Skip to content
compliancebase
GDPRChapter III — Information When Data Is Obtained Indirectly

Article 14

Information When Data Is Obtained Indirectly

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Inform individuals when personal data comes from another source, including the categories and source, unless a documented exception applies.

Points of focus

  • Identify indirect collection from customers, brokers, partners, and public sources
  • Provide required information within the applicable time or first contact
  • Document reliance on an exception and protect affected individuals

Implementation notes

Record source and collection date with imported datasets, assign notice responsibility during customer onboarding, and trigger notice before first outreach or the one-month limit where applicable. Operationalize identify indirect collection from customers, brokers, partners, and public sources in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain indirect-source register and notice delivery logs with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a customer uploads end-user data and both parties assume the other gave notice Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample indirect-source register and notice delivery logs with dates and named reviewers. Be ready to walk through how you detect and correct: a customer uploads end-user data and both parties assume the other gave notice

Evidence auditors typically request:

  • Indirect-source register and notice delivery logs
  • Customer contract process allocating notice responsibilities
  • Documented exception analysis with safeguards

Common gaps

  • A customer uploads end-user data and both parties assume the other gave notice
  • Publicly available data is treated as exempt without assessing Article 14

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 14This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Information When Data Is Obtained Indirectly applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — identify indirect collection from customers, brokers, partners, and public sources — with evidence stored where auditors and customers can sample it.

Lead with indirect-source register and notice delivery logs and pair it with customer contract process allocating notice responsibilities. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a customer uploads end-user data and both parties assume the other gave notice Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above