Skip to main content
Category: Data Subject Rights

Transparency Information

Also known as: Privacy Information, Data Transparency Information
Simply put

Transparency information is the clear, accessible information an organisation provides to people about how and why it collects and uses their personal data. The aim is to give individuals genuine visibility into data practices so they can understand what is happening to their information. In most cases this information is expected to be provided in plain, easily understood language and in a timely way.

Formal definition

In a data protection context, 'transparency information' generally refers to the body of information a controller must make available to data subjects to satisfy the transparency principle and related information obligations, typically covering how personal data is collected, processed, stored, and shared, and the purposes and parties involved. The provided evidence describes transparency and data transparency at a conceptual level (the provision of adequate, accessible information about processes and decision-making, and clear visibility for users, regulators, and stakeholders) but does not set out the specific GDPR provisions or mandated content elements. Practitioners should note that the precise content, timing, and format requirements for transparency information under the GDPR or UK GDPR, and any national derogations, are not established by the evidence here and should be verified against the current official text and applicable regulatory guidance. This entry does not address the distinct but related information notices, layered-notice practices, or specific Article-based obligations, none of which are supported by the sources provided.

Why it matters

Transparency information sits at the heart of the relationship between an organisation and the people whose data it uses. Without clear, accessible information about how and why personal data is collected and used, individuals cannot meaningfully understand what is happening to their information, and the wider accountability structure that data protection law depends on begins to break down. Transparency is widely regarded as a foundational condition for trust: as public-sector and philanthropic bodies have noted, sharing information about processes and operations in an accessible and timely manner is what allows others to see and evaluate what is being done.

For organisations, providing adequate transparency information is generally both a compliance expectation and a practical necessity. Clear visibility into how data is collected, processed, stored, and shared supports the ability of users, regulators, and stakeholders to scrutinise data practices, and it underpins the exercise of individual rights that depend on people first knowing what is happening to their data. Where information is absent, incomplete, or buried in language that is difficult to understand, individuals are effectively deprived of the visibility the transparency principle is intended to secure.

Because the precise content, timing, and format requirements for transparency information under the GDPR or UK GDPR are not settled by the general sources here, organisations should treat transparency as a principle to be operationalised carefully rather than a fixed checklist. The exact obligations, and any national derogations, should be verified against the current official text and applicable regulatory guidance, as the position can vary by jurisdiction and evolve over time.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for compliance programmes generally need to ensure that transparency information is adequate, accessible, and provided in a timely way, and that it gives individuals genuine visibility into data practices. They should confirm the specific content, timing, and format expectations against the current official GDPR or UK GDPR text and applicable regulatory guidance, since these are not fixed by the general sources here.
Privacy and Data Protection Lawyers
Legal advisers assessing whether an organisation meets the transparency principle will typically focus on whether information about collection, processing, storage, and sharing is clear and accessible. They should be alert to the boundary of this concept, distinguishing it from separate Article-based information obligations and layered-notice practices, and verify precise requirements and any national derogations against current authoritative sources.
Engineers and Product Teams
Teams building systems that collect and process personal data are often responsible for surfacing transparency information to users at the right point and in plain language. Their work supports the clear visibility that users, regulators, and stakeholders expect into how data is collected, processed, stored, and shared.
Individuals and Data Subjects
People whose personal data is used are the intended beneficiaries of transparency information. Its purpose is to give them genuine, accessible understanding of what is happening to their information, which in turn supports their ability to make informed decisions and exercise their rights.
Regulators and Oversight Stakeholders
Regulators and other stakeholders rely on transparency information to scrutinise data practices and assess whether processing is being carried out openly. Clear visibility into data handling supports their oversight function, though the specific standards they apply derive from the applicable legal text and guidance rather than the general sources cited here.

Inside Transparency Information

Controller identity and contact details
The identity and contact details of the controller and, where applicable, the controller's representative, so that data subjects know who is processing their personal data and how to reach them.
Data Protection Officer contact details
Where a Data Protection Officer has been designated, their contact details, typically enabling data subjects to raise queries about the processing.
Purposes and legal basis for processing
The purposes for which the personal data are processed and the applicable legal basis under Article 6 (for example consent, contract, legal obligation, vital interests, public task, or legitimate interests). Where special category data under Article 9 is involved, the relevant additional condition should also be identified. Where legitimate interests is relied on, the interests pursued are generally stated.
Recipients of the personal data
The recipients or categories of recipients of the personal data, if any, so data subjects understand with whom their data may be shared.
International transfer information
Where personal data are transferred to a third country or international organisation, information about the transfer, the relevant transfer mechanism (such as an adequacy decision or appropriate safeguards) and how to obtain a copy of, or where the safeguards are made available. These mechanisms evolve and any statement should be verified against the current position.
Retention period
The period for which the personal data will be stored, or where that is not possible, the criteria used to determine that period.
Data subject rights
Information about the data subject's rights, which may include access, rectification, erasure, restriction, portability, and objection, subject to the conditions and limitations that apply to each right, and, where processing is based on consent, the right to withdraw consent.
Right to lodge a complaint
Information about the right to lodge a complaint with a supervisory authority.
Source of the data (indirect collection)
Where personal data are not obtained directly from the data subject, the categories of personal data concerned and, generally, the source from which the data originate, including whether it came from publicly accessible sources.
Automated decision-making and profiling
Where applicable, the existence of automated decision-making, including profiling, together with meaningful information about the logic involved and the significance and envisaged consequences of such processing for the data subject.
Statutory or contractual requirement to provide data
Where data is collected directly, whether provision is a statutory or contractual requirement or a precondition to entering a contract, and the possible consequences of failing to provide the data.

Common questions

Answers to the questions practitioners most commonly ask about Transparency Information.

Does providing transparency information only require a privacy policy on our website?
Not necessarily. A published privacy notice is a common way to deliver transparency information, but the obligation is about ensuring individuals actually receive the required information in a concise, transparent, intelligible and easily accessible form, using clear and plain language. Depending on the context, this may require layered notices, just-in-time notices at the point of collection, or other delivery methods beyond a single static webpage. Whether a website policy alone is sufficient is subject to assessment based on how and where the data is collected.
Is transparency information only needed when we rely on consent as our legal basis?
No. Transparency obligations apply regardless of which Article 6 legal basis you rely on, whether that is consent, contract, legal obligation, vital interests, public task, or legitimate interests. The information provided should typically identify the applicable legal basis, but the duty to be transparent is not limited to consent-based processing. This is a common misconception; consent is only one of several legal bases and transparency runs across all of them.
When must transparency information be provided if we collect personal data directly from the individual?
Where personal data is obtained directly from the individual, transparency information is generally expected to be provided at the time the data is collected. The practical implication is that notices should typically be surfaced at or before the point of collection, for example within a form or interface, rather than after processing has begun. You should verify the precise timing requirements and any conditions against the current official text of the GDPR.
How should transparency information be handled when data is obtained from a third party rather than the individual?
Where personal data is not obtained directly from the individual, transparency information generally still needs to be provided within a reasonable period, and certain additional details such as the source of the data and the categories of data involved are typically expected. There are recognised exceptions in some circumstances, for example where provision proves impossible or would involve disproportionate effort, but reliance on any exception should be assessed carefully and documented. Confirm the specific conditions and timeframes against the current Regulation text.
How can a layered approach to transparency information be implemented in practice?
A layered approach typically presents the most important information first, such as the controller's identity, the purposes of processing, and how to exercise rights, with links or expandable sections leading to fuller detail. This can help meet the requirement for information to be concise and easily accessible while still covering the full set of required items. The design should be tested against the intelligibility and clear-language standard, and what counts as adequate layering may vary by context and audience, including where children are involved.
What should we do when our processing purposes or data uses change after the notice was issued?
Where processing changes materially, transparency information generally needs to be updated and, in many cases, the change communicated to affected individuals rather than simply revising the notice quietly. If a new purpose is introduced, you should assess its compatibility with the original purpose and whether further information or a different legal basis is required. The appropriate method and timing of communicating changes should be assessed case by case and documented.

Common misconceptions

A single privacy notice satisfies all transparency obligations regardless of how data is collected.
The required content and timing generally differ depending on whether personal data is collected directly from the data subject or obtained indirectly from another source. In particular, indirect collection typically requires disclosing the source and categories of data, and the timing rules for provision differ. Practitioners should tailor the information to the collection scenario.
Transparency information is only needed when consent is the legal basis.
Transparency obligations generally apply to processing across the Article 6 legal bases, not only consent. Consent is one distinct basis among several, and the duty to inform data subjects is not contingent on consent being used.
Listing every possible recipient and purpose in dense legal language makes a notice compliant.
Transparency is generally assessed on whether information is concise, intelligible, and provided in clear and plain language, not merely on whether it is technically complete. A comprehensive but unintelligible notice may not meet the standard, and assessments can vary by regulator and context.

Best practices

Maintain separate, scenario-specific notices or clearly delineated sections for directly and indirectly collected data, reflecting the different content and timing requirements that generally apply to each.
Map each processing activity to its specific Article 6 legal basis (and any Article 9 condition for special category data) before drafting, so the stated purposes and bases are accurate rather than generic.
Use layered notices with a concise top layer and deeper detail available on demand, drafting in clear and plain language appropriate to the audience, including where children may be data subjects.
Keep international transfer disclosures under regular review, since adequacy decisions, transfer tools, and supplementary measures evolve; verify the current mechanism rather than relying on a past snapshot.
Where automated decision-making or profiling occurs, prepare meaningful, non-technical explanations of the logic and envisaged consequences, and confirm whether the enhanced disclosure threshold applies.
Establish a review cadence to update transparency information when purposes, recipients, retention periods, or legal bases change, and document version history to evidence accountability.