Article 14 GDPR: Information to be provided where personal data have not been obtained from the data subject
CHAPTER III — RIGHTS OF THE DATA SUBJECT
Article 14 — Information to be provided where personal data have not been obtained from the data subject
Official text
(1)Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information:
(a)the identity and the contact details of the controller and, where applicable, of the controller’s representative;
(b)the contact details of the data protection officer, where applicable;
(c)the purposes of the processing for which the personal data are intended as well as the legal basis for the processing;
(d)the categories of personal data concerned;
(e)the recipients or categories of recipients of the personal data, if any;
(f)where applicable, that the controller intends to transfer personal data to a recipient in a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49 (1), reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available.
(2)In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing in respect of the data subject:
(a)the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;
(b)where the processing is based on point (f) of Article 6 (1), the legitimate interests pursued by the controller or by a third party;
(c)the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject and to object to processing as well as the right to data portability;
(d)where processing is based on point (a) of Article 6 (1) or point (a) of Article 9 (2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
(e)the right to lodge a complaint with a supervisory authority;
(f)from which source the personal data originate, and if applicable, whether it came from publicly accessible sources;
(g)the existence of automated decision-making, including profiling, referred to in Article 22 (1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
(3)The controller shall provide the information referred to in paragraphs 1 and 2:
(a)within a reasonable period after obtaining the personal data, but at the latest within one month, having regard to the specific circumstances in which the personal data are processed;
(b)if the personal data are to be used for communication with the data subject, at the latest at the time of the first communication to that data subject; or
(c)if a disclosure to another recipient is envisaged, at the latest when the personal data are first disclosed.
(4)Where the controller intends to further process the personal data for a purpose other than that for which the personal data were obtained, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2.
(5)Paragraphs 1 to 4 shall not apply where and insofar as:
(a)the data subject already has the information;
(b)the provision of such information proves impossible or would involve a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to the conditions and safeguards referred to in Article 89 (1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing. In such cases the controller shall take appropriate measures to protect the data subject’s rights and freedoms and legitimate interests, including making the information publicly available;
(c)obtaining or disclosure is expressly laid down by Union or Member State law to which the controller is subject and which provides appropriate measures to protect the data subject’s legitimate interests; or
(d)where the personal data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy.
Commentary
1. Introduction: Article 14 GDPR and the Problem of Invisible Data Collection
The General Data Protection Regulation (GDPR) is built upon the fundamental idea that individuals should not lose control over their personal data merely because organisations process information about them. One of the most important mechanisms through which the GDPR protects individual autonomy is transparency. Transparency enables individuals to understandwho is processing their data, why it is being processed, what risks arise from the processing, and how they can exercise their rights.
Article 14 GDPR represents one of the most important expressions of this transparency principle in circumstances where personal data are collected without the direct participation or knowledge of the data subject.
Unlike Article 13 GDPR, which governs situations where personal data are collected directly from the individual, Article 14 applies where personal data are obtained from another source. These situations are commonly described asindirect data collection.
Modern digital ecosystems increasingly rely on indirect collection. Individuals frequently generate extensive digital footprints without directly providing information to the organisation that later uses it. Examples include:
-
a data broker collecting information from public databases and selling profiles to advertisers;
-
a recruitment agency obtaining candidate information from professional networking platforms;
-
a bank obtaining fraud-related information from external databases;
-
an online platform receiving information from another service provider;
-
an artificial intelligence system obtaining training data from publicly accessible sources;
-
an insurance company purchasing information from third-party providers;
-
law enforcement authorities obtaining personal data from other agencies.
In all these situations, the individual may be unaware that their data has entered a new processing environment. Article 14 therefore performs a critical democratic function: it prevents secret processing of personal data and restores visibility to otherwise invisible data flows.
The provision ensures that even when individuals have not directly supplied their information, they are still informed about:
-
the identity of the controller;
-
the purpose and legal basis of processing;
-
the categories of personal data involved;
-
the source from which the information originated;
-
the recipients of the data;
-
their rights under the GDPR;
-
the existence of automated decision-making and profiling.
Therefore, Article 14 is not merely a procedural obligation. It is a substantive guarantee of informational self-determination.
2. Relationship with the Principle of Transparency under Article 5(1)(a) GDPR
Article 14 must be understood within the broader framework of Article 5(1)(a) GDPR, which requires personal data to be processed:
“lawfully, fairly and in a transparent manner in relation to the data subject.”
Transparency is one of the fundamental principles of GDPR compliance. It requires that processing activities should not be hidden from individuals and that controllers should communicate information in a manner that enables meaningful understanding.
Recital 60 GDPR explains that:
“The principles of fair and transparent processing require that the data subject be informed of the existence of the processing operation and its purposes.”
The importance of transparency is even greater in Article 14 situations because the data subject did not participate in the collection process.
When individuals provide their information directly, they normally have some awareness of:
-
what information they are submitting;
-
to whom they are providing it;
-
the circumstances of collection.
Example
when a customer completes an online shopping form, the customer knows that they are providing:
-
name;
-
address;
-
payment details;
-
contact information.
However, where information is obtained indirectly, the individual may have no knowledge that:
-
the information exists;
-
it has been collected;
-
it has been transferred;
-
it is being analysed;
-
it is being used for decision-making.
Consequently, Article 14 imposes stronger transparency requirements because the informational imbalance between the controller and the data subject is greater.
3. Legislative Purpose of Article 14 GDPR
The main objective of Article 14 is to address the risks created by hidden data processing operations.
The GDPR recognises that personal data may be collected from numerous sources, including:
-
public registers;
-
commercial databases;
-
business partners;
-
social media platforms;
-
other controllers;
-
sensors and technological systems;
-
publicly available online content;
-
data brokers.
Without Article 14, organisations could avoid transparency obligations simply by obtaining personal data indirectly.
For example:
A marketing company could avoid informing individuals about advertising profiling by purchasing customer information from another company rather than collecting it directly.
A recruitment company could avoid transparency obligations by collecting candidate profiles from online platforms rather than asking candidates directly.
A financial institution could create risk profiles using external databases without the individual's knowledge.
Article 14 prevents such circumvention.
The provision ensures that the method of collection does not determine whether transparency obligations exist.
Whether personal data are collected directly or indirectly, individuals retain the right to understand the processing.
4. Relationship Between Article 13 and Article 14 GDPR
Articles 13 and 14 GDPR are closely connected and serve the same underlying purpose: ensuring transparency.
However, the difference lies in the source of the personal data.
Article 13 GDPR
Article 13 applies where:
personal data are obtained from the data subject.
Examples
- completing an online registration form;
- opening a bank account;
- subscribing to a newsletter;
- applying for employment;
- providing medical information to a doctor. The data subject is the immediate source of the information.
Article 14 GDPR
Article 14 applies where:
personal data have not been obtained from the data subject.
Examples
- information obtained from another company;
- information collected from public databases;
- information obtained from social media platforms;
- information generated through observation;
- information obtained through sensors or tracking technologies. The individual is not the immediate source.
Although Article 13 and Article 14 contain many identical obligations, Article 14 contains additional requirements because the data subject lacks knowledge about the origin and nature of the information.
The most significant additional requirement is:
Article 14(1)(d): Categories of personal data
and
Article 14(2)(f): Source of personal data
These obligations do not normally exist under Article 13 because the individual already knows what information they have provided.
5. CJEU Interpretation: Broad Scope of Article 14
The Court of Justice of the European Union has confirmed that Article 14 has a broad scope.
A significant judgment is:
CJEU Case C-169/23 Másdi
The Court clarified that Article 14 is defined negatively by reference to Article 13.
The Court observed that:
-
Article 13 covers personal data collected from the data subject;
-
Article 14 covers all situations where personal data are not collected from the data subject.
Therefore, Article 14 is not limited only to data obtained from another person.
It also covers data generated by the controller itself.
This interpretation is important because modern processing frequently involves data creation rather than simple collection.
Examples
include:
Example 1
Behavioural profiles A platform may generate an interest profile based on:
- browsing behaviour;
- search history;
- interaction patterns. The profile itself was not provided by the individual. It was created by the controller.
Therefore, Article 14 principles may become relevant.
Example 2
Artificial intelligence systems An AI system may generate:
- predictions;
- classifications;
- risk scores;
- inferred characteristics.
Although these outputs were not directly supplied by the individual, they relate to that person and may constitute personal data.
Transparency requires explaining such processing.
6. Meaning of “Personal Data Have Not Been Obtained from the Data Subject”
The phrase “have not been obtained from the data subject” should be interpreted broadly.
A data subject is not the source where the controller obtains information from another origin.
This includes:
6.1 Third-party sources
Example
A credit reference agency provides information about an individual's payment history to a bank. The bank must comply with Article 14.
6.2 Publicly accessible sources
Examples
- company registers;
- government databases;
- publicly available websites;
- social networking platforms;
- online publications. The fact that information is publicly available does not remove transparency obligations.
Public availability does not mean individuals have lost their rights.
For example:
A company collecting professional profiles from a social media platform cannot argue:
“The information was public, therefore no information obligation exists.”
The GDPR distinguishes between:
-
public accessibility;
-
informed and fair processing.
6.3 Data brokers
Data brokers represent one of the most important applications of Article 14.
A data broker may collect information from:
-
online activity;
-
purchasing history;
-
public records;
-
loyalty programmes;
-
mobile applications.
It may then create profiles and sell them to other organisations.
The individual may never have interacted with the broker.
Article 14 ensures that the person learns:
-
that the broker exists;
-
what information is held;
-
where it came from;
-
how it is used.
6.4 Information provided by another individual
Article 14 also applies where another person provides information.
Examples
- customer complaints;
- whistleblowing reports;
- references;
- employee recommendations. However, controllers must balance transparency with other interests, particularly confidentiality and protection of third parties.
7. Data Generated by the Controller Itself
A particularly important issue is whether Article 14 applies only when information comes from another person or whether it also applies when the controller creates new data.
The CJEU has confirmed that Article 14 can apply to controller-generated information.
For example:
A bank receives transaction information and creates a fraud risk score.
The score:
-
was not supplied by the customer;
-
was created through analysis.
Nevertheless, it relates to an identifiable person and forms part of processing.
Therefore, transparency obligations may arise.
This approach is consistent with the GDPR's broad definition of personal data.
Article 4(1) GDPR includes information that relates to a person, whether directly provided or inferred.
8. Active Disclosure Requirement: Making Information Available Is Not Enough
A central principle under Article 14 is that controllers must actively provide information.
Simply placing a privacy notice on a website is generally insufficient.
The controller must take reasonable steps to bring the information to the data subject's attention.
This follows from Article 12 GDPR, which requires information to be:
-
concise;
-
transparent;
-
intelligible;
-
easily accessible;
-
written in clear language.
For example:
A recruitment company collecting LinkedIn profiles cannot merely publish an Article 14 privacy notice somewhere on its website.
It should provide the notice:
-
when contacting candidates;
-
through email communication;
-
through platform messages;
-
by another effective method.
The individual must reasonably be expected to receive the information.
9. Practical Importance in Modern Digital Ecosystems
Article 14 has become increasingly important because modern data processing is increasingly characterised by:
-
big data analytics;
-
artificial intelligence;
-
behavioural advertising;
-
data sharing ecosystems;
-
automated decision-making.
Traditional privacy models assumed individuals knew:
“I provide data → organisation uses data.”
Modern reality is different:
“Data is collected everywhere → combined → analysed → inferred → used for decisions.”
Article 14 addresses this new reality by requiring visibility into hidden processing chains
Article 14 GDPR: Information to be provided where personal data have not been obtained from the data subject
10. Information the Controller Must Provide under Article 14(1) GDPR
Article 14(1) GDPR establishes the core information obligations applicable when personal data are obtained indirectly. These requirements largely correspond to Article 13(1), but Article 14 introduces additional transparency obligations because the data subject is not the original source of the information.
Article 14(1) states:
“Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information…”
The wording “shall provide” creates a mandatory obligation. Controllers cannot treat transparency as a voluntary good practice. Failure to comply may constitute a violation of Article 5(1)(a) GDPR (transparency principle) and may attract enforcement action and administrative fines under Article 83 GDPR.
The information must be provided in accordance with Article 12 GDPR, meaning that it must be:
-
concise;
-
transparent;
-
intelligible;
-
easily accessible;
-
written in clear and plain language.
The purpose is not merely to disclose information but to ensure that individuals can actually understand the processing and exercise meaningful control over their personal data.
Article 14(1)(a): Identity and Contact Details of the Controller
Article 14(1)(a) requires the controller to provide:
“the identity and the contact details of the controller and, where applicable, of the controller's representative.”
This requirement performs a fundamental accountability function. A data subject must know who is responsible for processing their personal data.
When data are collected indirectly, identifying the controller becomes even more important because the individual may not have any previous relationship with that organisation.
For example:
A person discovers that a marketing company possesses their personal information. The first question naturally is:
-
Who collected my data?
-
Who is using it?
-
Who is responsible?
Article 14(1)(a) ensures that the individual has a clear answer.
Identity of the Controller
The controller must identify itself clearly.
A vague description such as:
“Our group companies may process your information”
would generally not satisfy the transparency requirement.
The data subject should know the specific legal entity responsible for processing.
For example:
Incorrect:
“ABC Group processes personal information.”
Correct:
“ABC Marketing Solutions Ltd. registered at [address], is the controller responsible for processing your personal data.”
This distinction is particularly important in corporate groups where multiple entities may exist.
Controllers, Joint Controllers and Complex Processing Structures
Modern processing often involves multiple organisations.
For example:
-
a social media platform collects user activity data;
-
an advertising company analyses the information;
-
a marketing agency creates targeted campaigns.
In such situations, transparency requires clarity regarding responsibility.
Where joint controllership exists under Article 26 GDPR, controllers must:
-
transparently determine their respective responsibilities;
-
make essential arrangements available to data subjects.
The data subject should not be forced to determine independently which organisation is responsible.
Representative of Non-EU Controllers
Article 14(1)(a) also requires information about the controller's representative where applicable.
This becomes relevant under Article 27 GDPR.
A controller established outside the European Union may need to appoint a representative within the EU where Article 3(2) GDPR applies.
For example:
A US-based AI company offers services to EU residents and monitors their behaviour.
If Article 27 applies, the company must provide details of its EU representative.
This enables EU individuals and supervisory authorities to communicate effectively with the organisation.
Article 14(1)(b): Contact Details of the Data Protection Officer
Article 14(1)(b) requires disclosure of:
“the contact details of the data protection officer, where applicable.”
The purpose of this obligation is to provide individuals with a direct communication channel regarding data protection concerns.
A Data Protection Officer (DPO) performs an important independent oversight function under Articles 37, 39 GDPR.
Why DPO Transparency Matters
Individuals may need to contact the DPO to:
-
ask questions about processing;
-
exercise their rights;
-
raise concerns;
-
seek clarification about privacy practices.
However, Article 14 does not require disclosure of the DPO's personal information.
The controller should provide professional contact details, such as:
-
email address;
-
postal address;
-
online contact form.
Example
Appropriate: “Data Protection Officer:dpo@company.com” Not necessary: “John Smith, personal mobile number…”
Article 14(1)(c): Purposes of Processing and Legal Basis
Article 14(1)(c) requires:
“the purposes of the processing for which the personal data are intended as well as the legal basis for the processing.”
This is one of the most important transparency obligations.
A person cannot meaningfully evaluate processing unless they know:
-
Why their data is being used; and
-
What legal justification permits that use.
Purpose Specification Requirement
The controller must explain purposes specifically.
A generic statement such as:
“We process your data for business purposes”
is insufficient.
The purpose should enable the individual to understand the actual processing activity.
Examples
Insufficient: “Data may be used to improve services.” More transparent: “Your purchasing history is analysed to identify products that may be relevant to your interests and to provide personalised recommendations.”
Multiple Processing Purposes
Controllers often process indirectly obtained data for multiple purposes.
Example
A data broker collects:
- name;
- age;
- location;
- purchasing behaviour. The data may be used for:
-
targeted advertising;
-
customer segmentation;
-
fraud prevention;
-
market research.
All significant purposes must be disclosed.
Legal Basis Requirement
The controller must also identify the GDPR legal basis.
Possible legal bases include:
Article 6(1)(a): Consent
Example
A company purchases information from a loyalty programme where users consented to data sharing.
Article 6(1)(b): Contract
Example
A payment processor receives customer details necessary to complete transactions.
Article 6(1)(c): Legal obligation
Example
A tax authority obtains salary information from employers.
Article 6(1)(f): Legitimate interests
This is particularly relevant for Article 14 situations.
Examples
- fraud prevention;
- business intelligence;
- direct marketing;
- security monitoring. Where legitimate interests are relied upon, Article 14(2)(b) requires additional disclosure.
Article 14(1)(d): Categories of Personal Data
Article 14(1)(d) requires controllers to inform individuals about:
“the categories of personal data concerned.”
This is one of the most significant differences between Article 13 and Article 14.
The reason is straightforward:
When individuals provide information themselves, they usually know what information they have submitted.
When information is obtained indirectly, they may have no knowledge whatsoever.
Purpose of Category Disclosure
The requirement enables individuals to understand:
-
what type of information is held;
-
the extent of processing;
-
potential risks;
-
whether processing is proportionate.
For example:
A data broker should not simply state:
“We process consumer information.”
This provides no meaningful transparency.
A more appropriate disclosure would identify categories such as:
-
identification information;
-
contact details;
-
demographic information;
-
purchasing history;
-
online identifiers;
-
browsing behaviour;
-
location information.
Meaning of “Categories”
The GDPR does not define “categories of personal data”.
However, the term must be interpreted consistently with:
-
transparency;
-
fairness;
-
intelligibility.
A controller cannot use categories so broad that they become meaningless.
For example:
Insufficient:
“Sensitive information.”
Better:
“Health-related information including medical conditions, treatment history and healthcare provider details.”
Special Categories of Personal Data
The existence of Article 9 special categories does not automatically define categories under Article 14.
Article 14 category disclosure should be sufficiently detailed to explain the actual information processed.
For example:
Simply stating:
“Health data”
may be insufficient.
A healthcare analytics company should explain whether it processes:
-
diagnosis information;
-
medication history;
-
laboratory results;
-
insurance information.
Example
Data Broker Scenario A company purchases information from multiple sources and creates consumer profiles. The Article 14 notice should explain:
Categories collected
-
name;
-
address;
-
email;
-
telephone number;
-
online identifiers;
-
browsing behaviour;
-
purchase preferences;
-
inferred interests.
This enables individuals to assess the impact of processing.
Article 14(1)(e): Recipients or Categories of Recipients
Article 14(1)(e) requires disclosure of:
“the recipients or categories of recipients of the personal data, if any.”
The purpose is to provide visibility into data sharing.
Indirect collection often involves complex data ecosystems where information moves between multiple organisations.
Meaning of Recipient
A recipient includes any person or organisation receiving personal data.
Examples
- processors;
- business partners;
- advertisers;
- government authorities;
- analytics providers. The controller must explain who receives the data.
Specific Recipient vs Category of Recipient
The GDPR permits either:
-
Naming specific recipients; or
-
Describing categories.
However, transparency requires sufficient detail.
Example
Weak: “We share information with third parties.” Strong: “Personal data may be shared with payment service providers, fraud prevention agencies, cloud hosting providers and regulatory authorities.”
Importance in Data Brokerage and AI Systems
Recipient disclosure is especially important where personal data circulate through multiple layers.
Example
A consumer profile may move: Consumer → Data Broker → Advertising Platform → Brand → Analytics Provider Without recipient transparency, individuals cannot understand the real processing environment.
Article 14(1)(f): International Transfers
Article 14(1)(f) requires disclosure where the controller intends to transfer personal data to:
-
a third country; or
-
an international organisation.
The controller must inform the data subject about:
-
Existence of transfer;
-
Destination;
-
Adequacy decision, if applicable;
-
Appropriate safeguards;
-
Means of obtaining a copy.
Importance After Schrems II
International transfer transparency has become increasingly important following:
CJEU Case C-311/18 Schrems II
The judgment emphasised that controllers must ensure adequate protection when transferring personal data outside the EU.
Therefore, Article 14 transparency requires more than simply stating:
“Data may be transferred internationally.”
The controller should explain:
-
destination countries;
-
safeguards used;
-
legal mechanisms relied upon.
Example
A cloud-based AI company obtains customer profiles from external providers and stores information in servers located outside the EU. The Article 14 notice should explain: “Your personal data may be transferred to the United States under approved transfer mechanisms and protected through appropriate safeguards.”
Article 14 GDPR: Information to be provided where personal data have not been obtained from the data subject
11. Additional Information Necessary for Fair and Transparent Processing under Article 14(2) GDPR
While Article 14(1) establishes the basic information requirements, Article 14(2) expands these obligations by requiring controllers to provide additional information necessary to ensure fair and transparent processing.
This paragraph reflects a central philosophy of the GDPR: transparency is not achieved merely by identifying the controller and stating the purpose of processing. Individuals must also understand:
-
how long their information will be retained;
-
what rights they possess;
-
how they can exercise those rights;
-
where the information came from;
-
whether automated decisions affect them.
Article 14(2) therefore transforms transparency from a simple notification requirement into a mechanism for meaningful individual control.
The requirement is closely linked with:
-
Article 5(1)(a) GDPR, lawfulness, fairness and transparency;
-
Article 12 GDPR, transparent communication;
-
Articles 15, 22 GDPR, data subject rights.
Article 14(2)(a): Storage Period or Criteria Used to Determine It
Article 14(2)(a) requires the controller to provide:
“the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period.”
This requirement ensures that individuals understand the lifecycle of their personal data.
A major risk in indirect collection is that individuals may discover that organisations possess their data but have no information about:
-
how long the information will exist;
-
whether outdated information will be deleted;
-
whether unnecessary data will continue to circulate.
Purpose of Retention Transparency
The retention period requirement supports several GDPR principles:
1. Storage limitation principle
Article 5(1)(e) GDPR requires that personal data should not be retained longer than necessary.
Without disclosure of retention practices, individuals cannot evaluate whether the controller respects storage limitation.
2. Accountability principle
Article 5(2) GDPR requires controllers to demonstrate compliance.
A controller should therefore be able to justify:
-
why a retention period exists;
-
how it was calculated;
-
when deletion or anonymisation occurs.
Specific Retention Periods Preferred
Controllers should provide specific periods whenever possible.
Example
Weak: “We retain personal data for as long as necessary.” This statement provides little transparency. Better: “Customer profile information is retained for three years from the last interaction unless a longer retention period is required by law.”
When Criteria May Be Provided Instead
Sometimes controllers cannot determine an exact period.
For example:
A cybersecurity company maintains threat intelligence databases.
The value of certain information may depend on:
-
relevance of the threat;
-
security requirements;
-
legal obligations.
In such situations, the controller may explain criteria such as:
-
legal retention obligations;
-
business necessity;
-
security requirements;
-
limitation periods.
Example
Data Broker A data broker collecting information from public sources should explain: “Consumer profile information is retained until it is no longer relevant for marketing analysis or until deletion is requested, subject to legal obligations.” However, merely using vague terms such as “commercial necessity” would likely fail the transparency requirement.
Article 14(2)(b): Legitimate Interests Pursued by Controller or Third Party
Article 14(2)(b) requires disclosure where processing is based on Article 6(1)(f):
“the legitimate interests pursued by the controller or by a third party.”
This requirement applies because legitimate interests involve a balancing exercise between:
-
the interests of the controller or third party; and
-
the rights and freedoms of the individual.
The data subject must therefore understand what interest justifies processing.
Legitimate Interests Are Not Self-Executing
A controller cannot simply state:
“We process your data based on legitimate interests.”
That does not satisfy Article 14(2)(b).
The controller must explain the actual interest.
Examples
Fraud prevention
Appropriate explanation:
“We process information obtained from fraud prevention databases to detect and prevent fraudulent transactions and protect customers and our business.”
Direct marketing
Appropriate explanation:
“We process publicly available professional information to identify potential business contacts and provide relevant service information.”
Network security
Appropriate explanation:
“We analyse security logs to detect cyber threats and prevent unauthorised access.”
Relationship with Legitimate Interest Assessment (LIA)
Although the GDPR does not require disclosure of the entire Legitimate Interest Assessment, the information provided should allow the individual to understand:
-
what interest is pursued;
-
why processing is considered necessary.
The individual can then challenge the processing through the right to object under Article 21 GDPR.
Article 14(2)(c): Information About Data Subject Rights
Article 14(2)(c) requires controllers to inform individuals about:
-
right of access;
-
right to rectification;
-
right to erasure;
-
right to restriction of processing;
-
right to object;
-
right to data portability.
This requirement connects transparency with practical empowerment.
A privacy notice that explains processing but does not explain remedies provides incomplete transparency.
Importance in Indirect Collection
When data are collected indirectly, individuals may discover processing only after the fact.
Therefore, awareness of rights becomes especially important.
Example
A person discovers through an Article 14 notice that a marketing company has created a behavioural profile. The person may then exercise:
- access rights to understand the profile;
- erasure rights;
- objection rights against marketing;
- restriction rights.
Right of Access
Article 15 GDPR allows individuals to obtain:
-
confirmation whether data are processed;
-
access to personal data;
-
information about processing.
Article 14 transparency complements Article 15.
Article 14 explains:
“We process your data.”
Article 15 allows the individual to ask:
“Show me the actual data.”
Right to Rectification
Indirectly obtained information may often be inaccurate.
Examples
- incorrect address information;
- outdated employment details;
- incorrect consumer classification. Article 16 GDPR enables correction.
Right to Erasure
Individuals may request deletion where applicable.
For example:
A data broker collecting information for marketing purposes may need to delete data after a valid objection.
Right to Restriction
Restriction allows individuals to limit processing temporarily.
Example
A person disputes the accuracy of information obtained from a third-party database. The controller may need to stop using the information until accuracy is verified.
Right to Object
This is particularly important where processing relies on:
-
legitimate interests;
-
direct marketing.
The individual must be informed that they may object.
Right to Data Portability
Where Article 20 applies, individuals may request their data in a structured, commonly used, machine-readable format.
This is especially relevant in platform ecosystems.
Article 14(2)(d): Right to Withdraw Consent
Where processing is based on:
-
Article 6(1)(a) consent; or
-
Article 9(2)(a) explicit consent,
the controller must inform individuals of the right to withdraw consent.
Withdrawal Does Not Affect Previous Processing
The GDPR clarifies:
Withdrawal affects future processing but does not make previous processing unlawful.
Example
A person consents to receive personalised recommendations. After six months, they withdraw consent. The company must stop future recommendation processing based on consent. However, previous lawful processing remains valid.
Importance in Indirect Collection
Consent-based indirect collection creates particular transparency challenges.
Example
A loyalty programme shares information with advertising partners. If the advertising partner relies on consent, individuals must know:
- consent was the legal basis;
- consent may be withdrawn;
- withdrawal does not affect previous processing.
Article 14(2)(e): Right to Lodge a Complaint with a Supervisory Authority
Article 14(2)(e) requires information about:
“the right to lodge a complaint with a supervisory authority.”
This ensures individuals have access to an external enforcement mechanism.
Importance of Supervisory Authorities
Individuals should not be forced to negotiate only with controllers.
They must know that they can approach an independent authority.
Examples
- challenging unlawful profiling;
- complaining about hidden data collection;
- objecting to unfair data brokerage.
Complaint Rights as a Fundamental Guarantee
The right to complain reflects Article 77 GDPR.
It reinforces that privacy rights are enforceable rights, not merely corporate commitments.
Article 14(2)(f): Source of Personal Data
Article 14(2)(f) is one of the most distinctive obligations under Article 14.
It requires disclosure of:
“from which source the personal data originate, and if applicable, whether it came from publicly accessible sources.”
This requirement exists because the individual did not provide the information.
Purpose of Source Transparency
Source disclosure enables individuals to understand:
-
how their information entered the processing system;
-
who shared it;
-
whether the source was legitimate;
-
whether they should exercise rights against another organisation.
Sources May Include:
1. Another organisation
Example
A bank receives credit information from a credit reference agency. The bank should disclose: “Your credit information was obtained from XYZ Credit Bureau.”
2. Public databases
Examples
- company registers;
- court records;
- government databases. The controller must state that the information originated from publicly accessible sources.
3. Technical sources
Modern systems may collect information through:
-
cookies;
-
tracking technologies;
-
sensors;
-
CCTV;
-
Internet-connected devices.
Example
A retail analytics company collects movement data through in-store cameras. The source is: “store CCTV systems.”
CJEU Interpretation: Source Is a Key Criterion
In:
CJEU Case C-422/24 AB Storstockholms Lokaltrafik
the Court emphasised that the source of personal data is central to determining whether Article 13 or Article 14 applies.
The Court explained that Article 14(2)(f) specifically requires disclosure of the source because the data subject was not the origin of the information.
Specific Source vs General Source Information
The GDPR prefers specific information.
Example
Better: “Your information was obtained from LinkedIn.” Rather than: “Your information was obtained from online sources.” However, where multiple sources exist and identifying each source is genuinely impossible, general information may be acceptable. Recital 61 recognises this possibility:
Where various sources have been used, general information should be provided.
Importance for AI Systems and Data Analytics
Source transparency is becoming increasingly important in artificial intelligence.
AI systems often rely on:
-
web-scraped information;
-
datasets obtained from third parties;
-
public repositories.
Individuals affected by AI decisions may need to know:
-
where their information originated;
-
whether it was publicly available;
-
who supplied it.
Article 14 provides an important foundation for AI accountability.
Article 14(2)(g): Automated Decision-Making and Profiling
Article 14(2)(g) requires information about:
-
existence of automated decision-making;
-
profiling under Article 22;
-
meaningful information about the logic involved;
-
significance and consequences of processing.
This requirement is particularly important because automated systems may influence:
-
employment;
-
credit decisions;
-
insurance;
-
advertising;
-
access to services.
Example
Credit Scoring A financial institution receives information from external databases and uses an algorithm to calculate creditworthiness. The individual should know:
- automated scoring exists;
- factors considered;
- consequences of the score.
A statement such as:
“Algorithms are used”
is insufficient.
Meaningful Information About Logic
The controller does not need to reveal trade secrets or source code.
However, it must explain:
-
the main factors;
-
decision criteria;
-
consequences.
Example
“Your credit assessment considers payment history, outstanding debts and financial reliability indicators.”
Importance for Artificial Intelligence
Article 14(2)(g) has increasing significance because AI systems frequently operate using indirectly collected data.
Examples
- facial recognition systems;
- predictive policing tools;
- recruitment algorithms;
- fraud detection systems. Transparency about automated processing is essential to prevent invisible algorithmic decision-making.
Article 14 GDPR: Information to be provided where personal data have not been obtained from the data subject
12. Article 14(3) GDPR: Time at Which Information Must Be Provided
Article 14(3) GDPR establishes when the controller must provide the information required under Article 14(1) and Article 14(2).
Unlike Article 13, where information must generally be provided at the moment of collection, Article 14 recognises that indirect collection creates practical difficulties.
When data are collected from another source, the controller may not immediately communicate with the data subject, may need time to verify the data, or may need to determine the appropriate method of informing individuals.
Therefore, Article 14(3) provides flexibility while ensuring that transparency is not indefinitely postponed.
The provision creates three alternative deadlines:
-
Within a reasonable period after obtaining the personal data, but no later than one month;
-
At the latest at the time of first communication with the data subject;
-
At the latest when personal data are first disclosed to another recipient.
These obligations operate together. The controller must comply with whichever deadline applies first.
Article 14(3)(a): Within a Reasonable Period, but at the Latest Within One Month
Article 14(3)(a) provides the general rule:
“Within a reasonable period after obtaining the personal data, but at the latest within one month.”
This is the default requirement.
The controller cannot delay transparency simply because the information was obtained indirectly.
Meaning of “Reasonable Period”
The GDPR does not define “reasonable period”. It must be assessed considering:
-
nature of the processing;
-
expectations of the data subject;
-
sensitivity of the data;
-
risk involved;
-
urgency of exercising rights.
The controller must consider when the information is necessary for the individual to meaningfully exercise GDPR rights.
Example 1
Recruitment Agency A recruitment company collects candidate information from professional networking platforms. The agency intends to contact candidates about employment opportunities. It cannot wait several months before informing candidates. The candidate should receive Article 14 information:
- before or during first contact;
- or within one month of obtaining the information.
Example 2
Fraud Prevention Database A fraud prevention organisation receives information from financial institutions. The information may be stored for fraud analysis. Even if no immediate communication occurs, individuals must generally receive Article 14 information within one month.
Maximum One-Month Limit
The one-month period is a strict outer limit.
The controller cannot argue:
“We planned to contact the person later, therefore we delayed the notice.”
The one-month deadline remains applicable.
The only exception would be where Article 14(5) exemptions apply.
Article 14(3)(b): Where Data Are Used for Communication with the Data Subject
Article 14(3)(b) provides:
If the personal data are to be used for communication with the data subject, information must be provided at the latest at the time of the first communication.
This provision recognises a common scenario:
The controller obtains information indirectly and then contacts the individual.
Examples
- recruitment messages;
- marketing emails;
- customer outreach;
- invitations;
- surveys.
Example
Direct Marketing A company purchases business contact information from a third-party database. It sends an introductory marketing email. The first email must include the Article 14 notice. It cannot send marketing communications first and provide privacy information later.
Why This Rule Exists
The first communication represents the moment when:
-
the controller enters into a relationship with the individual;
-
the individual becomes aware of the controller.
Transparency must therefore occur immediately.
Otherwise, the controller could exploit the individual's lack of awareness.
Interaction with the One-Month Rule
Article 14(3)(b) does not extend the one-month deadline.
If the controller waits more than one month before contacting the person, Article 14(3)(a) applies.
Example
A recruitment agency obtains a profile on 1 January. It contacts the person on 15 February. The agency cannot argue that information is required only at first communication because:
- one month expired on 1 February. The notice should already have been provided.
Article 14(3)(c): Disclosure to Another Recipient
Article 14(3)(c) provides:
Where disclosure to another recipient is envisaged, information must be provided at the latest when personal data are first disclosed.
This protects individuals from unexpected onward sharing.
Example
Data Sharing A healthcare analytics company obtains patient information from hospitals. It intends to disclose information to a research organisation. Before or at the time of disclosure, the individuals must receive information about:
- the processing;
- recipients;
-
purposes;
-
rights.
Importance in Data Ecosystems
Modern processing often involves multiple actors:
Individual → Organisation A → Organisation B → Organisation C
Article 14(3)(c) prevents individuals from discovering data sharing only after it occurs.
CJEU Interpretation of Article 14(3)
The Court of Justice has recognised that Article 14 provides flexibility because indirect collection makes immediate notification difficult.
In:
CJEU Case C-422/24 AB Storstockholms Lokaltrafik
the Court observed that:
-
Article 13 requires information at collection because the controller directly interacts with the individual;
-
Article 14 allows delayed disclosure because the controller obtained information from another source.
However, this flexibility does not eliminate the obligation.
The controller must still ensure timely transparency.
13. Article 14(4) GDPR: Information Before Further Processing for a New Purpose
Article 14(4) addresses situations where the controller wants to use indirectly obtained data for a purpose different from the original purpose.
It provides:
“Where the controller intends to further process the personal data for a purpose other than that for which the personal data were obtained, the controller shall provide the data subject prior to that further processing with information on that other purpose…”
This provision reflects two important GDPR principles:
-
purpose limitation (Article 5(1)(b));
-
transparency.
Purpose Limitation Principle
Article 5(1)(b) requires personal data to be:
-
collected for specified, explicit and legitimate purposes;
-
not further processed in a manner incompatible with those purposes.
Therefore, a controller cannot silently reuse information for a new purpose.
Example
Healthcare Data A hospital collects patient information for treatment. Later, it wants to use the information for:
- commercial research;
- artificial intelligence development;
- marketing analysis.
Before such further processing, individuals must be informed.
Example
Online Platform A platform collects user information to provide social networking services. Later, it intends to use the information for:
- advertising profiling;
- AI training;
- third-party analytics.
The platform must provide information before the new processing begins.
Relationship with Article 6(4) GDPR
Article 6(4) provides factors for assessing compatibility of further processing.
These include:
-
link between original and new purposes;
-
context of collection;
-
nature of data;
-
consequences for individuals;
-
safeguards.
Article 14(4) ensures transparency even where further processing is permitted.
14. Article 14(5) GDPR: Exceptions to the Information Obligation
Article 14(5) provides circumstances where paragraphs 1, 4 do not apply.
However, these exemptions are exceptions to a fundamental transparency obligation.
Therefore, they must be interpreted narrowly.
Controllers cannot use Article 14(5) as a general escape route.
The four exceptions are:
(a) The data subject already has the information;
(b) Providing information is impossible, involves disproportionate effort, or seriously impairs processing objectives;
(c) Obtaining or disclosure is required by EU or Member State law;
(d) Professional secrecy obligations prevent disclosure.
Article 14(5)(a): Data Subject Already Has the Information
This is the simplest exemption.
Where the individual already possesses the required information, repeating it may be unnecessary.
Example
A customer already received a detailed privacy notice explaining that information would be shared with a payment provider. The payment provider does not necessarily need to repeat identical information if the individual already has it.
Burden of Proof
The controller must be able to demonstrate that:
-
the person actually has the information;
-
the information is sufficiently complete;
-
it remains accurate.
A controller cannot assume knowledge.
Example
Incorrect: “The information was publicly available on our website.” This does not prove the individual knew it. Correct: “The individual previously received the same Article 14 information through a privacy notice dated…”
Article 14(5)(b): Impossibility, Disproportionate Effort, or Serious Impairment
This is the most complex exemption.
It applies where providing information:
-
proves impossible;
-
involves disproportionate effort;
-
would render processing impossible or seriously impair its objectives.
Even where this exemption applies, controllers must implement appropriate safeguards.
14.1 Impossibility
“Impossible” means genuinely impossible, not merely inconvenient or expensive.
The controller must show concrete reasons.
Examples
- no available contact information;
- data obtained from historical archives;
- identity of individuals cannot reasonably be established.
Example
Historical Archive An archive contains millions of historical documents. Many individuals mentioned in the documents cannot be identified or located. Individual notification may genuinely be impossible.
Partial Impossibility
If only part of the information cannot be provided, the controller must still provide what is possible.
Example
The controller cannot identify the exact source but can explain: “Information was obtained from publicly accessible business registers.”
14.2 Disproportionate Effort
This exemption requires balancing.
The controller must compare:
Effort required:
-
financial cost;
-
administrative burden;
-
technical difficulty.
Against:
Impact on individuals:
-
privacy risks;
-
sensitivity of data;
-
expectations;
-
potential harm.
Recital 62 Factors
Recital 62 identifies relevant factors:
-
number of data subjects;
-
age of data;
-
safeguards adopted.
Large Numbers Alone Are Not Enough
A common misunderstanding is:
“We process millions of records, therefore notification is impossible.”
This is incorrect.
Large-scale processing alone does not automatically create disproportionate effort.
Otherwise, large companies would have fewer transparency obligations than small organisations.
Example
Data Broker A data broker holds information about millions of individuals. It cannot simply argue: “We have too many people to inform.” The entire business model depends on transparency.
Research and Statistical Processing
Recital 62 identifies:
-
scientific research;
-
historical research;
-
statistical purposes;
-
public interest archiving
as areas where disproportionate effort may sometimes arise.
However, these purposes are not automatic exemptions.
Controllers must still conduct a balancing exercise.
Article 14(5)(b) Safeguards
Where controllers rely on this exemption, they must adopt measures protecting individuals.
These may include:
-
publishing information publicly;
-
providing general notices;
-
minimising data;
-
pseudonymisation;
-
security measures;
-
conducting DPIAs.
Transparency is reduced, not eliminated.
Article 14 GDPR: Information to be provided where personal data have not been obtained from the data subject
15. Article 14(5)(c) GDPR: Collection or Disclosure Required by Union or Member State Law
Article 14(5)(c) GDPR provides an exemption where:
“obtaining or disclosure of personal data is expressly laid down by Union or Member State law to which the controller is subject and which provides appropriate measures to protect the data subject's legitimate interests.”
This exemption recognises that there are situations where transparency under Article 14 may overlap with, or be replaced by, a comprehensive statutory framework governing the collection or disclosure of personal data.
However, this exemption is carefully limited. The mere existence of a legal basis for processing does not automatically remove the obligation to inform individuals.
The exemption applies only where strict conditions are satisfied.
15.1. Rationale Behind Article 14(5)(c)
The rationale is that where legislation itself already establishes:
-
who may obtain the data;
-
why the data may be obtained;
-
what safeguards apply;
-
how individuals' interests are protected,
a separate Article 14 notification may be unnecessary.
The legislator assumes that the individual's transparency interests are already protected through the legal framework.
However, the exemption cannot become a method for avoiding transparency.
15.2. Conditions for Applying Article 14(5)(c)
Three important requirements must be fulfilled.
Requirement 1: The Collection or Disclosure Must Be Expressly Required by Law
The law must specifically require the obtaining or disclosure of personal data.
A general permission is insufficient.
For example:
Insufficient:
“The controller may process personal data where necessary.”
This merely provides a legal basis.
It does not create a mandatory obligation.
Sufficient:
“Employers shall provide salary information of employees to the tax authority.”
Here, the law expressly requires disclosure.
Requirement 2: The Controller Must Be Subject to That Law
The controller must demonstrate that the legal obligation actually applies to it.
A company cannot rely on Article 14(5)(c) by merely pointing to a law that regulates another organisation.
Example
A financial institution cannot argue: “Banking law permits disclosure.” It must show that the law specifically requires the institution itself to disclose the information.
Requirement 3: The Law Must Provide Appropriate Measures Protecting Legitimate Interests
The legislation must contain safeguards comparable to transparency protection.
Examples
of safeguards include:
- limits on data use;
- restricted access;
- security requirements;
- oversight mechanisms;
- complaint mechanisms;
- retention limitations. Without safeguards, Article 14(5)(c) cannot apply.
CJEU Interpretation: Másdi Case
In:
CJEU Case C-169/23 Másdi
the Court examined the relationship between statutory obligations and Article 14.
The Court explained that the purpose of Article 14(5)(c) is to avoid imposing additional information obligations where another legal provision already creates a sufficiently comprehensive transparency framework.
The Court emphasised that:
-
the legal obligation must be binding;
-
individuals must have sufficient knowledge of the rules and purposes of processing;
-
the law must adequately protect legitimate interests.
Therefore, Article 14(5)(c) is not triggered merely because processing is lawful.
Example
Tax Authorities An employer is legally required to submit employee salary information to a tax authority. The tax authority obtains personal data indirectly. Normally, Article 14 would apply. However, if national law:
- expressly requires reporting;
-
identifies the authority;
-
explains the purpose;
-
establishes safeguards;
the tax authority may rely on Article 14(5)(c).
Example
Anti-Money Laundering Obligations Banks may be required under anti-money laundering laws to collect and disclose information about customers. Where legislation:
- mandates reporting;
- establishes confidentiality;
- limits use;
- creates oversight,
Article 14(5)(c) may become relevant.
Article 14(5)(c) and Article 23 GDPR Restrictions
Article 23 GDPR permits Member States and the EU legislature to restrict certain GDPR rights through legislation where necessary and proportionate.
Restrictions may protect:
-
national security;
-
defence;
-
public security;
-
criminal investigations;
-
regulatory functions.
However, Article 23 restrictions require:
-
clear legislative basis;
-
respect for fundamental rights;
-
proportionality.
A controller cannot create its own transparency exception.
16. Article 14(5)(d) GDPR: Professional Secrecy Obligations
Article 14(5)(d) provides an exemption where:
“the personal data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy.”
This exemption protects relationships where confidentiality is a fundamental legal requirement.
Common examples include:
-
healthcare professionals;
-
lawyers;
-
financial professionals;
-
certain regulatory bodies.
16.1. Purpose of Professional Secrecy Exemption
Certain relationships depend on confidentiality.
If a controller were forced to disclose information about processing in every circumstance, it could undermine:
-
legal privilege;
-
medical confidentiality;
-
investigative confidentiality;
-
professional trust.
Therefore, Article 14(5)(d) creates a narrow exception.
16.2. Conditions for Application
The controller must establish:
-
A professional secrecy obligation exists;
-
The obligation is established by EU or Member State law;
-
The obligation requires confidentiality of the personal data;
-
Disclosure under Article 14 would conflict with that secrecy obligation.
Example
Medical Confidentiality A physician receives information from another healthcare provider regarding a patient. Medical confidentiality rules may restrict disclosure. The doctor must demonstrate:
- the secrecy obligation;
- the legal basis;
- why transparency would violate confidentiality.
Example
Legal Professional Privilege A lawyer may receive personal information concerning:
- litigation;
- investigations;
- legal advice. Disclosure of processing information may reveal confidential legal strategy.
Professional secrecy may therefore apply.
Narrow Interpretation Required
Controllers cannot simply label information as “confidential”.
Confidentiality must arise from a legally recognised obligation.
Commercial sensitivity alone is insufficient.
Example
A company cannot say: “Our business information is confidential, therefore Article 14 does not apply.” That would undermine the GDPR.
17. Interaction Between Article 14 and Article 12 GDPR
Article 14 cannot be read separately from Article 12.
Article 12 establishes the method by which Article 14 information must be communicated.
The information must be:
Concise
Individuals should not receive overwhelming legal documents that hide important information.
Transparent
The notice should clearly explain:
-
what is happening;
-
why it is happening;
-
who is involved.
Intelligible
The average person should understand the processing.
Easily Accessible
Individuals should not have to search extensively for information.
Clear and Plain Language
Especially important where processing affects vulnerable individuals.
Layered Privacy Notices
The EDPB and WP29 recognise layered approaches as effective transparency tools.
A layered notice may contain:
First layer
Simple essential information:
-
who processes data;
-
why;
-
major risks;
-
key rights.
Second layer
Detailed information:
-
categories;
-
recipients;
-
retention;
-
legal basis;
-
safeguards.
This approach is particularly useful for Article 14 because indirect collection often involves complex processing.
18. Article 14 Compliance Challenges in Modern Technology
Article 14 has become increasingly significant because modern technologies frequently rely on indirect collection.
18.1. Artificial Intelligence Systems
AI systems create significant Article 14 challenges.
AI systems may obtain personal data from:
-
web scraping;
-
public databases;
-
third-party datasets;
-
user-generated content.
Individuals may not know:
-
their data was collected;
-
their information contributed to model training;
-
their information influenced outputs.
Example
AI Recruitment System A company uses an AI tool trained on publicly available professional profiles. The system analyses candidates and ranks applicants. Article 14 transparency requires information about:
- source of data;
- categories collected;
-
automated decision-making;
-
consequences.
18.2. Facial Recognition Systems
Facial recognition often involves indirect collection.
A person walking through a public area may not actively provide biometric information.
Article 14 issues include:
-
source of biometric data;
-
purpose;
-
retention;
-
automated identification.
Because biometric data are special category data under Article 9, transparency obligations become particularly important.
18.3. CCTV and Surveillance
CCTV is a classic Article 14 situation.
Individuals usually do not provide images directly.
Controllers must provide information regarding:
-
identity;
-
purpose;
-
legal basis;
-
retention period;
-
rights.
This is why CCTV notices are often placed at entrances.
18.4. Data Brokers
Data brokerage represents perhaps the strongest justification for Article 14.
A data broker may create detailed profiles using:
-
shopping behaviour;
-
location information;
-
online activity;
-
demographic information.
The individual may have no relationship with the broker.
Article 14 ensures that the invisible economy of personal data becomes visible.
19. Enforcement and Accountability Issues
Article 14 obligations are subject to the GDPR accountability principle.
Under Article 5(2), controllers must demonstrate compliance.
This means controllers should maintain evidence showing:
-
when Article 14 notices were issued;
-
what information was provided;
-
which sources were used;
-
how exemptions were assessed.
Documentation Should Include
Data source inventory
Controllers should know:
-
where data originate;
-
which systems receive them;
-
whether sources are public or private.
Privacy notice management
Controllers should maintain:
-
version history;
-
dates of publication;
-
affected processing activities.
Exemption assessments
Where Article 14(5) is relied upon, controllers should document:
-
why the exemption applies;
-
balancing exercises;
-
safeguards implemented.
20. Critical Evaluation of Article 14 GDPR
Article 14 is one of the GDPR's most important transparency provisions, but it also faces practical challenges.
Strength 1: Addresses Hidden Data Collection
The greatest achievement of Article 14 is that it prevents organisations from avoiding transparency through indirect collection.
Without Article 14:
“We did not ask you, therefore we do not need to tell you”
could become a widespread loophole.
Strength 2: Supports Individual Control
Article 14 allows individuals to:
-
challenge inaccurate data;
-
object to profiling;
-
request deletion;
-
understand data flows.
Strength 3: Supports Algorithmic Accountability
In the AI era, Article 14 provides a foundation for explaining:
-
where data came from;
-
how systems use it;
-
what decisions are produced.
Weakness 1: Information Overload
One challenge is that Article 14 notices can become extremely complex.
Individuals may technically receive information but practically fail to understand it.
Therefore, compliance requires not only disclosure but effective communication.
Weakness 2: Source Transparency Difficulties
Modern data ecosystems involve thousands of sources.
Controllers may struggle to track:
-
where each data point originated;
-
how it moved through systems.
This highlights the importance of:
-
data lineage systems;
-
privacy engineering;
-
governance frameworks.
Weakness 3: Broad Exceptions
The “disproportionate effort” exception creates uncertainty.
If interpreted too broadly, organisations could avoid transparency obligations.
Therefore, supervisory authorities and courts must continue ensuring narrow interpretation.