Skip to content
compliancebase
GDPRChapter III — Information When Data Is Collected from the Individual

Article 13

Information When Data Is Collected from the Individual

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Tell individuals at collection who controls their data, why it is used, the legal basis, recipients, transfers, retention, rights, and relevant automated decision information.

Points of focus

  • Deliver required information at or before direct collection
  • Describe purposes, legal bases, recipients, transfers, and retention
  • Notify individuals before materially new processing

Implementation notes

Attach notice identifiers to collection surfaces in code, make privacy review part of event-schema and form changes, and use just-in-time explanations for sensitive or unexpected uses. Operationalize deliver required information at or before direct collection in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain just-in-time product notice linked to a full privacy notice with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a new telemetry field launches without updating the collection notice Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample just-in-time product notice linked to a full privacy notice with dates and named reviewers. Be ready to walk through how you detect and correct: a new telemetry field launches without updating the collection notice

Evidence auditors typically request:

  • Just-in-time product notice linked to a full privacy notice
  • Data-collection inventory mapped to notice sections
  • Change review showing when renewed notice or choice was needed

Common gaps

  • A new telemetry field launches without updating the collection notice
  • The notice says data may be retained as needed but gives no meaningful criteria

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 13This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Information When Data Is Collected from the Individual applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — deliver required information at or before direct collection — with evidence stored where auditors and customers can sample it.

Lead with just-in-time product notice linked to a full privacy notice and pair it with data-collection inventory mapped to notice sections. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a new telemetry field launches without updating the collection notice Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above