Article 14
Information When Data Is Obtained Indirectly
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Inform individuals when personal data comes from another source, including the categories and source, unless a documented exception applies.
Points of focus
- Identify indirect collection from customers, brokers, partners, and public sources
- Provide required information within the applicable time or first contact
- Document reliance on an exception and protect affected individuals
Implementation notes
Record source and collection date with imported datasets, assign notice responsibility during customer onboarding, and trigger notice before first outreach or the one-month limit where applicable. Operationalize identify indirect collection from customers, brokers, partners, and public sources in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain indirect-source register and notice delivery logs with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a customer uploads end-user data and both parties assume the other gave notice Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample indirect-source register and notice delivery logs with dates and named reviewers. Be ready to walk through how you detect and correct: a customer uploads end-user data and both parties assume the other gave notice
Evidence auditors typically request:
- Indirect-source register and notice delivery logs
- Customer contract process allocating notice responsibilities
- Documented exception analysis with safeguards
Common gaps
- A customer uploads end-user data and both parties assume the other gave notice
- Publicly available data is treated as exempt without assessing Article 14
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 14 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 14: Regulation (EU) 2016/679, Article 14 — Information When Data Is Obtained Indirectly