Skip to main content
Category: Data Subject Rights

Information to Be Provided

Also known as: Right to be Informed, Transparency Information, Privacy Information
Simply put

This refers to the information organisations must give people about how their personal data is collected and used. Under data protection law, this information must be concise, transparent, intelligible, easily accessible, and written in clear and plain language so that ordinary individuals can understand it.

Formal definition

The 'information to be provided' concerns the transparency obligations owed to individuals in connection with the processing of their personal data, commonly framed as the right to be informed. According to ICO guidance, the information provided must be concise, transparent, intelligible, easily accessible, and expressed in clear and plain language. The precise content, timing, and manner of provision (for example whether personal data is collected directly from the individual or obtained from another source) depend on the applicable provisions of the UK GDPR and any relevant national implementing measures; practitioners should verify the specific requirements and article references against the current official text, as detailed content requirements are not enumerated in the evidence provided here.

Why it matters

Transparency sits at the heart of data protection law. The obligation to provide information to individuals about how their personal data is collected and used underpins the ability of people to exercise their other rights, such as access, rectification, and objection. Without clear and accessible information, individuals cannot meaningfully understand or challenge what is being done with their data, and organisations cannot demonstrate that their processing is fair and lawful. According to ICO guidance, the information provided must be concise, transparent, intelligible, easily accessible, and expressed in clear and plain language.

For organisations, meeting this obligation is not merely a formality of publishing a privacy notice. The quality and accessibility of the information matter: dense, jargon-heavy, or hard-to-find notices may fall short of the standard even where all required content is technically present. Regulators generally treat transparency as a foundational principle, and failure to inform individuals adequately can affect the lawfulness of processing more broadly.

The precise content, timing, and manner in which information must be provided depend on the applicable provisions of the UK GDPR and any relevant national implementing measures, and these can differ depending on whether personal data is collected directly from the individual or obtained from another source. The detailed content requirements are not enumerated in the evidence available here, so practitioners should verify the specific requirements and article references against the current official text before relying on them in a compliance program.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams are typically responsible for ensuring that transparency information meets the standard of being concise, transparent, intelligible, easily accessible, and written in clear and plain language. They generally oversee the drafting, review, and updating of privacy notices and coordinate verification of the applicable content and timing requirements against the current official text.
Privacy and Data Protection Lawyers
Legal advisers assess whether an organisation's transparency information satisfies the applicable UK GDPR provisions and any relevant national implementing measures. They are typically alert to differences in requirements depending on whether personal data is collected directly from individuals or obtained from another source, and to divergence between UK and EU positions.
Product Managers and Engineers
Those designing services and data collection points often need to implement transparency information in a way that is easily accessible and intelligible to users, for example at the point of collection. Clear, plain-language presentation within user interfaces is generally central to meeting the standard in practice.
Individuals (Data Subjects)
The information to be provided exists primarily for the benefit of individuals, enabling them to understand how their personal data is collected and used. This understanding generally supports their ability to exercise further rights over their data.

Inside Information to Be Provided

Controller identity and contact details
The information provided to data subjects generally includes the identity and contact details of the controller and, where applicable, the controller's representative, so individuals know who is responsible for the processing.
Data protection officer contact details
Where a data protection officer has been designated, their contact details are typically included so data subjects have a point of contact for privacy matters.
Purposes and legal basis of processing
The information should state the purposes for which personal data are processed and the applicable Article 6 legal basis. Where legitimate interests is relied upon, the specific interests pursued are generally identified, and for special category data an additional Article 9 condition applies.
Recipients or categories of recipients
Details of the recipients or categories of recipients of the personal data are typically provided, so data subjects understand who may receive their information, including processors where relevant.
International transfer information
Where personal data are transferred to a third country or international organisation, information about the transfer mechanism relied upon is generally provided. Because adequacy decisions and transfer tools evolve, this should reflect the arrangement currently in place and be reviewed over time.
Retention period
The information should indicate the period for which personal data will be stored, or, where that is not possible, the criteria used to determine that period.
Data subject rights
Individuals are typically informed of their rights, which may include access, rectification, erasure, restriction, objection, and portability, subject to the conditions and exceptions that apply to each right, and of the right to lodge a complaint with a supervisory authority.
Source of the data (where not obtained directly)
Where personal data are not collected directly from the data subject, information about the source of the data, and whether it came from publicly accessible sources, is generally included, subject to the exceptions recognised for indirectly collected data.

Common questions

Answers to the questions practitioners most commonly ask about Information to Be Provided.

Does the obligation to provide information only apply when personal data is collected directly from the individual?
No. The transparency obligations generally apply both where personal data is collected directly from the data subject and where it is obtained from another source. The GDPR addresses these two situations separately, and the required information and timing differ between them. In most cases, information for indirectly collected data must still be provided, subject to certain recognized exceptions. You should verify the specific provisions and any applicable exemptions against the current official text.
Is a privacy notice only required when consent is the legal basis for processing?
No. The duty to provide information applies regardless of which Article 6 legal basis is relied upon. Consent is only one of several distinct legal bases, and the transparency obligations are independent of the basis chosen. Even where processing relies on contract, legal obligation, vital interests, public task, or legitimate interests, the relevant information generally still needs to be provided to the data subject.
At what point should this information be provided to individuals?
The timing generally depends on how the data was obtained. Where data is collected directly from the individual, information is typically provided at the time of collection. Where data is obtained from another source, the position differs and typically involves providing information within a defined period, or at the latest by certain trigger points such as first communication or disclosure. You should confirm the precise timing requirements and any exceptions against the current official text, as the boundaries can be context dependent.
How should the information be presented to satisfy transparency requirements?
Information should generally be provided in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. In practice, many organizations use a layered approach, presenting key points prominently with links or references to fuller detail. The appropriate format can depend on the audience and context, for example where information is directed at children. Regulator guidance in this area may evolve, so approaches should be reviewed periodically.
What should an organization do if providing the information proves impossible or disproportionate?
For data obtained from sources other than the data subject, the GDPR recognizes certain exceptions, which may include situations where provision proves impossible or would involve disproportionate effort. Reliance on such an exception generally requires a documented assessment and may call for alternative measures to protect individuals. These exceptions are limited and context dependent, and their application can be subject to regulator scrutiny, so the specific conditions should be verified against the current official text.
How should the information provided be kept accurate over time?
Transparency is generally treated as an ongoing obligation rather than a one-time exercise. In most cases organizations should review and update the information when processing activities change, for example new purposes, recipients, or transfer mechanisms. Where material changes occur, it may be necessary to actively inform affected individuals rather than rely on a passively updated notice. The appropriate approach depends on the nature and significance of the change and should be assessed accordingly.

Common misconceptions

The information provided must always state that consent is the legal basis for processing.
Consent is only one of the distinct Article 6 legal bases. The information should identify whichever basis actually applies, such as contract, legal obligation, vital interests, public task, or legitimate interests, and treating consent as universal misstates the position.
The same information obligations apply identically whether or not the data comes directly from the individual.
There are generally differences between data collected directly from the data subject and data obtained from other sources, including the addition of source information and certain recognised exceptions where data are collected indirectly. Practitioners should verify the applicable requirements against the current official text.
Once a privacy notice is published it does not need to change.
The information should reflect the processing as it is actually carried out. Elements such as international transfer mechanisms, retention criteria, and recipients can change over time, and adequacy decisions and transfer tools in particular evolve, so the information typically needs review and updating.

Best practices

Map each processing activity to its specific Article 6 legal basis before drafting, and where special category data are involved, identify the additional Article 9 condition rather than defaulting to consent.
Use clear, plain language and layered notices so data subjects can readily locate controller identity, purposes, retention, recipients, and their rights.
Where legitimate interests is relied upon, articulate the specific interests pursued, and document the underlying assessment.
State retention periods or, where a fixed period is not possible, the criteria used to determine them, and keep these aligned with actual practice.
Review information about international transfers periodically, since transfer mechanisms, adequacy decisions, and supplementary measures can change, and verify the current position against official sources.
Distinguish notices for directly and indirectly collected data, including source information where applicable, and confirm whether any recognised exceptions apply before relying on them.