Article 13
Information When Data Is Collected from the Individual
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Tell individuals at collection who controls their data, why it is used, the legal basis, recipients, transfers, retention, rights, and relevant automated decision information.
Points of focus
- Deliver required information at or before direct collection
- Describe purposes, legal bases, recipients, transfers, and retention
- Notify individuals before materially new processing
Implementation notes
Attach notice identifiers to collection surfaces in code, make privacy review part of event-schema and form changes, and use just-in-time explanations for sensitive or unexpected uses. Operationalize deliver required information at or before direct collection in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain just-in-time product notice linked to a full privacy notice with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a new telemetry field launches without updating the collection notice Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample just-in-time product notice linked to a full privacy notice with dates and named reviewers. Be ready to walk through how you detect and correct: a new telemetry field launches without updating the collection notice
Evidence auditors typically request:
- Just-in-time product notice linked to a full privacy notice
- Data-collection inventory mapped to notice sections
- Change review showing when renewed notice or choice was needed
Common gaps
- A new telemetry field launches without updating the collection notice
- The notice says data may be retained as needed but gives no meaningful criteria
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 13 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 13: Regulation (EU) 2016/679, Article 13 — Information When Data Is Collected from the Individual