> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What Is the “Right to Be Informed” Under the GDPR?
- URL: https://www.thedelatorrereview.com/what-is-the-right-to-be-informed-under-the-gdpr/
- Published: 2019-02-21T20:41:00.000Z
- Updated: 2026-07-14T21:40:06.000Z
- Description: The GDPR's right to be informed requires organizations to be transparent about how they collect, use, and share personal data. This article explains Articles 13 and 14, outlines key disclosure requirements, highlights best practices, and examines the main exceptions to this obligation.
- Author: Lydia
- Tags: Transparency, Right to Be Informed, GDPR, Data Protection Law, EU, Data Mapping, Privacy Rights

> **Key points:** (1) **Data subjects have the right to be informed** about the collection and use of their personal data. This is a fundamental transparency requirement under the GDPR. (2) **Controllers must provide key information**, including the purposes of processing, retention periods, and the recipients or categories of recipients of the personal data. (3) **When data are collected directly from the data subject**, this information must generally be provided at the time of collection, typically through a privacy notice. (4) **When data are obtained from another source**, the information must be provided within a reasonable period and no later than one month after collection. (5) **Limited exceptions apply**, such as where the individual already has the information or providing it would involve a disproportionate effort.(6) **Privacy information must be clear and accessible**—concise, transparent, intelligible, and written in plain language. (7) **Organizations should use effective transparency tools**, such as layered notices, privacy dashboards, and just-in-time notices.(8) **Privacy notices should be kept up to date**, and individuals must be informed before their personal data are used for a new purpose.

### What is the right to be informed, and why is it important?

The right to be informed encompasses some of the most important transparency requirements under the GDPR. It requires controllers to provide individuals with clear, accessible, and concise information about how their personal data are collected, used, shared, stored, and otherwise processed.

Articles 13 and 14 of the GDPR set out these transparency obligations.

[**Article 13**](https://gdpr-info.eu/art-13-gdpr/?ref=thedelatorrereview.com) governs situations in which **personal data are collected directly from the data subject**. It requires controllers to provide, at the time the data are collected, information including:

- the identity and contact details of the controller (and, where applicable, its representative);
- the contact details of the data protection officer, where applicable;
- the purposes of the processing and the applicable legal basis;
- any legitimate interests relied upon under [Article 6](https://gdpr-info.eu/art-6-gdpr/?ref=thedelatorrereview.com)(1)(f);
- the recipients or categories of recipients of the personal data;
- details of international transfers, where applicable;
- the retention period or the criteria used to determine it;
- the individual's rights, including the rights of access, rectification, erasure, restriction, objection, and data portability;
- the right to withdraw consent where processing is based on consent;
- the right to lodge a complaint with a supervisory authority;
- whether providing the personal data is a statutory or contractual requirement and the consequences of failing to provide the data; and
- information about automated decision-making, including profiling, where applicable.

The information should be provided **at the time of collection**.

If the controller later intends to process the personal data for a purpose different from the one originally disclosed, it must provide information about the new purpose before that further processing takes place. These obligations do not apply to the extent that the data subject already has the required information.

[**Article 14**](https://gdpr-info.eu/art-14-gdpr/?ref=thedelatorrereview.com) applies when **personal data have not been obtained directly from the data subject**. In addition to many of the same disclosures required by Article 13, controllers must also inform individuals:

- of the categories of personal data obtained;
- of the source from which the personal data originated, including whether the data came from publicly available sources; and
- of the applicable timeframe for providing the information.

Article 14 generally requires the information to be provided **within a reasonable period after obtaining the personal data** and, in any event, no later than one month. If the data are used to communicate with the individual or are disclosed to another recipient before then, the information must be provided no later than the time of the first communication or the first disclosure, as applicable.

Article 14 also contains **several exceptions**. For example, controllers are not required to provide the information where the data subject already has it, where providing it would prove impossible or involve a disproportionate effort in certain circumstances, where the collection or disclosure is expressly required by Union or Member State law, or where the personal data are subject to a legal duty of confidentiality.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-14--2026-at-02_33_34-PM.png)

When collecting personal data from data subjects, controllers are **not required to provide them with any information that the data subjects already have**.

### Best Practices

Before preparing a privacy notice, controllers should understand what personal data they collect, where it comes from, how it is used, who it is shared with, and how long it is retained. **Information audits or data mapping** exercises are valuable tools for building this understanding and ensuring that privacy notices accurately reflect an organization's data processing activities.

The GDPR requires privacy information to be:

- Concise
- Transparent
- Intelligible
- Easily accessible
- Written in clear and plain language

A **single, lengthy privacy notice is not always the most effective** way to inform individuals. Depending on the context, controllers can combine different techniques to improve transparency, including:

**Layered notices:** Short summaries with links to more detailed information.

- **Privacy dashboards:** Tools that allow individuals to understand and manage how their personal data is used.
- **Just-in-time notices:** Contextual notices presented when personal data are collected.
- **Privacy icons:** Simple visual symbols highlighting key processing activities.
- **Mobile and smart device features:** Pop-ups, voice prompts, or other device-specific notifications.

Whenever possible, information should be delivered through the same channel used to collect the personal data.

When processing children's personal data, controllers must take particular care to present the information in language that children can easily understand.

> **Best practice:** Test privacy notices with real users to confirm that they are easy to find, read, and understand.

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-14--2026-at-02_37_27-PM.png)

Transparency is an ongoing obligation, not a one-time exercise. **Privacy notices should be reviewed regularly** to ensure they remain accurate and complete.

If personal data will be processed for a new purpose, controllers must update the relevant information and inform affected individuals before the new processing begins.

### Special Considerations When Selling and Buying Personal Data

When controllers sell personal data, they must ensure there is a viable lawful basis for doing so and tell individuals who will receive their data by identifying either the specific recipients or the categories of recipients, unless an exception under the GDPR applies. Where individuals have a choice about these disclosures, privacy dashboards can provide an effective way to let them manage who their data is shared with or sold to.

Controllers that obtain personal data from another organization must generally inform the affected individuals, unless an exception under Article 14 of the GDPR applies. This information must be provided within a reasonable period after obtaining the data and, in any event, no later than one month.

If providing the information would be impossible or involve a disproportionate effort, controllers should conduct a DPIA and implement appropriate measures to protect individuals' rights.

### Using Publicly Available Data

The GDPR's transparency obligations also apply when personal data are obtained from publicly accessible sources. Unless an exception applies, controllers must inform individuals within a reasonable period and no later than one month after obtaining the data. This is particularly important where publicly available information is combined from multiple sources or used in ways that individuals would not reasonably expect.

If providing the information would be impossible or involve a disproportionate effort, controllers should conduct a DPIA and implement appropriate measures to protect individuals' rights.

### Transparency When Using Artificial Intelligence

Organizations using AI to process personal data should clearly explain that AI is being used and describe the purposes of the processing. If those purposes evolve over time, controllers should update individuals before using their personal data for any new purpose.

Where AI is used to make solely automated decisions that produce legal or similarly significant effects, individuals must also be informed about:

- The data used in the decision-making process.
- Why that information is relevant.
- The likely consequences of the automated decision.

### Can the Right to Be Informed Be Restricted?

Yes. Although the right to be informed is a fundamental transparency obligation under [Article 23](https://gdpr-info.eu/art-23-gdpr/?ref=thedelatorrereview.com) of the GDPR, Member State law may restrict this right in limited circumstances. 

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/Screenshot-2026-07-04-at-4.45.19---PM-54.png)

## 

##