
ICO privacy notice: who your site shares data with
At a glance
UK-06HighUK GDPR Art. 13(1)(e), 14(1)(e); Art. 83(5)(b)
Peeky lists the outside companies your public pages contact and compares them with the companies your privacy notice names.
Last checked against the source:
The rule
Article 13(1) of the UK GDPR applies “where personal data relating to a data subject are collected from the data subject”. The controller must, “at the time when personal data are obtained”, provide a list of information, and point (e) of the list is “the recipients or categories of recipients of the personal data, if any”. Article 14(1)(e) uses the same words for personal data that has come from somewhere other than the person, and Article 14(3) sets the timing: within a reasonable period, and at the latest within one month.
The text on legislation.gov.uk is the revised version, which includes the changes made since the end of 2020, most recently by the Data (Use and Access) Act 2025. Point (e) of both articles reads as it does in the EU text, so the same two words, “named” and “categories”, are the ones in play. The EU version of this check, EU-04, covers the GDPR and the EU authorities.
The ICO’s guidance says what it expects to see.
“Say who you share people’s personal data with. This includes anyone that processes the personal data on your behalf, as well all other organisations. You can tell people the names of the organisations or the categories that they fall within. Be as specific as possible if you only tell people the categories of organisations.”
Article 12(1) adds that the controller “shall take appropriate measures to provide any information referred to in Articles 13 and 14”, in a form that is concise, transparent, intelligible and easy to reach, so the way the list is presented counts as well as its content.
On penalties, Article 83(5)(b) of the UK GDPR places “the data subjects’ rights pursuant to Articles 12 to 21” in the upper tier, which carries a maximum of GBP 17.5 million or 4% of worldwide annual turnover, whichever is higher, for an undertaking. Section 157 of the Data Protection Act 2018 sets out the same two tiers. The check’s citation lists Art. 13(1)(e) and 14; the tier is point (b).
What PeekWell checks and how
UK-06 asks one question: does the privacy notice say who the site actually talks to? It compares two lists, one built from what the browser did and one built from what the notice says.
The method is the same as EU-04, and the limits are the same. The scan opens a public page as an ordinary visitor’s browser would and records every distinct third-party domain the page contacts and every cookie it sets. A maintained mapping table turns domains into companies, so a request to connect.facebook.net is recorded as Meta. The scan then fetches the privacy notice the site links to, using the UK wording and sections. A language model reads it and writes out a structured list of the recipients it names and the categories of recipient it mentions.
The comparison is code, not judgement. The model reads and lists; it never decides that a company is missing. Each company on the observed list is put in one of three groups: named in the notice, covered only by a general category, or not mentioned. A category such as “analytics providers” is reported as generic cover, which is a different observation from silence.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. A request to a domain shows that the page contacted that company, not what data was sent or whether the company is a processor or a controller in its own right. Sharing that happens on a server, in an app, or after a step the scan did not take is outside what a browser visit can see. The mapping table only knows the companies on it. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
The clearest published example of how the ICO reads point (e) is the TikTok penalty notice of 4 April 2023, a penalty of GBP 12.7 million that also covers the way TikTok handled children’s data. On 24 September 2026 the ICO announced that TikTok had withdrawn two appeals and accepted the penalty, so the notice is final.
Annex 3 of the notice goes through the three privacy policies TikTok had in force from August 2018 to 28 July 2020. The first named two recipients, Google as its analytics provider and Facebook as its advertising tool, with their addresses. The second and third named none themselves, though the cookie policies they linked to named Google and Facebook. All three relied on descriptors such as “business partners”, “advertising and advertising networks”, “cloud storage providers”, “IT service providers” and “analytics and search engine providers”. The Commissioner’s view was that these categories were “too broad and not adequately explained”, and that “it is unreasonable to assume that a data subject would have had knowledge of all of the various entities with whom TikTok does business”. TikTok argued that Article 13(1)(e) allows either recipients or categories. The ICO’s answer was that TikTok had to give either the named recipients or categories with enough detail that people could “know exactly who held their personal data”.
The notice leaned on the Working Party’s transparency guidelines for its reading, quoting the annex passage that EU-04 sets out, including the sentence that in practice this “will generally be the named recipients”.
Three things follow for a company. The finding was drawn from the text of the policies, which a regulator can read from outside. Naming two companies did not settle it: the ICO looked at the descriptors that sat beside them. And the findings on recipients sat inside a larger notice, so a gap here travels with other findings rather than standing alone.
Smaller companies and larger companies
The rule and the penalty tiers apply to any controller. Section 157 gives the higher maximum as GBP 17.5 million or 4% of turnover for an undertaking, and the fixed sum for others. What differs is how the gap arises. No published ICO penalty against a smaller company on this point could be confirmed, so the smaller-company picture below is a description of how the problem tends to form, not a statement about enforcement.
In a small company the notice usually comes from a template or a generator, written once when the site launched. Afterwards someone adds a chat widget, a booking tool, a review plugin or an ad pixel, and the notice is never reopened. Nobody decides to leave a company out. The notice simply dates from before the tool arrived.
In a larger company the pattern is the one the TikTok annex shows. Several teams add tools, the policy is rewritten for new products, and the notice reaches for umbrella terms such as “partners” and “service providers” to stay accurate as the list changes. The ICO’s answer was that umbrella terms were not enough. A company with an analytics provider, an ad network and a consent platform on every page can have a recipient list that is long and changing, and the notice has to keep up with it.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
TikTok Information Technologies UK Limited and TikTok Inc
The ICO found that none of TikTok's three privacy policies in force between August 2018 and July 2020 gave enough information on recipients. The first named Google and Facebook as its analytics and advertising providers, but all three also used descriptors such as 'business partners', 'advertising networks', 'cloud storage providers' and 'analytics and search engine providers'. The ICO said terms like 'business partners' were too broad, and found an infringement of Article 13(1)(e). The penalty also covers findings on children's consent and on transparency more widely. TikTok withdrew its appeals in September 2026 and the penalty notice is final.
Read the ICO (United Kingdom) publication about TikTok Information Technologies UK Limited and TikTok Inc
Smaller companies
No ICO penalty against a smaller company that rests on recipient disclosure under Article 13(1)(e) or 14(1)(e) could be confirmed at the ICO's own publications, so none is listed.
How to fix it
The steps below fit most sites. Whether a tool counts as a processor or a controller is a question for your legal adviser.
- Make the observed list yourself. Open the site in a private window with the browser’s network tab open, load the main pages without touching the cookie banner, and write down every third-party domain that appears. Add any company that sets a cookie. A spreadsheet is enough.
- Name the company behind each domain. Use the vendor’s own site, not a guess. Note what it does for you and what visitor data it receives.
- Choose names or specific categories. The ICO’s wording is to be “as specific as possible” if you give only categories. “Analytics provider” says more than “partner”. “Business partners” on its own is the kind of descriptor the TikTok notice criticised.
- Put the list in the notice itself. Add a section such as “Who we share data with”, in plain language, giving the company or category and what it does for you. Do not leave visitors to find it in a long vendor list or in a separate document.
- Keep the cookie notice and privacy notice in step. The TikTok notice records that two of the privacy policies pointed to cookie policies that named some companies. If the two documents disagree, readers cannot tell which one is current.
- Tie the notice to your release process. Add one line to the checklist for any new tag, plugin or SDK: “Is this company in the privacy notice?” Put a review date on the notice.
- Re-scan. Run a scan again once the notice is live. Companies that were on the observed list only should now show as named.
Questions
What does the ICO expect a privacy notice to say about who you share data with?
The ICO's guidance says to say who you share people's personal data with, including anyone that processes it on your behalf as well as other organisations. That means the recipients or categories of recipients in Article 13(1)(e).
The ICO's own wording is that you can give the names or the categories, and should be as specific as possible if you give only categories. The rule has the quote.
Does UK GDPR Article 13 ask for names or categories of recipients?
Either, on the text: point (e) reads "the recipients or categories of recipients of the personal data, if any". The ICO's guidance says to choose the option that is most meaningful.
In the TikTok penalty notice the ICO took the view that broad categories such as "business partners" were not enough. It wanted the named recipients, or categories with enough detail that people could tell who held their data.
What are the ICO's privacy notice requirements for a website?
Article 13 sets a list of items to give people when you collect their data, and recipients are point (e) of it. Others include who you are and why you use the data.
Peeky checks only the recipients item, by comparing the companies your pages contact with the companies your notice names. UK-07 looks at the rest of the list.
Is a tool like Google Analytics a recipient?
It can be. The ICO's guidance says the recipients you tell people about include anyone that processes personal data on your behalf, not only other companies you pass data to for their own use.
Whether a given tool is a processor or acts for itself changes the wording of your notice, and your legal adviser can say which applies.
Can a privacy notice template cover the companies my site uses?
Only if you edit it to match what your site actually loads. A template cannot know which analytics, advertising or chat tools you added after it was written.
Peeky lists the companies your pages contact and shows which ones your notice names, which ones it covers only with a general category, and which it does not mention.
Filed with
The rule
UK GDPR, Arts. 12(1), 13(1)(e), 14(1)(e) and 83(5)(b)
Read the rule (UK GDPR, Arts. 12(1), 13(1)(e), 14(1)(e) and 83(5)(b))A case
TikTok Information Technologies UK Limited and TikTok Inc
Read the decision (TikTok Information Technologies UK Limited and TikTok Inc)Sources
- UK GDPR, Article 13 (legislation.gov.uk, revised version)
- UK GDPR, Article 14 (legislation.gov.uk, revised version)
- UK GDPR, Article 83 (legislation.gov.uk, revised version)
- Data Protection Act 2018, section 157 (legislation.gov.uk)
- ICO, What privacy information should we provide?
- ICO, TikTok penalty notice, dated 4 April 2023
- ICO, TikTok penalty notice, Annex 3: Infringements of Article 13
- ICO, TikTok withdraws two appeals in children's privacy action and accepts £12.7m fine, 24 September 2026
- Article 29 Working Party, Guidelines on transparency (WP260 rev.01), Annex, as quoted in the ICO's TikTok notice
Last checked against the source:
For information only. Not legal advice.


