Skip to content

What Must a Privacy Notice Say Under the EU GDPR Rules?

What must a privacy notice say? Compare Articles 13 and 14 GDPR, check every required field, fix timing, and retain practical evidence of delivery.

Two isometric data-origin paths feed a layered notice system whose icon modules pass through a timed delivery gate into an evidence archive.
By AI Priority Map Editorial

What must a privacy notice say when a business collects names, contact details, purchase records or leads from different places? The practical answer begins with one processing activity and one fact: whether the information came directly from the person or from somewhere else.

On 19 March 2026, the EDPB launched its fifth coordinated enforcement action, involving 25 supervisory authorities and addressing transparency and information obligations across sectors through enforcement or fact-finding. Findings were expected in the second half of 2026, so the launch is a reason to inspect notices, not evidence of any result 1,2.

Quick Answer: What must a privacy notice say depends first on data origin. Use Article 13 for data collected from the person and Article 14 for data obtained elsewhere; apply Article 12 to both. State the actual purposes, legal bases, recipients, retention and rights, deliver the information on time, and retain evidence 3.

Last updated: 26 August 2026.

Start with how the data reached the organisation

A privacy notice is information about a specific controller and real processing, not a generic statement of good intentions. Before reviewing wording, select one activity, such as taking online orders, responding to enquiries or contacting people whose details came from a business directory. Define which personal data enters the activity, where it comes from, why it is used and who receives it.

The origin determines the main content branch. Article 13 applies when the organisation obtains personal data from the person. Article 14 applies when the data was not obtained from that person. Article 12 then sets the common standard for how either body of information must be presented 3.

How the data arrivedMain branchImmediate audit question
A person typed it into an order or enquiry formArticle 13Was the information available when collection occurred?
A supplier, public source or another organisation provided itArticle 14Are the data categories and actual source disclosed?
One activity combines both routesTest each stream separatelyCan the reader tell which statements apply to each source?

Consider a business that accepts direct newsletter sign-ups and also receives contact details from an event organiser. The purpose may look similar, but the information duties are not identical. The sign-up stream needs the Article 13 route at collection. The event list needs the Article 14 route, including categories and source, on its own timing. Calling both streams “marketing contacts” does not erase that distinction.

This activity-first method exposes scope errors. A notice may describe customers accurately while saying nothing about purchased contacts, or list a source without explaining a later purpose. The repair should follow the stream that failed rather than add broad text everywhere.

Article 12 governs how every notice is delivered

Article 12 requires the information to be concise, transparent, intelligible and easily accessible, using clear and plain language. It is normally provided in writing, including electronically. Those requirements apply to information supplied under Articles 13 and 14; they are not optional styling preferences 3.

Clarity is tested from the reader's position. A purpose called “business administration” may be short but reveal little. A single dense page may be complete in theory yet difficult to navigate at the moment of collection. Conversely, a friendly headline cannot compensate for missing recipients, retention information or a legal basis.

Delivery evidence matters because an accurate file on an internal drive proves neither accessibility nor timing. For an online form, retain the published notice version, the placement shown beside the form and the date it became active. For a first email to an indirectly sourced contact, retain the approved template and configuration that exposed the Article 14 information. Evidence should connect content, channel and triggering event.

An accessibility test should follow the real delivery route rather than the drafting file. A reviewer should open the page on the device and at the stage where collection or first contact occurs, locate the relevant activity without internal knowledge, identify the controller and understand the purpose, source branch and rights route. If a key fact is visible only after an unrelated choice or the contact route does not work, the delivery has failed operationally. Article 12 also allows standardised icons alongside the information, but any machine-readable icons supplement rather than replace the required clear account 3. The test record should identify the version, route, device or channel, reviewer and outcome so a later audit can reproduce what the person actually encountered.

Use Article 13 when data comes from the person

When personal data is collected directly, Article 13 requires the information at the time it is obtained. A checkout, registration, quotation form or recorded telephone intake therefore needs an accessible route at that collection point 3. A notice published later cannot change when the duty arose.

The field checklist must be completed against the selected activity:

  • the controller's identity and contact details, and those of its representative where applicable;
  • the data protection officer's contact details where applicable;
  • each processing purpose and its legal basis;
  • legitimate interests where that is the legal basis;
  • recipients or categories of recipients;
  • intended transfers and the applicable safeguard or adequacy information;
  • the retention period, or the criteria used to determine it;
  • rights to access, rectification, erasure, restriction, objection and data portability;
  • where processing rests on consent, the right to withdraw it without affecting earlier lawful processing;
  • the right to lodge a complaint with a competent national supervisory authority;
  • whether provision is a statutory or contractual requirement, or necessary to enter a contract, whether the person must provide it, and possible consequences of not doing so; and
  • relevant automated decision-making, including profiling, with meaningful information about the logic, significance and envisaged consequences 3.

Not every field needs a long paragraph. Some may be inapplicable, but that conclusion should come from the activity record. If there is no intended transfer, the reviewer records that finding rather than inventing safeguard language. If retention is controlled by criteria because no single period fits the data set, the notice should explain those criteria accurately enough to be useful.

If the controller later intends further processing for another purpose, it must provide information about that purpose and other relevant information before the further processing. Article 13 contains one exception to the original duty: the person already has the information 3. Broader Article 14 exceptions must not be imported into direct collection.

Use Article 14 when data comes from somewhere else

Article 14 covers personal data not obtained from the person. Its core fields largely mirror Article 13: controller and representative details, data protection officer details where applicable, purposes and legal bases, legitimate interests, recipients, transfers, retention, rights, consent withdrawal, complaint rights and relevant automated decisions 3.

Two additions are essential. The notice must state the categories of personal data concerned and the source from which the data originated, including whether it came from publicly accessible sources. A phrase such as “from third parties” may conceal the information the person needs. The activity record should name the real source class and the actual categories received.

A business contacting someone from an event list should be able to answer which event or provider supplied it; whether the source was public; which fields were received; whether later enrichment added fields; and whether the purpose in the notice matches the purpose now used. The answer belongs in the controlled record and, at an appropriate level, in the notice.

Article 14 requires information about further processing for a new purpose before that further processing begins 3. A later campaign cannot rely silently on wording used for the original indirect activity. The new purpose should be checked against the stored notice version and person-facing route before data is selected.

The practical difference is more than adding “source” to a template. It is maintaining a chain from origin and category to purpose, timing and delivery. That chain allows a reviewer to determine whether Article 14 was applied at all.

Timing is part of the answer

Direct collection has a simple anchor: Article 13 information is supplied when the personal data is obtained 3. The collection point should therefore include the notice route before launch. A footer link discovered after submission may not show what was accessible at the decisive moment.

Indirect collection has three timing outcomes. Article 14 requires information within a reasonable period after obtaining the data and at the latest within one month, considering the circumstances. If data is used to communicate with the person, information must be provided at the latest when the first communication occurs. If disclosure to another recipient is envisaged, it must be provided at the latest when the data is first disclosed 3. The earlier applicable event controls.

Activity eventTiming anchorEvidence to retain
Person submits data directlyAt collectionForm version, notice route and activation date
Indirect data is held without earlier communication or disclosureReasonable period, no later than one monthIntake date and scheduled delivery record
First contact occurs earlierBy that first communicationMessage template, send event and notice version
First disclosure occurs earlierBy that first disclosureDisclosure record and delivery route

A calendar reminder is weak evidence if nobody knows when data entered the system. Intake logging, first-use controls and version ownership make the timing rules reviewable. If a mixed batch contains records obtained on different dates, the procedure should not treat the batch as if everything arrived on the last date.

Exceptions are narrow decision branches

Article 13 does not require information to the extent the person already has it 3. The activity owner should identify exactly which information is already held by the person and preserve the basis for that conclusion. Familiarity with the business does not establish knowledge of a new purpose, recipient or retention rule.

Article 14 has four distinct exception branches. First, the person already has the information. Second, providing it proves impossible or involves disproportionate effort, particularly for specified archiving, research or statistical processing, subject to conditions and appropriate measures; measures include making information publicly available. Third, obtaining or disclosure is expressly laid down by Union or Member State law that provides appropriate measures protecting legitimate interests. Fourth, data must remain confidential under professional secrecy regulated by Union or Member State law, including a statutory secrecy obligation 3.

These are not interchangeable shortcuts. High contact volume does not by itself prove disproportionate effort. A legal-obligation branch needs the applicable law and protective measures, not a generic compliance reference. A confidentiality branch requires the regulated duty. Each conclusion should be recorded per activity, with evidence and safeguards.

Where no exception is evidenced, the organisation follows the ordinary Article 14 route. Where an exception applies only to part of the information or population, the record should preserve that scope rather than suppress the whole notice.

Make one activity match the notice

The fastest useful audit compares operations with person-facing statements. Choose an activity with a clear owner and inspect the live system, intake route, recipients and retention control. Then compare each fact with the notice version currently delivered.

Audit fact for an indirectly sourced campaignCurrent statementDecision and repair owner
Names and work emails arrive from a named event provider“We collect contact information”Hold: add categories and actual source; campaign owner
Purpose is one defined outreach campaign“We use data for business purposes”Hold: state the real purpose and legal basis; privacy owner
A mailing provider receives the selected listOnly internal teams are namedHold: correct recipient information; system owner
Records expire under a documented criterion“We keep data as long as needed”Hold: state the usable criterion; record owner
First email is planned before one monthNo delivery step existsHold: add Article 14 delivery to first-contact control; campaign owner
Rights inbox and complaint route workCurrent route is accuratePass, with test evidence retained

The table separates a true statement that is too vague from a missing statement and from one already supported by evidence. “Hold” means the route should not launch in its current form; it is not a verdict on every other activity.

After repairs, repeat the path as a person would experience it. Open the form or message, locate the information, compare it with the approved record and confirm that the correct version appears. A legal review of a document disconnected from the live route leaves the operational defect untouched.

A layered notice still needs a complete route

Layering can make complex information easier to use. The first layer can identify the controller, purpose, data origin, important consequences and a clear route to remaining detail. The next layer can organise legal bases, recipients, transfers, retention, rights and activity-specific facts. Article 12's standards apply to the whole route 3.

Layers should answer the question when it arises. At a direct form, the person needs to understand why fields are requested and any consequences of not providing required information. At a first indirect communication, source and categories cannot be hidden behind an ambiguous menu. Important facts should not depend on guessing which heading contains them.

Version control prevents a common split: the short layer changes while the detailed layer does not. Give the package one version identifier and owner. A change request should identify every affected layer and delivery point.

Plain language also requires testing. A reviewer who did not draft the text should identify the activity, purpose, source branch, recipients, retention approach and rights route without interpreting internal labels. Any phrase only a system owner understands needs revision.

Keep the evidence current

A notice becomes stale when processing changes, not merely when a review anniversary arrives. Useful triggers include a new purpose, source, data category, recipient, transfer, retention rule, automated decision or collection and communication route. The change process should identify the affected activity and branch before release.

Evidence can remain simple. A controlled folder or register may hold the activity map, approved text, version date, source and field checklist, delivery screenshots or configuration, exception assessment and owner sign-off. No purchased platform is required. What matters is a traceable relationship between the record and the experience presented to people.

The owner should test contact and rights routes. Article 12 requires facilitation of rights and sets response and refusal-information duties 3. A notice naming an unattended mailbox is not operationally current even if its legal wording was once correct.

Before publishing or continuing an activity, apply a short gate:

  • Publish when the origin branch is identified, applicable fields are accurate, timing is controlled, delivery is accessible and supporting version evidence exists.
  • Hold when the source is unknown, a purpose or legal basis is unresolved, a recipient or transfer is missing, an exception lacks evidence, or the live route serves the wrong version.
  • Repair and retest by assigning each failed fact to an owner, updating both record and person-facing route, then walking through the triggering event again.

The strongest answer to “what must a privacy notice say” is not a universal paragraph. It is a complete, clear and timely account of an actual activity, selected through the correct data-origin branch and supported by evidence that the same account reached the person.

Frequently Asked Questions

What must a privacy notice say under the GDPR?
It must describe the controller, purposes, legal bases, recipients, transfers, retention, rights and relevant automated decisions. Direct collection also requires the Article 13 collection details. Indirect collection follows Article 14, adding data categories and sources. The exact checklist depends first on how the data reached the organisation.
What is the difference between Article 13 and Article 14?
Article 13 applies when personal data comes from the person and requires information at collection. Article 14 applies when it comes from another source, adds the categories and source of the data, and has different timing and exception branches. Article 12 governs clear, accessible presentation for both routes.
When must a privacy notice be given?
For direct collection, Article 13 requires information when the data is obtained. For indirect collection, Article 14 requires it within a reasonable period, no later than one month, or earlier at the first communication or first disclosure. The organisation should retain evidence of the applicable event and delivery.
Can one privacy notice cover every processing activity?
One document can provide a route to several activities, but each activity still needs accurate information and the correct Article 13 or Article 14 branch. A broad document that hides missing purposes, sources or recipients does not solve the problem. Map activities first, then test whether every route is complete and accessible.
Can a layered privacy notice meet GDPR requirements?
Yes. A short first layer can show the facts needed at the decision point and point clearly to detail, provided the complete information remains concise, intelligible and easily accessible. Layers should reduce reading friction, not bury legal bases, sources, rights, retention information or important consequences behind vague headings.
How should a business prove that it gave the notice?
Keep the approved notice version, publication date, activity mapping, delivery channel and a record of the event that triggered delivery. Evidence might include a form version, transaction message or campaign configuration. The aim is to show what information was presented, when, to whom and through which controlled route.

Sources

  1. 1.CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPREDPB · 2026
  2. 2.EDPB Work Programme 2026–2027EDPB · 2026
  3. 3.Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex · 2016

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.