Information to Be Provided
This refers to the information organisations must give people about how their personal data is collected and used. Under data protection law, this information must be concise, transparent, intelligible, easily accessible, and written in clear and plain language so that ordinary individuals can understand it.
The 'information to be provided' concerns the transparency obligations owed to individuals in connection with the processing of their personal data, commonly framed as the right to be informed. According to ICO guidance, the information provided must be concise, transparent, intelligible, easily accessible, and expressed in clear and plain language. The precise content, timing, and manner of provision (for example whether personal data is collected directly from the individual or obtained from another source) depend on the applicable provisions of the UK GDPR and any relevant national implementing measures; practitioners should verify the specific requirements and article references against the current official text, as detailed content requirements are not enumerated in the evidence provided here.
Why it matters
Transparency sits at the heart of data protection law. The obligation to provide information to individuals about how their personal data is collected and used underpins the ability of people to exercise their other rights, such as access, rectification, and objection. Without clear and accessible information, individuals cannot meaningfully understand or challenge what is being done with their data, and organisations cannot demonstrate that their processing is fair and lawful. According to ICO guidance, the information provided must be concise, transparent, intelligible, easily accessible, and expressed in clear and plain language.
For organisations, meeting this obligation is not merely a formality of publishing a privacy notice. The quality and accessibility of the information matter: dense, jargon-heavy, or hard-to-find notices may fall short of the standard even where all required content is technically present. Regulators generally treat transparency as a foundational principle, and failure to inform individuals adequately can affect the lawfulness of processing more broadly.
The precise content, timing, and manner in which information must be provided depend on the applicable provisions of the UK GDPR and any relevant national implementing measures, and these can differ depending on whether personal data is collected directly from the individual or obtained from another source. The detailed content requirements are not enumerated in the evidence available here, so practitioners should verify the specific requirements and article references against the current official text before relying on them in a compliance program.
Who it's relevant to
Inside Information to Be Provided
Common questions
Answers to the questions practitioners most commonly ask about Information to Be Provided.