Only where they hold permission on the same report type. Permissions apply per report type, not per individual report.
Users at other organisations can never see your reports. The separation is enforced in the database, not in the interface — see "How is our data kept separate from other customers'?".