Beck 2024, 3rd Edition).
- ↑ Kamann, Braun, in Ehmann, Selmayr, DS-GVO, Article 19 GDPR, margin number 14 (C.H. Beck 2024, 3rd Edition).
- ↑ Kamann, Braun, in Ehmann, Selmayr, DS-GVO, Article 19 GDPR, margin number 15 (C.H. Beck 2024, 3rd Edition).
- ↑ Gonzáles Fuster, in Kuner, Bygrave and Docksey, The EU General Data Protection Regulation (GDPR): A commentary, Article 19 GDPR, p. 496 (Oxford University Press, 2020).
- ↑ Peuker, in Sydow, Marsch, EU-DSGVO BDSG, Article 19 GDPR, margin number 13 (C.H. Beck, 3rd Edition 2022); Herbst, in Kühling, Buchner, DS-GVO BDSG, Article 19 GDPR, margin numbers 14 (C.H. Beck 2024, 4th Edition).
- ↑ EDPB, ‘Guidelines 01/2022 on data subject rights - Right of access’, 28 March 2023 (Version 2.0), p. 49 (available, 18 January 2022 (Version 1.0), p. 39 (available here), in which the Board states that they recall that “storing information relating to the actual recipients is necessary inter alia to be able to comply with the controller’s obligations under Art. 5(2) and 19 GDPR”.
- ↑ E.g. see Herbst, in Kühling, Buchner, DS-GVO BDSG, Article 19 GDPR, margin numbers 13 (C.H. Beck 2024, 4th Edition) arguing for a obligation to store the recipients for an appropriate duration.
- ↑ Peuker, in Sydow, Marsch, EU-DSGVO BDSG, Article 19 GDPR, margin number 14 (C.H. Beck, 3rd Edition 2022).




