7.5 Privacy Notices & Transparency Obligations
Key Takeaways
- Indicator VI.A.1 requires privacy notices and policies to be transparent and to clearly articulate data subject rights — notice quality is a tested competency, not a legal drafting afterthought.
- GDPR Article 12 sets the manner: concise, transparent, intelligible, easily accessible, in clear and plain language, and free of charge.
- Articles 13 and 14 set the content, and they differ on timing: Article 13 applies at the point of collection from the individual, Article 14 within a reasonable period and at the latest one month when data came from elsewhere.
- Layered notices with just-in-time disclosures at the point of collection outperform a single long document for both comprehension and compliance.
- A notice is a living control: material changes require proactive communication and, where the change alters the processing the individual agreed to, a new lawful basis rather than a silent republish.
The Rights Nobody Can Exercise
Domain VI's first indicator is easy to skim past: ensure privacy notices and policies are transparent and clearly articulate data subject rights. It sits before the indicators about handling requests, and the ordering is deliberate. A right an individual cannot discover is a right they cannot exercise, so notice quality is the upstream control on the entire rights workflow.
Article 12 governs the manner
GDPR Article 12(1) requires information to be provided in a form that is concise, transparent, intelligible and easily accessible, using clear and plain language — in particular for information addressed to a child. Article 12(5) makes it free of charge.
That standard has operational teeth. A notice that is technically complete but written at postgraduate reading level, buried four clicks deep, or presented only in a language much of the audience does not read, fails Article 12 regardless of its content. Regulators have repeatedly criticised notices for being accurate but unreadable.
Articles 13 and 14 govern the content
| Required information | Art. 13 (from the individual) | Art. 14 (from elsewhere) |
|---|---|---|
| Controller identity and contact details; DPO contact | Yes | Yes |
| Purposes and lawful basis (and the legitimate interests, if relied on) | Yes | Yes |
| Recipients or categories of recipients | Yes | Yes |
| Transfers outside the EEA and the safeguard relied on | Yes | Yes |
| Retention period or the criteria used to set it | Yes | Yes |
| The rights available, including withdrawal of consent and complaint to a supervisory authority | Yes | Yes |
| Whether provision is statutory/contractual and the consequences of not providing | Yes | — |
| Categories of personal data concerned | — | Yes |
| Source of the data, and whether from publicly accessible sources | — | Yes |
| Existence of automated decision-making, with meaningful information about the logic and consequences | Yes | Yes |
Timing is the difference candidates miss. Article 13 information must be given at the time the data is obtained. Article 14 information must be given within a reasonable period and at the latest within one month, or at the first communication with the individual if earlier, or when the data is first disclosed to another recipient if earlier. Article 14(5) provides narrow exceptions, including where provision would involve disproportionate effort — a genuinely narrow exception that requires compensating measures such as publishing the information, not a general excuse.
Layered and just-in-time design
One long document serves lawyers; layers serve people.
- Layer one — just-in-time. A short, contextual disclosure at the moment of collection: why this field, what happens next, a link onward. The most effective transparency control there is.
- Layer two — summary. A short-form notice with the headline purposes, recipients, retention and rights, ideally with icons or a table.
- Layer three — full notice. The complete Article 13/14 content, version-controlled and dated.
Supporting devices matter too: a privacy dashboard where individuals see and change their choices, a rights portal with a clear route to each right, and a change log showing what was updated and when.
The inverse discipline is avoiding dark patterns — pre-ticked boxes, an "Accept all" button with the reject option hidden a layer down, confusing double negatives, or manufactured urgency. Regulators on both sides of the Atlantic now treat these as invalidating consent, and several US state laws define such interference explicitly.
The US notice layer
Under the CCPA as amended, a business must give a notice at collection at or before the point of collection listing the categories collected, the purposes, whether the data is sold or shared, and the retention period; maintain a privacy policy updated at least every 12 months; provide a notice of right to opt-out of sale or sharing; and give a notice of financial incentive where it offers something in exchange for data. Other state laws follow a similar shape with local variation, and the practical consequence is that a single global notice usually needs jurisdiction-specific sections rather than a lowest-common-denominator paragraph.
Keeping the notice true
The notice is the artifact most likely to fall out of sync with reality, because it is drafted once and processing changes weekly. A defensible programme ties notice review to the same triggers as the data inventory — new system, new purpose, new recipient, new jurisdiction, M&A — plus an annual review with a version log. For material changes, republishing quietly is not enough: notify affected individuals proactively, and if the change alters processing the individual previously agreed to, obtain a new lawful basis rather than relying on a footnote.
Worked scenario
A company buys a marketing list from a data broker and begins emailing the contacts. No notice was given, because the individuals never interacted with the company. This is exactly the Article 14 case: the information must be provided within a reasonable period and at the latest within one month, or at the first communication — which means the first marketing email itself must carry it, including the source of the data and the categories of personal data held. Skipping it converts a marketing campaign into a transparency violation on every send.
A company obtains personal data from a third-party data broker rather than from individuals directly. When must it provide privacy information, and what extra content is required?
A privacy notice is legally complete but written in dense legal prose, published as a single 6,000-word page four clicks from the homepage. Which obligation is most directly at risk?