UK GDPR: Privacy Notice Requirements (Articles 13-14)
Privacy Notice Requirements [Arts 13-14]
Rule: You must tell people what you’re doing with their data at the point of collection.
Article 13: Data collected directly from the person
Must include:
| Information | Details | Citation |
|---|---|---|
| Who you are | Controller identity, contact details, DPO contact | Art 13(1)(a-b) |
| Why you’re processing | Purposes and legal basis | Art 13(1)(c) |
| Legitimate interests | If relying on LI, explain what they are | Art 13(1)(d) |
| Who receives data | Recipients or categories of recipients | Art 13(1)(e) |
| International transfers | If transferring outside UK, explain safeguards | Art 13(1)(f) |
| Retention period | How long you’ll keep data, or criteria to determine | Art 13(2)(a) |
| Rights | Access, rectification, erasure, portability, objection | Art 13(2)(b-d) |
| Withdrawal | Right to withdraw consent (if applicable) | Art 13(2)(c) |
| Complaints | Right to complain to ICO | Art 13(2)(d) |
| Automated decisions | If using profiling/automated decisions, explain logic | Art 13(2)(f) |
Article 14: Data obtained from other sources
Same requirements as Art 13, plus:
- Categories of data obtained
- Source of the data
- Must provide within 1 month (or at first communication)
Source Text (Article 13)
Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information: (a) the identity and the contact details of the controller and, where applicable, of the controller’s representative; (b) the contact details of the data protection officer, where applicable; (c) the purposes of the processing for which the personal data are intended as well as the legal basis for the processing; (d) where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third party…
In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing: (a) the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period; (b) the existence of the right to request from the controller access to and rectification or erasure of personal data…
Citation
Article 13, UK GDPR | Article 14