Sharing personal data with another organisation may feel like a routine: a marketing platform, an analytics tool, a payroll provider, a partner integration. Each one of those relationships is also a distinct legal exposure under GDPR, and the biggest fine in the regulation’s history was issued over exactly this kind of arrangement.
• GDPR treats data sharing as a “transfer” with additional legal requirements whenever the recipient sits outside the EEA, regardless of whether the recipient is a separate controller, a joint controller, or a processor.
• Meta was fined €1.2 billion in 2023, the largest GDPR fine to date, specifically over how it transferred EU users’ data to the US using Standard Contractual Clauses that the regulator found insufficient.
• Article 82’s joint and several liability means an individual harmed by a data sharing failure can pursue the better-funded party in the chain, regardless of which organisation actually caused the problem.
• If you share data without checking a recipient’s safeguards first, you accept the risk of that recipient’s non-compliance by default.
Data sharing covers any disclosure of personal data from one organisation to another, whether that recipient is a separate controller determining its own purposes for the data, a joint controller sharing decision-making with you, or a processor handling the data purely on your instructions. Each of these relationships carries different obligations, but all three require a lawful basis, transparency to the individuals involved, and appropriate safeguards before the sharing happens.
A transfer occurs when a controller or processor makes personal data available to another controller, joint controller, or processor located outside the European Economic Area. Where that condition is met, Chapter V of GDPR adds a further layer of requirements on top of the general obligations that apply to any data sharing, typically an adequacy decision covering the destination country, Standard Contractual Clauses, or another approved transfer mechanism.
This distinction matters because international transfers carry meaningfully higher enforcement risk than domestic sharing. The mechanism itself, such as SCCs, is not automatically sufficient. It has to be backed by an assessment of whether the destination country’s laws actually allow the protections in that mechanism to function in practice.
On 22 May 2023, the Irish Data Protection Commission fined Meta Ireland €1.2 billion, the largest GDPR fine issued to date, over how Facebook transferred EU users’ personal data to the United States. Meta had relied on Standard Contractual Clauses and supplementary measures to justify these transfers since July 2020, following the CJEU’s Schrems II ruling, which struck down the previous EU-US Privacy Shield framework.
The regulator concluded that Meta’s SCCs and additional safeguards did not adequately address the risk that US surveillance laws posed to the data once it arrived, meaning the transfers themselves were unlawful regardless of the paperwork behind them. Meta was ordered to suspend further transfers within five months and bring its US processing into compliance within six. At a record-breaking fine, the case confirmed that signing a standard transfer mechanism is not sufficient on its own if the destination country’s legal environment undermines what that mechanism promises.
Article 82 GDPR establishes joint and several liability between controllers and processors involved in the same processing operation where damage results. In practice, this means an individual harmed by a data sharing failure can pursue full compensation from whichever party in the chain is best positioned to pay, regardless of which specific organisation actually caused the failure. The controller that shared the data with a non-compliant recipient does not get to point to that recipient as the sole responsible party.
This is a strong incentive to assess data recipients before sharing, not after something goes wrong. A controller that shares data with a vendor without checking that vendor’s security measures or compliance posture is generally treated as having accepted the risk of that vendor’s failures, rather than being shielded by the fact that the failure technically happened on the vendor’s side.
Beyond headline international transfer cases, everyday data sharing risk tends to cluster around a smaller set of patterns: analytics and advertising tools that transmit user data to servers outside the EEA by default, embedded third-party scripts and pixels that fire before a user has given consent, vendor integrations added without a signed Data Processing Agreement in place, and internal data exports, such as spreadsheets sent to a partner, that bypass whatever controls exist on the primary systems.
Tools like Google Analytics and the Meta Pixel are common sources of exactly this kind of exposure, since both transmit user data to servers outside the EEA as part of normal operation, and both have been the subject of specific GDPR enforcement action in multiple member states over how that transfer and the underlying consent were handled.
Practical risk reduction starts with mapping every third party your organisation actually shares personal data with, since undocumented sharing relationships are the ones that get missed during a compliance review. From there, confirming a Data Processing Agreement is in place wherever a processor relationship exists, checking whether any recipient sits outside the EEA and what transfer mechanism covers that specific relationship, and periodically reassessing vendors rather than treating the initial due diligence as permanent all reduce exposure meaningfully.
Minimising what gets shared in the first place is the most durable control. A vendor that never receives a field cannot leak, misuse, or unlawfully transfer that field, regardless of how strong their own security posture is.
Data sharing risk usually goes unnoticed until something forces a review. It builds up through ordinary vendor relationships, analytics tools, and cross-border integrations that each seemed reasonable in isolation. The Meta case shows what that risk looks like at the largest possible scale. The same underlying failure, signing a transfer mechanism once and never checking it again, shows up far more often in much smaller organisations. Mapping who actually receives your data, and checking that the legal basis for sending it to them still holds, is the work that prevents both outcomes.
Yes. Sharing with a processor requires a Data Processing Agreement under Article 28 governing how that processor handles the data on your instructions. Sharing with a separate or joint controller requires its own lawful basis and, where the relationship is a joint controllership, an arrangement under Article 26 setting out each party’s responsibilities.
No, not automatically. It depends on whether the provider has a valid transfer mechanism in place, such as an adequacy decision or Standard Contractual Clauses backed by an adequate assessment of the destination country’s legal environment. The Meta case shows that having SCCs in place is not sufficient on its own if the underlying risk to the data has not genuinely been addressed.
Potentially, yes. Article 82’s joint and several liability means the organisation that originally shared the data can be pursued for compensation alongside or instead of the vendor, particularly if adequate due diligence was not carried out before the sharing relationship began.
Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.
About the Author
Ana Mishova
Sales and Business Development Consultant — GDPRLocal
Ana focuses on helping organisations understand their compliance obligations and find the right data protection solutions. At GDPRLocal she works closely with businesses of all sizes, making GDPR and privacy compliance clear, practical, and accessible.