Article 12
Transparent Information and Data-Subject Communications
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Provide privacy information and rights communications in a concise, accessible, clear form and respond through secure, timely processes.
Points of focus
- Use plain, accessible language suited to the audience
- Facilitate requests and verify identity proportionately
- Track statutory response periods and explain refusals
Implementation notes
Route privacy requests from product, email, and support into one case system, calculate deadlines, apply risk-based identity verification, and retain the exact response and notice version. Operationalize use plain, accessible language suited to the audience in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain layered privacy notices and accessibility review with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the notice is technically complete but hides key processing in dense legal text Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample layered privacy notices and accessibility review with dates and named reviewers. Be ready to walk through how you detect and correct: the notice is technically complete but hides key processing in dense legal text
Evidence auditors typically request:
- Layered privacy notices and accessibility review
- Rights-request workflow with deadlines and identity checks
- Response templates and extension or refusal approvals
Common gaps
- The notice is technically complete but hides key processing in dense legal text
- Request deadlines are tracked manually in personal calendars
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 12 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 12: Regulation (EU) 2016/679, Article 12 — Transparent Information and Data-Subject Communications