
GDPR Article 13: privacy policy missing processors
At a glance
EU-04HighGDPR Art. 13(1)(e), 14(1)(e); Art. 83(5)(b)
Peeky lists the outside companies your public pages contact and compares them with the companies your privacy policy names.
Last checked against the source:
The rule
Article 13(1) of the GDPR applies “where personal data relating to a data subject are collected from the data subject”. The controller “shall, at the time when personal data are obtained”, provide a list of information, and point (e) of that list is “the recipients or categories of recipients of the personal data, if any”. Article 14(1)(e) repeats point (e) in the same words for data that “have not been obtained from the data subject”.
The word “recipient” is wide. Article 4(9) defines it as “a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not”. A processor, which under Article 4(8) processes personal data “on behalf of the controller”, is therefore a recipient. So is an analytics provider, an ad network or a chat widget, once personal data reach it.
The Article 29 Working Party’s transparency guidelines say how to choose between naming recipients and giving categories.
“The actual (named) recipients of the personal data, or the categories of recipients, must be provided. In accordance with the principle of fairness, controllers must provide information on the recipients that is most meaningful for data subjects. In practice, this will generally be the named recipients, so that data subjects know exactly who has their personal data.” Where categories are used, they “should be as specific as possible by indicating the type of recipient (i.e. by reference to the activities it carries out), the industry, sector and sub-sector and the location of the recipients.”
Article 12(1) adds that the information be given “in a concise, transparent, intelligible and easily accessible form, using clear and plain language”, so where the list sits and how it reads count as well as what it says.
On penalties, Article 83(5)(b) places “the data subjects’ rights pursuant to Articles 12 to 22” in the upper tier, with a ceiling of EUR 20 million or 4% of worldwide annual turnover, whichever is higher. Articles 13 and 14 sit inside that range. The check’s citation lists Art. 83(5) generally; the applicable point is (b), and the AEPD applied it to an Article 13 finding in the decision listed below. It set EUR 2,000 and noted that Spanish law classes a failure to give all the Article 13 and 14 information as minor for limitation purposes. The Garante’s EUR 120,000 covers several findings together, so the share for the notice is not stated.
What PeekWell checks and how
EU-04 asks one question: does the privacy policy say who the site actually talks to? It answers by comparing two lists, one from what the browser did and one from what the policy says.
The observed list comes from the same clean visit the other checks use. The scan opens a public page as an ordinary visitor’s browser would and records every distinct third-party domain the page contacts and every cookie it sets. A maintained mapping table turns domains into companies, so that a request to connect.facebook.net is recorded as Meta.
The disclosed list comes from your privacy policy. The scan fetches the policy the site links to, and a language model reads the text and writes out a structured list of the recipients it names and the categories of recipient it mentions. The model only reads and lists. Code then takes the observed list and subtracts the disclosed list, and each company ends up in one of three groups: named in the policy, covered only by a general category, or not mentioned. A company in the second group is reported as covered generically, because generic wording is a different observation from silence.
The decision is made by code from that evidence. The language model reads the policy and may help word the report, but it never decides that a company is missing, and the report gives no legal conclusion.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. A request to a domain shows that the page contacted that company, not what data was sent or whether the company acts as a processor or as a controller in its own right; that is for you and your legal adviser. Sharing that happens on a server, in an app, or after a step the scan did not take is outside what a browser visit can see. The mapping table only knows the companies on it. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
The browser method is the one EU-01 describes. The UK version of this check, UK-06, runs the same comparison against UK GDPR and the ICO’s guidance.
Why it matters for a company
Both decisions began with a complaint to the regulator, one in Italy and one in Spain. From there the regulator could read the notice and set it against what the company actually did.
In the AEPD’s procedure PS/00080/2023, the agency visited the website on 8 February 2023 and checked its privacy and cookie policies. The complaint describes a consent banner that spoke of “us and our partners” and led to a list of 1,522 vendors. The policy did name tools, among them Google Analytics and Google AdSense. The AEPD’s concern was that the interests of the third parties behind the banner were not set out, so a reader had to open the vendor policies one by one, and that no transfer outside the EU was mentioned. It found an infringement of Article 13 and ordered the company to adapt its policy within a month.
The Garante’s decision of 18 December 2025 shows the same article at group scale. The company’s notice came from a template prepared for every affiliate in the group, some outside the EU. The Garante found that it did not clearly identify the controller, the processors or the recipients, and that the phrase “those who need to know” did not say who could in fact reach the data.
In practice a complaint can start the process, and the notice is the first document read. A notice that is right on the day it is written can fall behind the site within weeks, because the site changes more often than the policy.
Smaller companies and larger companies
The rule has no size threshold. What differs is how the gap appears.
In a small company the privacy policy usually comes from a generator or a template, written once when the site launched. Afterwards someone adds a chat widget, a review plugin, a booking tool or an ad pixel, and the policy is never reopened. The notice is simply older than the site. The Spanish decision shows a limited company with a website was within the AEPD’s reach on Article 13 transparency; its findings concerned purposes, legal basis, third-party interests and transfers, not a recipient list.
In a larger company the problem is the number of owners. Marketing runs the tag manager, product adds an SDK, and a consent platform brings in a vendor list that runs to the thousands. One notice is written for many sites and countries, so it stays general. The Italian decision describes this pattern: a document drafted for the whole group and applied to one company. The guidelines ask for the specific recipients, or for categories that are specific.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Pioneer Hi-Bred Italia Sementi S.r.l.
After a complaint, the Garante inspected the company's vehicle telematics programme. It found that the information notice had been drafted at group level for all affiliates, some outside the EU, and did not clearly name the controller, the processors and the recipients of the data. The notice spoke of access by 'those who need to know', while a supervisor and an administrator, who could be employees of another group company, could reach the data. The fine also covers findings on legitimate interest, processor appointment and worker safeguards. The company is part of a multinational group, which is why it is shown as the larger-company example. This was not a website matter, but it applies the same Article 13 rule on recipients.
Read the Garante (Italy) publication about Pioneer Hi-Bred Italia Sementi S.r.l.
Smaller companies
No penalty against a smaller company that rests on recipient disclosure under Article 13(1)(e) could be confirmed at a regulator's own publication, so none is listed.
How to fix it
The steps below fit most sites. Whether a given tool counts as a processor or a controller is a question for your legal adviser.
- Make the observed list yourself. Open the site in a private window with the browser’s network tab open, load the main pages and write down every third-party domain that appears. Then open the cookie list in your consent tool or in the browser’s storage panel and add any company that sets a cookie. A spreadsheet is enough.
- Name the company behind each domain. Use the vendor’s own site, not a guess. Note what it does for you and what visitor data it receives.
- Choose names or specific categories for each. The Working Party’s default is the name. If you use a category, make it specific: “analytics provider based in the United States” says more than “partners” or “service providers”.
- Put the list in the policy itself. Add a section headed “Who we share data with”, in plain language, with the company or category, what it does and where it is based. Do not rely on a link to a vendor list that runs to thousands of entries as the only place visitors can find out.
- Check the policy matches the transfer and legal basis sections. If a recipient sits outside the EU, Article 13(1)(f) asks the policy to say so.
- Tie the policy to your release process. Add one line to the checklist for adding any tag, plugin or SDK: “Is this company in the privacy policy?” Put a review date on the policy.
- Re-scan. Run a scan again once the policy is live. Companies that were on the observed list only should now show as named.
Questions
What does GDPR Article 13 say about recipients?
A privacy policy has to tell visitors who receives their personal data, either by name or by category. Article 13(1)(e) asks for "the recipients or categories of recipients of the personal data, if any".
The Article 29 Working Party's transparency guidelines say that in practice this will generally mean the named recipients. The rule has the wording.
Does the privacy policy need to name every company?
Not always, but naming is the starting point. The Article 29 Working Party says controllers should give the information that is most meaningful to people, which will generally be the named recipients.
If you use categories instead, they have to be specific. The guidelines ask for the type of recipient, the industry or sector, and where the recipient is. "Partners" on its own is thin.
What is the difference between Article 13 and Article 14?
Article 13 covers data you collect from the person themselves, such as a visitor filling in a form or browsing your site. Article 14 covers data you get from somewhere else.
Both ask for the recipients or categories of recipients in point (e). Peeky looks at what a public website tells its own visitors, which is the Article 13 situation.
Does Article 12 matter for this?
Yes, because it sets how the information is delivered. Article 12(1) asks for it to be concise, transparent, intelligible and easily accessible, in clear and plain language.
The AEPD's Chatwith decision found an Article 13 infringement where the policy did not set out the third-party interests behind a banner that led to a list of more than 1,000 vendors. It did not make a separate finding on recipients.
How does Peeky compare my site with my privacy policy?
Peeky writes down which outside companies your public pages contact, then reads your privacy policy for the companies it names. Each company on the first list is marked named, covered only by a general category, or not mentioned.
Peeky reports that gap as an observation. It never decides that a rule was broken. How a scan works has the full path.
Filed with
The rule
GDPR (Regulation (EU) 2016/679), Arts. 4(8), 4(9), 5(1)(a), 12(1), 13(1)(e), 14(1)(e) and 83(5)(b)
Read the rule (GDPR (Regulation (EU) 2016/679), Arts. 4(8), 4(9), 5(1)(a), 12(1), 13(1)(e), 14(1)(e) and 83(5)(b))A case
Pioneer Hi-Bred Italia Sementi S.r.l.
Read the decision (Pioneer Hi-Bred Italia Sementi S.r.l.)Sources
- Regulation (EU) 2016/679 (GDPR), Official Journal L 119
- Article 29 Working Party, Guidelines on transparency under Regulation 2016/679 (WP260 rev.01), adopted 29 November 2017, last revised 11 April 2018
- Garante, provvedimento of 18 December 2025 [doc. web n. 10213711], Pioneer Hi-Bred Italia Sementi S.r.l.
- AEPD (Spain), resolution in procedure PS/00080/2023 (Chatwith.io Worldwide, S.L.)
Last checked against the source:
For information only. Not legal advice.


