Concise, Transparent, Intelligible Form
This is a standard for how organisations must present privacy information and communications to individuals. It generally requires that the information be short and to the point, open and honest, easy to understand, and simple to find, using clear and plain language. The goal is to make sure people can actually understand what happens to their personal data rather than being confronted with dense or overly legalistic text.
A qualitative transparency standard associated with Article 12 GDPR (and the corresponding UK GDPR provision) governing how controllers must communicate information under the transparency and information provisions and when responding to data subject rights requests. The information must be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language, with a particular emphasis on clarity where information is addressed specifically to a child. This is a modality-of-delivery obligation rather than a standalone legal basis; it shapes how notices and communications are formatted and does not itself expand or limit the substantive content that must be disclosed. Application is context-dependent and subject to assessment, and practitioners should verify the precise wording and article references against the current official GDPR and UK GDPR texts, as well as applicable regulatory guidance.
Why it matters
Transparency is a foundational principle of the GDPR, but disclosure alone is not enough; the information must actually reach and be understood by the individuals it concerns. The 'concise, transparent, intelligible and easily accessible form' standard under Article 12 addresses a common failure mode where organisations publish exhaustive but impenetrable privacy notices that satisfy the letter of disclosure while defeating its purpose. Where communications are dense, buried, or written in legalistic language, individuals cannot meaningfully exercise their rights or make informed choices, and a controller may face criticism from supervisory authorities even if the underlying substance of the notice is complete.
This standard matters because it operates as a modality obligation that sits alongside, rather than replaces, the substantive content requirements found elsewhere in the transparency provisions. A notice can contain every required data point and still fall short if it is not accessible or intelligible to its intended audience. The obligation carries particular weight where information is addressed to children, for whom a higher degree of clarity is generally expected. Because assessment of what is 'concise' or 'intelligible' is context-dependent, controllers should treat readability and accessibility as ongoing design considerations rather than a one-time compliance box.
Practitioners should note that the precise application of this standard continues to be shaped by regulatory guidance, and the boundary between an acceptable and a deficient notice is a matter of judgement rather than a fixed threshold. The reader should verify the current wording and article references against the official GDPR and UK GDPR texts and consult applicable supervisory authority guidance, as interpretations and expectations can evolve.
Who it's relevant to
Inside Concise, Transparent, Intelligible Form
Common questions
Answers to the questions practitioners most commonly ask about Concise, Transparent, Intelligible Form.