Skip to main content
Category: Data Subject Rights

Transparency Obligations

Also known as: Transparency Obligation, Transparency Duties
Simply put

Transparency obligations are duties that require organizations to give people clear, accessible information about how a system works and, in the AI context, to tell people when they are interacting with or seeing content produced by an artificial intelligence system. The aim is to help individuals understand what is happening with the technology so they can make informed decisions. The specific requirements depend on the applicable law and the type of system involved.

Formal definition

In the sources provided, 'transparency obligations' most prominently refers to disclosure duties under the EU AI Act (see Article 50 as referenced in the evidence), which generally require providers and deployers of certain AI systems to make AI use visible to affected persons, such as disclosing when someone is interacting with an AI system and disclosing when content has been artificially generated or manipulated. The concept also appears in a broader governance sense as a duty to share information needed for informed decision-making and accountability. Practitioners should note that the term as used in this evidence derives principally from AI regulation and general transparency policy rather than from GDPR data protection transparency provisions; the precise scope, triggering conditions, and responsible actors (for example, provider versus deployer) vary by instrument and should be verified against the current official text, as related requirements and effective dates continue to evolve.

Why it matters

Transparency obligations sit at the heart of trustworthy technology governance because they address a basic information asymmetry: people often cannot tell when they are dealing with an automated or artificially generated system rather than a human or authentic content. When individuals do not know they are interacting with an AI system, or that content has been generated or manipulated, they cannot meaningfully assess what they are seeing or make informed decisions about it. Disclosure duties are designed to close that gap and to support accountability for how systems operate.

In the AI regulatory context, these duties are given concrete form. Under the EU AI Act, as referenced in the evidence at Article 50, providers and deployers of certain AI systems are generally required to make AI use visible to affected persons, including disclosing when someone is interacting with an AI system and when content has been artificially generated or manipulated. The precise triggers, the allocation of responsibility between provider and deployer, and the applicable timing continue to evolve, so organizations should verify the current scope and any effective dates against the official text rather than relying on a fixed snapshot.

It is worth noting that transparency is also used in a broader governance sense, as a duty to share the information needed for informed decision-making and accountability, including in public-sector contexts. Practitioners should be careful not to conflate the AI Act transparency duties described here with data protection transparency requirements under the GDPR, which are distinct in source and scope. The term as used in this evidence derives principally from AI regulation and general transparency policy.

Who it's relevant to

AI system providers
Organizations that build or supply AI systems may bear transparency duties to design or configure their systems so that AI use can be made visible, for example enabling disclosure that someone is interacting with an AI system or that content has been artificially generated. The allocation of these duties between provider and deployer varies by instrument and should be verified against the current text.
AI system deployers
Entities that put AI systems into use in their own operations may be required to disclose AI use to affected persons, such as informing users they are interacting with an AI system or disclosing that content has been artificially generated or manipulated. As referenced in the evidence, certain EU AI Act disclosure duties fall specifically on deployers.
Compliance and legal teams
Lawyers, compliance leads, and data protection officers advising on AI governance need to map which transparency obligations apply, to whom, and under which instrument. They should take care to distinguish AI Act transparency duties from separate transparency requirements under data protection law and to confirm scope and timing against official sources.
Individuals and affected persons
The obligations exist primarily to benefit the people who interact with AI systems or encounter AI-generated content. Transparency is intended to help them recognize and understand what is happening so they can make informed decisions, and, in broader governance terms, to support accountability.

Inside Transparency Obligations

Right to be Informed
The overarching principle, derived from the transparency requirement in Article 5(1)(a) and given effect through the information obligations in Articles 13 and 14, that individuals must be told how their personal data is processed. This generally applies to the personal data of living individuals and does not extend to anonymous data or, typically, to the data of legal entities.
Article 13 Information (data collected from the individual)
The set of information a controller must provide when personal data is obtained directly from the data subject. This generally includes the identity and contact details of the controller, the purposes and legal basis for processing, and related particulars. The precise items should be verified against the current text of Article 13.
Article 14 Information (data obtained indirectly)
The information a controller must provide where personal data has not been obtained directly from the data subject, together with the categories of data and the source. Article 14 contains certain exceptions or exemptions from providing information; their availability is subject to assessment against the conditions in the Regulation and any applicable member state derogations.
Identification of the Controller and DPO
Transparency information should identify the controller (and any representative) and, where one has been designated, the contact details of the Data Protection Officer. Note that whether a DPO is required depends on separate criteria and is not universal.
Purposes and Legal Basis
Transparency information should state the purposes of the processing and the relevant Article 6 legal basis for each purpose. These bases are distinct, so consent should not be presented as the default; where special category data under Article 9 is involved, the additional Article 9 condition should also be identified.
Recipients and Transfers
Information about recipients or categories of recipients, and about any transfers of personal data to third countries or international organisations, including reference to the relevant transfer tool relied upon. Transfer mechanisms and adequacy positions evolve, so the specific mechanism described should be verified against the current position.
Retention and Data Subject Rights
Information on the retention period (or the criteria used to set it) and on the data subject rights available, such as access, rectification, erasure, and the right to lodge a complaint with a supervisory authority. The precise rights and their limits are subject to the conditions set out in the Regulation.
Form and Manner of Communication
Transparency information should generally be provided in a concise, transparent, intelligible, and easily accessible form, using clear and plain language, consistent with the modalities in Article 12. This is typically delivered through a privacy notice or layered notices.

Common questions

Answers to the questions practitioners most commonly ask about Transparency Obligations.

Does providing a privacy notice on your website satisfy transparency obligations by itself?
Not necessarily. Publishing a privacy notice is an important element, but transparency is a broader principle. The information must actually reach the individuals concerned, be presented in a concise, transparent, intelligible and easily accessible form, and use clear and plain language. A notice that is buried, overly legalistic, or not surfaced at the point of data collection may fall short even if it technically exists. Transparency also interacts with the information duties owed when personal data is collected directly from the individual versus obtained from other sources, and the timing of those disclosures differs. You should assess whether your delivery mechanism genuinely informs the relevant individuals in context.
Is transparency the same thing as obtaining consent?
No. Transparency and consent are distinct concepts. Transparency is an overarching principle requiring that individuals are informed about how their personal data is processed, and it applies regardless of which lawful basis under Article 6 you rely on. Consent is only one of several possible legal bases. You owe transparency information even when you process on the basis of, for example, contract, legal obligation, or legitimate interests. Treating transparency as though it only matters where consent is used is a common error; the duty to inform generally exists across all processing activities.
What information typically needs to be included in transparency disclosures to individuals?
Disclosures generally cover matters such as the identity and contact details of the controller and, where applicable, its representative and data protection officer; the purposes and legal basis for the processing; the recipients or categories of recipients; details of any transfers outside the relevant jurisdiction and the safeguards relied upon; retention periods or the criteria used to set them; the individual's rights; and, where processing is based on legitimate interests, the interests pursued. The precise content differs depending on whether the data was collected directly from the individual or obtained from another source. You should confirm the applicable list against the current text of the Regulation and any relevant national implementing law, as details and derogations can vary.
How should transparency information be delivered when data is collected through channels with limited space, such as mobile apps or connected devices?
A layered approach is commonly used, where key information is provided upfront at the point of collection with links or references to fuller detail. Supervisory authority guidance has discussed just-in-time notices, icons, and other mechanisms suited to constrained interfaces. The core requirement is that the information remains concise, intelligible, and easily accessible in context. Because approaches and expectations continue to develop, and regulators may take differing views, you should test your chosen method against current guidance rather than assuming a particular format is definitively compliant.
When personal data is obtained from a third party rather than directly from the individual, when must transparency information be provided?
Where data is obtained from a source other than the individual, the information generally must be provided within a reasonable period after obtaining it, and at the latest by defined trigger points such as when the data is first used to communicate with the individual or first disclosed to another recipient. There are also recognised exceptions, for example where provision proves impossible or would involve disproportionate effort, subject to conditions. The exact timing rules and available exceptions should be checked against the current Regulation text, as their application is fact-specific and subject to assessment.
How should transparency notices be maintained over time as processing changes?
Transparency is an ongoing obligation rather than a one-off exercise. As purposes, recipients, retention practices, transfer mechanisms, or legal bases change, the information provided to individuals should be reviewed and updated, and material changes may need to be communicated proactively rather than simply posted. It is generally advisable to version-control notices, keep records of what was communicated and when, and align updates with related instruments and assessments. Because transfer tools and adequacy positions can evolve, disclosures referencing them should be revisited periodically and verified against the current position.

Common misconceptions

Transparency obligations are satisfied by a single long privacy policy that is technically available on a website.
Availability alone is not sufficient. The information must generally be concise, intelligible, and in clear and plain language, and must actually be brought to the individual's attention at the appropriate time. A dense or hard-to-find notice may not meet the standard, though how this is assessed can depend on context and regulator guidance.
Transparency means the organisation must always obtain consent for the processing it describes.
Transparency and consent are distinct concepts. Transparency requires informing individuals about the processing regardless of the legal basis; consent is only one of several Article 6 bases. A notice should identify whichever legal basis actually applies rather than defaulting to consent.
If data was not collected directly from the individual, there is no duty to inform them.
Article 14 generally requires controllers to inform individuals even where data is obtained indirectly, including the source of the data. Certain exceptions may apply, but their availability is subject to assessment against the conditions in the Regulation and should not be assumed.

Best practices

Map each processing purpose to its specific Article 6 legal basis (and any Article 9 condition where special category data is involved) before drafting notices, so the transparency information reflects the actual basis rather than a generic reference to consent.
Use a layered approach, pairing a short, prominent notice with a fuller privacy notice, to meet the requirement for concise, intelligible, and easily accessible information in clear and plain language.
Distinguish notices for directly collected data (Article 13) from those for indirectly obtained data (Article 14), and where relying on an Article 14 exception, document the assessment supporting its availability.
Describe recipients, third-country transfers, and the transfer tool relied upon in a way that can be updated, and review these entries periodically because adequacy decisions and transfer mechanisms evolve.
State retention periods or the criteria for determining them, and clearly set out the data subject rights and the route to complain to a supervisory authority.
Verify article references, exemptions, and any national or UK GDPR variations against the current official text and applicable member state law, since derogations and regulator guidance can vary the position.