When does a GDPR notice need content?
Use when the collects personal data from the person. The information must be provided at the time the personal data is obtained.
Build privacy notices around the actual Article 12, 13 and 14 fields: who controls the processing, why data is used, legal basis, recipients, transfers, retention, rights, and data sources.
Use one notice record per processing purpose so legal, product, marketing, HR, support, procurement, and data-governance teams keep the public notice aligned with the data flow.
Structured answer sets in this page tree.
Cited legal and guidance references.
A GDPR transparency notice should tell a person who the is, what personal data is processed, why and on which lawful basis, who receives it, how long it is kept, whether it is transferred internationally, and how to exercise relevant rights or complain. applies when personal data is collected from the person. applies when it is obtained elsewhere or generated from data not collected directly from that person.
Article 12 sets the form of the notice. The must provide and 14 information in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. Information addressed specifically to a child must be written so the child can understand it.
Keep the notice separate from unrelated terms, support articles, and sales copy. The person should be able to find the identity, purpose, lawful basis, retention position, recipients, transfer information, and rights without searching through unrelated material.
For forms, account sign-up, checkout, job applications, support chats, newsletter sign-ups, events, identifiers collected from a person's device, and other direct collection points, information is due at the time the personal data is obtained.
The notice should describe the processing purpose by purpose. If the same person gives data for account creation, billing, fraud prevention, analytics, marketing, and support, each purpose needs its own lawful basis, recipient position, retention position, and rights context.
applies when the did not collect the personal data from the person. Common examples include data bought from a broker, received from a partner or group company, collected from public sources, supplied by an employer, customer, referrer, or fraud-prevention service, or inferred or generated from data obtained elsewhere. In its 28 November 2024 judgment in C-169/23, the Court of Justice confirmed that Article 14 also covers data the controller generates from data not collected directly from the person.
The notice overlaps with , but it adds the categories of personal data concerned and the source from which the data originates, including whether it came from publicly accessible sources.
Treat one month as the latest deadline. The must choose a reasonable delivery time for the circumstances and give the notice sooner if it communicates with the person or first discloses the data before then.
(5) has limited exceptions. The must identify the exact exception, document why it applies, and meet any safeguard conditions. A difficult or expensive notification exercise does not by itself establish disproportionate effort.
Do not describe sharing only with a broad partner label. Articles 13 and 14 require recipients or categories of recipients, if any, and separate information where the intends to transfer personal data to a third country or international organisation.
For international transfers, the notice should say whether the transfer relies on an adequacy decision or on another safeguard. Where Article 46, Article 47, or the second subparagraph of Article 49(1) is relevant, the notice must refer to the safeguards and say how to obtain a copy or where they are available.
Maintain a matching evidence record for each processing purpose. The public notice should not state a basis, retention period, recipient list, or transfer safeguard that the record of processing, contract file, data map, or product implementation cannot support.
Review the notice when a purpose changes, a new recipient receives data, a new data source is added, data moves to a third country, retention rules change, or is introduced. Articles 13(3) and 14(4) require the to give information about a new purpose, and the relevant additional information, before further processing begins.
Use when the collects personal data from the person. The information must be provided at the time the personal data is obtained.
Use when the did not collect the personal data directly from the person. This includes data received from someone else and data the controller generates from data obtained elsewhere. The notice must include the categories of personal data and the source, including whether it was publicly accessible.
It should state the period for which the personal data will be stored. If a fixed period is not possible, it should state the criteria used to determine that period.
It should say whether personal data is transferred to a third country or international organisation and, where applicable, whether there is an adequacy decision or which safeguard applies and how the person can obtain a copy or find it.
Not for that reason alone. The must satisfy a specific (5) exception. If it relies on impossibility, disproportionate effort, or serious impairment under Article 14(5)(b), it must document the assessment and take appropriate measures to protect people, including making the information publicly available.
Yes. A can put the most important information at the collection point and link directly to complete details. The must still provide every applicable or 14 item in a concise, clear, accessible, and easy-to-find form.
Sorena can help map each notice section to the underlying purpose, lawful basis, recipient, transfer safeguard, retention rule, rights workflow, and data source.
Ask questions tied to cited sources about GDPR notice content, Article 13 direct collection, Article 14 source disclosures, transfers, retention, and data subject rights.
Review your GDPR transparency notices against processing purposes, data sources, recipients, transfers, retention rules, and rights workflows.
"Standard contractual clauses"
"the purposes of the processing"