CHAPTER IIIRIGHTS OF THE DATA SUBJECT

Article 13Information to be provided where personal data are collected from the data subject

Official text

(1)Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:

(a)the identity and the contact details of the controller and, where applicable, of the controller’s representative;

(b)the contact details of the data protection officer, where applicable;

(c)the purposes of the processing for which the personal data are intended as well as the legal basis for the processing;

(d)where the processing is based on point (f) of Article 6 (1), the legitimate interests pursued by the controller or by a third party;

(e)the recipients or categories of recipients of the personal data, if any;

(f)where applicable, the fact that the controller intends to transfer personal data to a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means by which to obtain a copy of them or where they have been made available.

(2)In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing:

(a)the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;

(b)the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;

(c)where the processing is based on point (a) of Article 6 (1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;

(d)the right to lodge a complaint with a supervisory authority;

(e)whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and of the possible consequences of failure to provide such data;

(f)the existence of automated decision-making, including profiling, referred to in Article 22 (1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

(3)Where the controller intends to further process the personal data for a purpose other than that for which the personal data were collected, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2.

(4)Paragraphs 1, 2 and 3 shall not apply where and insofar as the data subject already has the information.

Commentary

Article 13 GDPR, Information to be provided where personal data are collected from the data subject

1. Introduction: The Central Role of Article 13 GDPR in Transparency and Fair Processing

Article 13 GDPR establishes one of the most fundamental obligations imposed on controllers under European data protection law: the obligation to inform individuals about the processing of their personal data when such data are collected directly from them.

The provision represents the practical implementation of the transparency principle contained in Article 5(1)(a) GDPR, which requires personal data to be processed “lawfully, fairly and in a transparent manner in relation to the data subject.”

Transparency under the GDPR is not merely a procedural obligation requiring controllers to publish privacy notices. Rather, it is a substantive requirement designed to ensure that individuals understand:

  • who is processing their personal data;

  • why their data are being processed;

  • how long their data will be retained;

  • with whom their data will be shared;

  • what rights they possess;

  • what consequences may arise from the processing; and

  • how they can exercise control over their personal information.

Article 13 therefore creates an obligation of active transparency. The controller cannot remain passive and expect individuals to discover information themselves. The controller must proactively communicate relevant information at the appropriate time and in an understandable manner.

The underlying philosophy of Article 13 is that individuals cannot meaningfully exercise their rights or make informed decisions unless they understand the nature and consequences of processing activities.

For example:

  • A user cannot decide whether to subscribe to a digital platform if they are unaware that their behavioural data will be used for targeted advertising.

  • A customer cannot evaluate the privacy implications of a mobile application if they are not informed that location data will be continuously collected.

  • An employee cannot understand workplace monitoring if they are not informed about surveillance technologies deployed by the employer.

Thus, Article 13 transforms transparency from an abstract principle into a concrete legal obligation.

2. Relationship between Article 13 and Article 12 GDPR

Article 13 must be read together with Article 12 GDPR, which establishes the general rules governing transparency and communication between controllers and data subjects.

While Article 13 identifies what information must be provided, Article 12 explainshow that information must be provided.

Article 12(1) requires information to be provided:

  • in a concise manner;

  • in a transparent manner;

  • in an intelligible form;

  • in an easily accessible form;

  • using clear and plain language.

Therefore, compliance with Article 13 requires more than merely including all legally required information in a privacy policy.

A controller may technically mention:

  • the controller identity;

  • legal bases;

  • retention periods;

  • recipients;

  • rights;

but still violate Article 13 if the information is hidden within lengthy legal documents, written in complex language, or structured in a manner that prevents ordinary users from understanding it.

The former Article 29 Working Party (WP29), whose guidance continues to be relied upon by the European Data Protection Board (EDPB), emphasised that transparency requires information to be presented in a manner that allows the average individual to understand the consequences of processing.

A privacy notice containing hundreds of pages of legal terminology may therefore fail Article 13 even if every required element technically appears somewhere within the document.

3. Relationship with the Accountability Principle

Article 13 also reflects the accountability principle under Article 5(2) GDPR.

The accountability principle requires controllers not only to comply with GDPR obligations but also to demonstrate compliance.

A controller must therefore be able to demonstrate:

  • when information was provided;

  • what information was provided;

  • which version of the privacy notice applied;

  • whether the information was understandable;

  • whether individuals had access to the information before processing began.

Example

an online platform launching a new advertising feature should maintain records showing:

  • the privacy notice version before introduction of the feature;

  • the date users were informed;

  • the communication method used;

  • whether users had an opportunity to understand the new processing.

Transparency obligations are therefore closely linked with governance, documentation and compliance management.

4. Relationship between Article 13 and Article 14 GDPR

Article 13 and Article 14 GDPR establish similar transparency obligations, but they apply in different circumstances.

Article 13 GDPR

Article 13 applies where:

personal data are collected directly from the data subject.

Examples

  • a customer fills an online registration form;
  • an employee provides information during recruitment;
  • a user creates an account;
  • a patient provides medical information to a healthcare provider.

Article 14 GDPR

Article 14 applies where:

personal data are obtained from sources other than the data subject.

Examples

  • data purchased from a data broker;
  • information received from another organisation;
  • publicly available information collected by a controller;
  • information obtained from government databases. The distinction between Article 13 and Article 14 depends primarily on the source of the data, not on whether the individual actively participated in providing the information. The Court of Justice of the European Union (CJEU) confirmed this approach in:

Case C-422/24, AB Storstockholms Lokaltrafik

The Court clarified that the decisive factor for determining whether Article 13 or Article 14 applies is the source from which personal data are obtained.

Therefore, even if the individual is unaware that data collection is occurring, Article 13 applies where the data originates from the data subject.

5. Meaning of “Collected from the Data Subject”

Article 13 applies whenever personal data are collected from the data subject.

The concept of collection is interpreted broadly.

Collection does not require:

  • a conscious act by the individual;

  • an intentional submission of information;

  • direct interaction with a human employee.

Collection includes any situation where personal data come into the possession of the controller through interaction with the data subject.

Examples

include:

(a) Information knowingly provided

The simplest example is where an individual voluntarily provides information.

Examples

  • entering name and email address into an online form;
  • submitting a job application;
  • completing a customer survey;
  • creating a bank account. Here, the individual actively communicates information to the controller.

(b) Observation-based collection

Article 13 also applies where information is collected through observation.

Examples

include:

CCTV monitoring

A shopping centre installing CCTV cameras collects personal data from individuals entering the premises.

Although individuals do not actively provide their images, the data originates from their presence in the monitored area.

The controller must therefore provide Article 13 information through:

  • signs;

  • layered notices;

  • online privacy information.

Location tracking

A mobile application collecting GPS information from a user's device is collecting data directly from the data subject.

The individual may not manually provide location information, but the data is generated through interaction with the person's device.

Wearable devices

Fitness trackers collect:

  • heart rate;

  • movement patterns;

  • sleep information;

  • exercise behaviour.

Although sensors automatically generate this information, it is collected from the individual.

Therefore, Article 13 applies.

Wi-Fi tracking and RFID technology

Retailers may track:

  • customer movements;

  • device identifiers;

  • shopping patterns.

Even where individuals do not knowingly provide information, Article 13 applies because the information is obtained through observation of the individual.

6. Timing Requirement: “At the Time When Personal Data Are Obtained”

Article 13 requires information to be provided:

“at the time when personal data are obtained.”

This timing requirement is fundamental.

The purpose of transparency is preventive.

Individuals must understand processing before or at the beginning of processing, not after their information has already been used.

Providing information after collection may deprive individuals of meaningful choice.

For example:

A mobile application collects contact lists immediately after installation but provides privacy information only after account creation.

This approach is problematic because the user has already disclosed personal information before understanding:

  • why the information is required;

  • whether it is mandatory;

  • who receives it;

  • whether it will be transferred internationally.

7. Ex Ante Transparency

The information required under Article 13 is fundamentally ex ante information.

This means it informs individuals about intended processing before or at the beginning of processing.

The controller communicates its planned processing activities.

For example:

A social media platform may inform users:

“Your profile information will be used to provide personalised recommendations.”

However, actual processing may later differ.

If circumstances change, transparency requires updating individuals.

8. When Information Cannot Be Provided Before Collection

Although Article 13 requires information at the time of collection, practical situations may create difficulties.

For example:

An individual sends an unsolicited email containing personal information to a company.

The company did not initiate collection.

In such circumstances, the controller should provide information:

  • without undue delay;

  • preferably at the first communication with the individual;

  • before further processing occurs.

The principle remains that individuals should not be surprised by processing.

9. Active Provision of Information

Article 13 requires controllers to provide information.

This creates a positive obligation.

The individual should not be required to search for privacy information.

The WP29 Transparency Guidelines state that controllers must take active steps to communicate information.

Acceptable methods include:

  • privacy notices;

  • layered notices;

  • direct links;

  • QR codes;

  • pop-up notifications;

  • written notices.

However, merely placing a privacy policy somewhere on a website without drawing attention to it may be insufficient.

Example

A mobile application collects location information. Unacceptable approach: “By using this application, you agree to our terms and privacy policy.” The user must search through lengthy documents to discover location processing. Better approach: At the moment location permission is requested:

“We collect your location information to provide navigation services. You may withdraw permission at any time through your device settings.”

This approach satisfies transparency requirements.

10. Privacy Notices and Article 13 Compliance

Most controllers satisfy Article 13 through privacy notices.

A privacy notice may exist as:

  • a standalone document;

  • website privacy policy;

  • employee privacy notice;

  • customer information notice;

  • mobile application privacy notice.

However, the privacy notice must not merely reproduce legal language.

It should answer practical questions:

Legal RequirementPractical Question
Controller identityWho has my data?
PurposeWhy is my data being used?
Legal basisWhy is this processing lawful?
RecipientsWho receives my information?
RetentionHow long will my data remain?
RightsWhat control do I have?

11. Identity and Contact Details of Controller, Article 13(1)(a)

The first requirement under Article 13 is disclosure of:

  • identity of the controller; and

  • contact details of the controller.

This information enables individuals to know who determines the purposes and means of processing.

The controller identity should include the full legal identity.

For example:

Insufficient:

“ABC Services processes your data.”

Better:

“ABC Technologies GmbH, registered under German commercial law, located at [address], is the controller responsible for processing your personal data.”

The individual must be able to identify the organisation legally responsible.

12. Contact Details of Controller

Contact information must allow individuals to communicate easily with the controller.

Useful contact details include:

  • postal address;

  • email address;

  • telephone number;

  • privacy contact point.

The purpose is to facilitate:

  • access requests;

  • deletion requests;

  • correction requests;

  • complaints;

  • privacy enquiries.

Providing only a generic contact form may not always satisfy transparency requirements because it may impose unnecessary burdens.

For example:

A controller requiring users to create an account before submitting a privacy request may violate the principle of facilitating rights under Article 12(2).

13. Controller Representative

Article 13(1)(a) also requires disclosure of the representative where applicable.

This refers primarily to Article 27 GDPR.

Controllers outside the European Union may be required to appoint an EU representative where they:

  • offer goods or services to EU individuals; or

  • monitor behaviour of EU individuals.

The representative acts as an accessible contact point for:

  • supervisory authorities;

  • data subjects.

The privacy notice should identify:

  • name of representative;

  • contact details;

  • communication address.

14. Contact Details of Data Protection Officer (Article 13(1)(b))

Where a controller has appointed a Data Protection Officer (DPO), Article 13 requires disclosure of the DPO's contact details.

Importantly, the obligation applies:

  • where appointment is mandatory under Article 37; and

  • where an organisation voluntarily appoints a DPO.

The purpose is to provide individuals with a direct privacy contact point.

The DPO contact information may include:

  • dedicated email address;

  • postal address;

  • telephone number.

However, the controller is not required to disclose the personal name of the DPO.

Example

Appropriate: Data Protection Officer:dpo@company.com Not necessarily required: John Smith, Data Protection Officer. The emphasis is accessibility rather than personal identification.

Article 13 GDPR, Information to be provided where personal data are collected from the data subject

15. Purposes of Processing and Legal Basis, Article 13(1)(c)

Article 13(1)(c) requires the controller to provide information regarding:

  1. the purposes of processing for which personal data are intended; and

  2. the legal basis for such processing.

This requirement represents the practical application of two fundamental GDPR principles:

  • purpose limitation under Article 5(1)(b); and

  • lawfulness, fairness and transparency under Article 5(1)(a).

A controller cannot simply inform individuals that their data will be “processed” or “used for business purposes.” Such broad and vague descriptions fail to satisfy Article 13.

The information must allow the data subject to understand:

  • what processing activity is taking place;

  • why the controller requires the data;

  • how the processing affects the individual;

  • what legal justification permits the processing.

16. Requirement to Specify Processing Purposes

Under Article 5(1)(b) GDPR, personal data must be:

“collected for specified, explicit and legitimate purposes.”

Article 13 operationalises this requirement by requiring controllers to disclose those purposes to individuals.

The purpose description must be sufficiently specific.

A controller cannot rely on generic statements such as:

  • “improving our services”;

  • “business purposes”;

  • “enhancing user experience”;

  • “conducting research”.

Such expressions provide little meaningful information.

Insufficient Purpose Descriptions

The WP29 Transparency Guidelines identify several examples of inadequate purpose statements.

Example 1

“We may use your personal data to develop new services.” This is insufficient because:

  • What services?
  • How will data contribute to development?
  • What type of processing occurs?

Example 2

“We process your data for research purposes.” This does not explain:

  • the nature of research;
  • whether data will be shared;
  • whether research involves profiling or analytics.

Example 3

“We use your data to personalise services.” This fails because the individual cannot understand:

  • what personalisation means;
  • whether it involves tracking;
  • whether it involves behavioural analysis.

17. Adequate Purpose Descriptions

A transparent purpose statement should explain:

  • the category of data used;

  • the activity performed;

  • the expected outcome.

Examples

Example 1

, E-commerce Poor: “We use your information to improve shopping experience.” Better: “We analyse your previous purchases and browsing history to recommend products that may be relevant to your interests.” The second statement informs the individual about:

  • the data used;

  • the processing activity;

  • the consequence.

Example 2

, Website Analytics Poor: “We use cookies for analytics.” Better: “We collect information about pages visited, time spent on the website and interaction patterns to understand how users navigate our website and improve website design.”

A common compliance failure is providing separate lists of:

  • personal data categories;

  • processing purposes;

  • legal bases;

without establishing the relationship between them.

Such an approach does not satisfy Article 13.

The data subject must understand:

Which personal data are used for which purpose under which legal basis?

Example

A healthcare provider processes:

  • name;
  • address;
  • medical information;
  • email address. Possible processing activities:
DataPurposeLegal Basis
Name and addressAppointment managementContract performance
Health dataMedical treatmentArticle 9(2)(h)
Email addressMarketing newsletterConsent

A privacy notice simply stating:

“We process contact data and health data for contractual, legal and marketing purposes”

would be insufficient.

The individual cannot understand:

  • whether health data is used for marketing;

  • whether consent is required;

  • whether objection rights apply.

Article 13 requires controllers to identify the legal basis under Article 6 GDPR.

The controller must specify whether processing relies on:

  • consent (Article 6(1)(a));

  • contract (Article 6(1)(b));

  • legal obligation (Article 6(1)(c));

  • vital interests (Article 6(1)(d));

  • public task (Article 6(1)(e));

  • legitimate interests (Article 6(1)(f)).

The purpose of this requirement is to enable individuals to understand:

  • why processing is lawful;

  • whether they have control rights;

  • whether they can object or withdraw consent.

20. Additional Disclosure for Special Categories of Data

Where processing involves special categories of personal data under Article 9 GDPR, Article 13 requires additional transparency.

Examples

  • health data;
  • biometric data;
  • genetic data;
  • religious beliefs;
  • political opinions. The controller must disclose:
  1. the Article 6 legal basis; and

  2. the applicable Article 9(2) exception.

Example

A hospital processing health information may state: “We process your health data under Article 6(1)(b) GDPR and Article 9(2)(h) GDPR for the provision of healthcare services.”

21. Disclosure for Criminal Data under Article 10 GDPR

Where personal data relating to criminal convictions or offences are processed, transparency should also identify:

  • Article 6 legal basis; and

  • relevant Union or Member State law authorising processing.

Example

An employer conducting mandatory criminal background checks should identify:

  • the legal requirement;
  • the statutory provision requiring verification.

22. Categories of Personal Data

Unlike Article 14 GDPR, Article 13 does not expressly require disclosure of categories of personal data.

The reason is logical:

Where information is collected directly from individuals, they generally know what information they provide.

For example:

A person completing a registration form knows that they provide:

  • name;

  • email;

  • address.

However, modern processing increasingly involves invisible collection.

Therefore, EDPB guidance recommends voluntarily explaining categories of data even in Article 13 notices.

Examples

  • identification data;
  • contact information;
  • transaction data;
  • behavioural data;
  • device information;
  • location information.

This enhances transparency.

23. Legitimate Interests, Article 13(1)(d)

Where processing relies on Article 6(1)(f) GDPR, the controller must disclose:

“the legitimate interests pursued by the controller or by a third party.”

Legitimate interest is unique because it requires a balancing exercise between:

  • controller interests; and

  • individual rights and freedoms.

Therefore, individuals must know what interest is being pursued.

24. CJEU Judgment, Case C-394/23 Mousse

The CJEU emphasised that Article 13(1)(d) requires controllers to directly inform individuals about the legitimate interest relied upon.

The disclosure must occur:

  • at the time of collection; and

  • before processing begins.

A controller cannot later justify processing by claiming legitimate interests if individuals were never informed.

25. Example of Legitimate Interest Disclosure

Insufficient:

“We process your data based on legitimate interests.”

This tells the individual almost nothing.

Better:

“We process your IP address to detect and prevent fraudulent activity, cybersecurity threats and unauthorised access to our systems.”

The individual can evaluate whether:

  • security protection is reasonable;

  • processing is proportionate;

  • objection rights should be exercised.

26. Disclosure of Legitimate Interest Balancing Test

The EDPB has suggested that transparency may require controllers to provide information about the balancing assessment conducted under Article 6(1)(f).

The balancing test normally evaluates:

  1. purpose pursued by controller;

  2. necessity of processing;

  3. impact on individual;

  4. safeguards implemented.

Providing such information strengthens accountability.

For example:

A company processing employee data for monitoring productivity should explain:

  • why monitoring is necessary;

  • what safeguards exist;

  • why employee privacy rights are not disproportionately affected.

27. Recipients or Categories of Recipients, Article 13(1)(e)

Article 13 requires disclosure of:

  • recipients of personal data; or

  • categories of recipients.

A recipient is defined under Article 4(9) GDPR as any person or organisation receiving personal data.

The concept is broad.

Recipients include:

  • processors;

  • service providers;

  • group companies;

  • government authorities;

  • payment providers.

28. Named Recipients versus Categories of Recipients

The GDPR permits disclosure of either:

  • specific recipients; or

  • categories.

However, transparency requires meaningful disclosure.

A statement such as:

“We may share data with third parties”

is inadequate.

The term “third parties” is too vague.

Better:

“We share payment information with payment service providers including Stripe Payments Europe Ltd. We share delivery information with logistics providers responsible for shipment.”

29. When Categories May Be Used

Categories are acceptable where identifying individual recipients is impossible or impractical.

Examples

A public database may not know every future person accessing information. In such cases, categories should still be specific. Poor: “Business partners.” Better: “Cloud hosting providers located within the European Economic Area.”

30. Linking Recipients with Data Categories

Transparency requires explaining:

  • which data are shared;

  • with whom;

  • for what purpose.

Example

Online retailer:

RecipientData SharedPurpose
Courier companyName and addressDelivery
Payment providerPayment detailsTransaction processing
Analytics providerDevice dataWebsite analytics

31. International Transfers, Article 13(1)(f)

Article 13 requires information about transfers of personal data to:

  • third countries outside the EEA;

  • international organisations.

The controller must disclose:

  1. whether transfer occurs;

  2. destination country;

  3. legal mechanism;

  4. safeguards used.

32. Transfer Mechanisms

The GDPR recognises several transfer mechanisms.

(a) Adequacy Decision, Article 45

The European Commission may determine that a country provides adequate protection.

Example

EU, Japan data transfers are supported by an adequacy decision.

(b) Appropriate Safeguards, Article 46

Examples

include:

  • Standard Contractual Clauses (SCCs);
  • Binding Corporate Rules;
  • approved codes of conduct. The controller must inform individuals how they can obtain copies of safeguards.

33. Example of Transfer Disclosure

Insufficient:

“Your information may be transferred internationally.”

Better:

“Your personal data may be transferred to our service provider located in the United States. The transfer is based on Standard Contractual Clauses approved by the European Commission. A copy of these safeguards is available upon request.”

34. Importance of Transfer Transparency after Schrems II

Following the CJEU judgment in:

Schrems II (Case C-311/18)

controllers cannot simply rely on transfer mechanisms mechanically.

They must consider:

  • legal environment of destination country;

  • supplementary safeguards;

  • risks to individuals.

Article 13 transparency therefore plays a critical role by allowing individuals to understand international exposure of their data.

35. Obligation to Provide Further Information Necessary for Fair and Transparent Processing, Article 13(2)

Article 13(2) GDPR introduces additional information requirements that controllers must provide at the time personal data are obtained.

While Article 13(1) focuses primarily on the identity of the controller, purposes, legal basis, recipients and transfers, Article 13(2) focuses on information necessary for individuals to understand:

  • the duration of processing;

  • their rights;

  • their ability to withdraw consent;

  • complaint mechanisms;

  • whether providing data is mandatory;

  • consequences of refusal;

  • automated decision-making risks.

The distinction between Article 13(1) and Article 13(2) is historical rather than substantive.

During legislative negotiations, there was debate regarding whether the information listed in Article 13(2) should be mandatory only where necessary. The final GDPR text made clear that both paragraphs establish binding obligations.

Therefore, controllers must provide all applicable information under both paragraphs.

36. Retention Period, Article 13(2)(a)

Article 13(2)(a) requires controllers to inform data subjects about:

“the period for which the personal data will be stored, or where that is not possible, the criteria used to determine that period.”

This requirement directly implements the storage limitation principle under Article 5(1)(e) GDPR.

The GDPR requires that personal data are not retained:

  • indefinitely;

  • without justification;

  • merely because future use may be possible.

The controller must therefore publicly declare how long information will remain stored.

37. Importance of Retention Transparency

Retention information enables individuals to evaluate:

  • how long they remain exposed to privacy risks;

  • whether storage periods are proportionate;

  • whether deletion rights should be exercised.

For example:

A social media platform collecting photographs should explain:

  • how long photographs are stored;

  • whether deleted photographs are removed immediately;

  • whether backups continue to retain copies.

38. Specific Retention Periods versus Criteria

The GDPR prefers specific retention periods.

Example

“Customer transaction records are retained for seven years to comply with tax obligations.” This is transparent. However, sometimes a specific period cannot reasonably be determined. In such cases, controllers must provide criteria.

Example

“Support communications are retained for six months after closure of the customer request unless required for legal proceedings.”

39. Inadequate Retention Statements

The following statements generally fail Article 13:

“We retain your information as long as necessary.”

The phrase “necessary” is too vague unless the controller explains:

  • necessary for what purpose;

  • determined according to which criteria.

Similarly:

“We retain data according to our internal policies.”

This does not provide meaningful information.

40. Retention Periods Must Reflect Different Categories of Data

A common mistake is providing one universal retention period.

Different information may require different retention periods.

Example

An online retailer may process:

Data TypePurposeRetention
Order recordsTax compliance7 years
Marketing preferencesMarketing communicationUntil withdrawal
Website logsSecurity monitoring6 months
Customer support messagesResolution tracking3 months
A single statement such as:
“We retain customer data for 7 years”
would be misleading.

41. Retention and Accountability

Article 13(2)(a) also forces controllers to internally examine whether their retention practices comply with Article 5(1)(e).

A controller cannot publish a retention period without ensuring:

  • deletion procedures exist;

  • systems implement deletion;

  • backups are managed appropriately;

  • processors follow equivalent rules.

Therefore, transparency acts as a governance mechanism.

42. Information About Data Subject Rights, Article 13(2)(b)

Article 13(2)(b) requires controllers to inform individuals about the existence of their GDPR rights.

The rights include:

  1. Right of access, Article 15;

  2. Right to rectification, Article 16;

  3. Right to erasure, Article 17;

  4. Right to restriction, Article 18;

  5. Right to object, Article 21;

  6. Right to data portability, Article 20.

43. Purpose of Rights Information

The GDPR recognises that rights are meaningless if individuals are unaware that they exist.

Transparency therefore requires controllers to educate individuals about available remedies.

For example:

A customer cannot request deletion of an account if they do not know:

  • deletion rights exist;

  • how to request deletion;

  • limitations applicable to deletion.

44. Mere Listing of Rights Is Not Always Sufficient

A privacy notice stating:

“You have rights under GDPR.”

is inadequate.

The controller should provide meaningful explanation.

Example

Better: “You may request access to the personal data we hold about you. You may also request correction of inaccurate information or deletion where the GDPR permits. To exercise these rights, contactprivacy@example.com.”

45. Right to Object

The right to object under Article 21 receives special protection.

Where processing is based on:

  • legitimate interests under Article 6(1)(f); or

  • direct marketing,

individuals may object.

Article 21(4) requires controllers to specifically bring this right to the attention of individuals.

This information must be:

  • clearly separated;

  • easy to notice;

  • not hidden among other information.

Example

A marketing email should include: “You can unsubscribe from marketing communications at any time.” The right cannot be buried in general terms.

46. Right to Data Portability

Article 13 requires information about portability where applicable.

Data portability allows individuals to:

  • receive their personal data;

  • transfer data to another controller.

However, portability applies only where:

  1. processing is based on consent or contract; and

  2. processing is carried out by automated means.

Controllers should avoid creating confusion by suggesting portability exists where GDPR conditions are not satisfied.

47. Right to Withdraw Consent, Article 13(2)(c)

Where processing relies on consent under:

  • Article 6(1)(a); or

  • Article 9(2)(a),

the controller must inform individuals about:

the right to withdraw consent at any time.

This obligation reflects Article 7(3).

Consent under GDPR requires genuine control.

Therefore:

If consent was obtained through:

  • one click online,

withdrawal should not require:

  • lengthy correspondence;

  • postal letters;

  • contacting customer service.

Example

Acceptable: A newsletter contains: “Unsubscribe” button. Unacceptable: User must:

  1. login;

  2. navigate five pages;

  3. email support;

  4. wait for approval.

49. Withdrawal Does Not Affect Past Processing

Article 13 requires informing individuals that:

withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

Example

A person consents to receiving marketing emails for one year. After six months, they withdraw consent. The previous six months of processing remain lawful. However, future processing must stop.

50. Right to Lodge Complaint, Article 13(2)(d)

Controllers must inform individuals about their right to lodge complaints with a supervisory authority.

This implements Article 77 GDPR.

Individuals may complain to a supervisory authority where they believe GDPR has been violated.

The complaint may generally be submitted to the authority:

  • where the individual resides;

  • where they work;

  • where the alleged infringement occurred.

51. Importance of Complaint Information

Complaint rights represent an external accountability mechanism.

Without this information, individuals may believe that the controller is the only available avenue.

Example

A company refuses a deletion request. The privacy notice should inform the individual that they may complain to the competent supervisory authority.

52. Requirement Regarding Provision of Personal Data, Article 13(2)(e)

Article 13(2)(e) requires controllers to inform individuals whether providing personal data is:

  1. required by law;

  2. required by contract;

  3. necessary to enter into a contract;

  4. optional.

The controller must also explain consequences of failure to provide data.

53. Purpose of Mandatory Data Transparency

This requirement prevents controllers from misleading individuals into believing that unnecessary information is compulsory.

Example

An online shopping website asks: Required:

  • name;
  • delivery address. Optional:
  • birthday;
  • preferred colour;

  • survey responses.

The privacy notice should distinguish between them.

54. Example: Employment Context

A company recruiting employees may request:

  • identity documents;

  • qualification records;

  • criminal background information.

Some information may be legally required.

Other information may merely improve evaluation.

The applicant must understand:

  • which information must be provided;

  • which information is optional;

  • consequences of refusal.

55. Consequences of Failure to Provide Data

Controllers must explain practical consequences.

Examples

Failure to provide delivery address: “We cannot deliver purchased products without your address.” Failure to provide optional marketing preference: “You may continue using our services but will not receive personalised offers.”

56. Automated Decision-Making and Profiling, Article 13(2)(f)

Article 13(2)(f) is one of the most technologically significant provisions of the GDPR.

It requires information about:

  • existence of automated decision-making;

  • profiling;

  • logic involved;

  • significance;

  • consequences.

This provision is increasingly important because modern organisations rely on:

  • artificial intelligence;

  • machine learning;

  • algorithmic scoring;

  • automated recommendations;

  • fraud detection systems.

57. Relationship with Article 22 GDPR

Article 22 GDPR provides protection against certain forms of automated decision-making.

Article 13(2)(f) requires transparency about such systems.

The obligation applies where automated decision-making:

  • produces legal effects; or

  • similarly significantly affects individuals.

Examples

  • automatic rejection of loan applications;
  • employment screening algorithms;
  • insurance pricing decisions;
  • eligibility assessments.

58. Elements of Automated Decision-Making

Automated decision-making generally requires:

(1) A decision

There must be an outcome or determination.

Example

Loan approved or rejected.

(2) Solely automated processing

The decision must occur without meaningful human involvement.

A human merely pressing an approval button does not necessarily constitute meaningful human review.

(3) Significant effect

The decision must substantially affect the individual.

Examples

  • denial of employment;
  • refusal of credit;
  • exclusion from services.

59. Meaningful Information About Logic Involved

Controllers are not required to disclose source code or algorithms.

The purpose is not algorithmic transparency but meaningful understanding.

The individual should understand:

  • what factors influence the decision;

  • how those factors affect outcomes;

  • what role personal data plays.

Example

Insufficient: “Our algorithm calculates your credit score.” Better: “Your credit assessment considers income information, repayment history, outstanding debts and previous account activity. These factors influence whether credit is offered and under what conditions.”

60. CJEU Judgment, C-203/22 Dun & Bradstreet Austria

The CJEU clarified that meaningful information does not require disclosure of a complex mathematical formula.

Simply providing:

  • algorithmic code;

  • technical formula;

  • statistical model;

would not satisfy transparency requirements.

Individuals require understandable explanations regarding:

  • procedure;

  • principles;

  • factors considered;

  • consequences.

61. AI Systems and Article 13 Transparency

Article 13 has become particularly important with the growth of generative AI and automated systems.

AI providers and deployers should consider explaining:

  • whether AI is used;

  • what data categories are analysed;

  • whether decisions are automated;

  • whether humans review outcomes;

  • possible consequences.

Example

A recruitment platform using AI screening should inform applicants: “Applications are initially evaluated using automated tools analysing qualifications, experience and skills. Human recruiters review shortlisted applications before final decisions.”Article 13 GDPR, Information to be provided where personal data are collected from the data subject

62. Information about Further Processing and Change of Purpose - Article 13(3)

Article 13(3) GDPR addresses one of the most important consequences of the principle of purpose limitation.

It provides that where the controller intends to further process personal data:

“for a purpose other than that for which the personal data were collected,”

the controller must provide the data subject with information about:

  1. the new purpose of processing; and

  2. any relevant additional information referred to in Article 13(2).

This obligation must be fulfilled:

“prior to that further processing.”

The provision ensures that individuals are not surprised by unexpected secondary uses of their personal data.

63. Relationship with the Purpose Limitation Principle - Article 5(1)(b)

Article 5(1)(b) GDPR establishes that personal data must be:

  • collected for specified, explicit and legitimate purposes; and

  • not further processed in a manner incompatible with those purposes.

Article 13(3) operationalises this principle by requiring transparency when the controller changes or expands the purpose of processing.

The GDPR therefore recognises that data originally collected for one purpose may later become valuable for another purpose.

However, such secondary use requires transparency.

Example

A retailer collects customer information for: “processing purchases and delivering products.” Later, the retailer decides to use purchase history to train an artificial intelligence recommendation system. The retailer must inform customers before this new processing begins. The privacy notice must explain:

  • the new purpose;
  • the categories of data used;

  • legal basis;

  • retention period;

  • rights available.

64. Compatible and Incompatible Further Processing

Article 13(3) applies even where the new purpose may be considered compatible with the original purpose.

This is important.

A common misunderstanding is that transparency is required only where the secondary purpose is unlawful or incompatible.

That is incorrect.

A new purpose remains a new purpose.

Therefore, even if Article 6(4) GDPR allows further processing based on compatibility, transparency obligations continue.

65. Article 6(4) Compatibility Assessment

Where processing is not based on:

  • consent; or

  • Union or Member State law,

the controller must consider whether the new purpose is compatible with the original purpose.

Article 6(4) identifies factors including:

Example

Using customer purchase history to provide customer support may be closely connected. Using it for political advertising is not.

(b) Context of collection

Controllers must consider:

  • relationship with individual;

  • expectations of individuals;

  • nature of information collected.

(c) Nature of personal data

Special category data requires greater caution.

Example

Health information collected by a hospital cannot easily be reused for commercial advertising.

(d) Consequences of processing

The controller must consider possible effects on individuals.

(e) Safeguards

Examples

  • encryption;
  • pseudonymisation;
  • access controls;
  • limited retention.

66. Timing of Information under Article 13(3)

The controller must inform individuals:

before the further processing begins.

The GDPR does not prescribe a specific number of days or weeks.

However, the timing must allow individuals to:

  • understand the new processing;

  • evaluate consequences;

  • exercise available rights.

The more intrusive the processing, the earlier and more prominent the notification should be.

Example

A company decides to introduce facial recognition technology for security purposes. Providing notice immediately before activation may be insufficient. Affected individuals should receive information sufficiently early to understand:

  • how facial images are processed;
  • retention period;
  • risks;
  • available objections.

67. Content of Further Processing Notice

The controller must provide:

(1) New purpose

Example

“We intend to analyse customer purchase patterns to develop personalised product recommendations.”

(2) Relevant Article 13(2) information

Including:

  • retention period;

  • rights;

  • legal basis;

  • complaint rights;

  • automated processing information where applicable.

68. Article 13(4): Exception Where Data Subject Already Has Information

Article 13(4) provides:

“Paragraphs 1, 2 and 3 shall not apply where and insofar as the data subject already has the information.”

This prevents unnecessary repetition.

The GDPR does not require controllers to repeatedly provide identical information.

69. Interpretation of “Already Has the Information”

The exemption must be interpreted narrowly.

The controller must be able to demonstrate that:

  1. the individual received the information;

  2. the information was complete;

  3. the information was provided in compliance with Article 12;

  4. the information remains accurate and current.

A controller cannot rely on Article 13(4) merely because:

  • a privacy policy existed somewhere;

  • information was technically available;

  • the individual could have found it.

The information must actually have been provided.

70. Accountability Requirement under Article 13(4)

The controller should document:

  • when information was provided;

  • the version of privacy notice used;

  • communication method;

  • evidence of delivery.

Example

An online platform introducing new processing should maintain:

  • previous privacy notice;
  • updated privacy notice;
  • date users were notified;
  • notification method.

71. Partial Information Does Not Satisfy Article 13(4)

If the data subject received only some information, the controller cannot rely completely on the exemption.

Example

A customer received information about:

  • controller identity;
  • purpose; but not:
  • retention period;
  • recipients;
  • rights.

The controller must still provide missing information.

72. Recital 60 - Information Requirements

Recital 60 explains the objective behind Articles 13 and 14.

It states that the controller should provide:

  • fair and transparent processing information;

  • information regarding processing purposes;

  • information necessary to ensure fair processing.

The recital emphasises that transparency enables individuals to understand:

  • how their personal data are processed;

  • what risks exist;

  • what rights they may exercise.

Therefore, Article 13 should not be interpreted as a formal checklist only.

It is a mechanism for empowering individuals.

73. Recital 61 - Timing of Information Provision

Recital 61 explains that information should be provided:

  • when personal data are obtained;

  • or shortly thereafter where Article 14 applies.

The purpose is to prevent individuals from losing control over their information.

The recital recognises that timely information is essential because:

  • individuals may need to make decisions;

  • consent may depend on understanding;

  • objections must be possible before processing occurs.

74. Recital 62 - Exceptions to Information Requirements

Recital 62 recognises that information obligations should not apply where:

  • individuals already possess the information;

  • providing information would require disproportionate effort in specific Article 14 situations.

However, these exceptions must not undermine transparency.

The GDPR adopts a restrictive approach to exceptions.

Transparency remains the rule.

75. EDPB and WP29 Transparency Guidance

The WP29 Transparency Guidelines remain the primary interpretative document for Article 13.

The guidance emphasises several principles.

76. Layered Privacy Notices

One of the most important recommendations is the use of layered notices.

A layered approach provides:

First layer

Short essential information:

  • who processes data;

  • why;

  • key rights.

Second layer

Detailed explanation:

  • legal bases;

  • recipients;

  • retention;

  • transfers.

Third layer

Technical and legal details.

Example

A mobile application may display: First screen: “We collect your location to provide navigation services.” Link: “Learn more about location processing.” Second layer:

Detailed explanation of:

  • storage;

  • sharing;

  • deletion;

  • safeguards.

77. Avoiding Information Overload

Transparency does not mean providing unlimited information.

The GDPR requires information that is:

  • concise;

  • understandable;

  • relevant.

A privacy notice containing excessive unnecessary detail may itself undermine transparency.

This is sometimes described as:

“information fatigue.”

Controllers must balance:

  • completeness; and

  • usability.

78. Article 13 and Dark Patterns

Modern privacy compliance must consider manipulative design practices.

A controller violates transparency where it:

  • hides important information;

  • uses confusing language;

  • makes privacy choices difficult;

  • emphasises acceptance while minimising refusal.

Examples

Unfair: “Continue enjoying services by accepting all cookies.” Hidden: “Manage preferences”

79. Article 13 and Children

Where processing concerns children, transparency requirements become stricter.

Article 12(1) requires information to be understandable.

Therefore, controllers should consider:

  • age;

  • maturity;

  • comprehension level.

Example

A gaming application targeting children should avoid: “We process identifiers for service optimisation.” Instead: “We collect information about how you play so we can improve the game.”

80. Article 13 and Artificial Intelligence Systems

The increasing use of AI makes Article 13 particularly important.

AI systems often involve:

  • complex processing;

  • profiling;

  • inference;

  • automated decisions.

Controllers deploying AI should disclose:

  • whether AI is involved;

  • what data categories are analysed;

  • whether decisions are automated;

  • human oversight mechanisms;

  • consequences for individuals.

81. Example: AI Recruitment Platform

A recruitment platform uses AI to rank candidates.

Article 13 disclosure should explain:

Purpose

“Applications are analysed to identify candidates whose qualifications match job requirements.”

Data

“The system evaluates education, professional experience and skills information.”

Logic

“The system assigns higher rankings based on relevant experience, qualifications and skills matching.”

Consequence

“Candidates with higher rankings may be reviewed earlier by recruiters.”

This enables applicants to understand the system.

82. Enforcement Importance of Article 13

Supervisory authorities have repeatedly treated transparency violations as serious GDPR breaches.

The reason is simple:

Without transparency, individuals cannot exercise:

  • access rights;

  • deletion rights;

  • objection rights;

  • complaint rights.

Article 13 is therefore considered a foundational GDPR obligation.

83. Practical Article 13 Compliance Checklist

A controller collecting personal data directly should ensure:

Controller Information

✓ Legal identity disclosed ✓ Contact details provided ✓ EU representative disclosed where required

DPO Information

✓ DPO contact details provided where applicable

Processing Information

✓ Purposes clearly explained ✓ Legal bases identified ✓ Special category exceptions disclosed where applicable

Legitimate Interests

✓ Specific interests identified ✓ Balancing assessment considered

Sharing

✓ Recipients identified ✓ Categories sufficiently specific ✓ Processor relationships disclosed

International Transfers

✓ Countries identified ✓ Transfer mechanism disclosed ✓ Safeguards explained

Retention

✓ Retention periods provided ✓ Criteria explained where necessary

Rights

✓ Access explained ✓ Rectification explained ✓ Erasure explained ✓ Restriction explained ✓ Objection explained ✓ Portability explained

✓ Withdrawal right disclosed ✓ Withdrawal consequences explained

Complaints

✓ Supervisory authority complaint right disclosed

Mandatory Data

✓ Required fields identified ✓ Consequences of refusal explained

Automated Processing

✓ AI/profiling disclosed ✓ Logic explained ✓ Consequences described

84. Critical Evaluation of Article 13 GDPR

Article 13 represents one of the GDPR's strongest expressions of informational self-determination.

Its greatest strength is that it shifts transparency from a passive publication model to an active communication obligation.

However, practical challenges remain.

Challenge 1: Complexity

Modern processing ecosystems involve:

  • multiple processors;

  • AI systems;

  • global transfers;

  • behavioural analytics.

Explaining such processing simply remains difficult.

Challenge 2: Privacy Notice Fatigue

Many users ignore privacy notices because they are:

  • lengthy;

  • repetitive;

  • legalistic.

The challenge is not merely providing information but making it meaningful.

Challenge 3: AI Opacity

Modern AI systems create difficulties because:

  • models are complex;

  • outcomes may not be predictable;

  • explanations may be difficult.

Article 13 requires organisations to develop new approaches to explainability.