Transparency (Article 5(1)(a) GDPR)
The GDPR's principle of transparency: retrospective and prospective comprehensibility of the processing, substantive and linguistic requirements for the information provided to data subjects.
Article 5(1)(a) GDPR requires that personal data be processed "in a transparent manner in relation to the data subject". The principle of transparency has thus been expressly designated as a self-standing principle in order to underline its particular importance. Traditionally, it was understood as an aspect of the principle of fairness (CJEU, judgment of 1 October 2015, C-201/14, Bara, para. 34).
Key takeaways
- Transparency requires processing that is comprehensible to the data subject and is a basic precondition for informational self-determination.
- The principle operates retrospectively and prospectively: the data subject must also be able to assess future processing operations (Recital 39, second sentence, GDPR).
- It is given concrete expression in the information obligations under Articles 13 and 14 GDPR, but may go beyond their minimum catalog.
- The information must at least make the controller and the purposes apparent, as well as the most significant risks of the processing.
- In linguistic terms, a clear, plain and audience-appropriate presentation is required (Recital 39, third sentence, GDPR), and it must be child-friendly where an offering is addressed to children.
1 Overview
1.1 Background and purpose
Transparency is a basic precondition for informational self-determination. Without knowledge of a processing operation, the data subject can neither survey whether and how their data are processed nor exercise their rights. The German Federal Constitutional Court (BVerfG) described these interrelationships as early as the Census judgment: anyone who cannot assess what information about them is known in particular areas of their social environment may be substantially inhibited in their freedom to plan or to decide on the basis of their own self-determination (BVerfG, judgment of 15 December 1983, 1 BvR 209/83 et al., Census, BVerfGE 65, 1).
1.2 Relationship to the information obligations
The principle of transparency has a direct bearing on the information obligations under Articles 13 and 14 GDPR. Those provisions specify the minimum information that must be provided to the data subject. The principle is, however, broader: in an individual case it may give rise to information obligations that go beyond the minimum catalog of Articles 13 and 14 GDPR, where this is necessary to ensure fair and transparent processing.
2 Content of the principle
2.1 Retrospective and prospective comprehensibility
The wording of Article 5(1)(a) GDPR initially suggests retrospective comprehensibility: the processing must be discernible to the data subject after the event. Recital 39, second sentence, GDPR makes clear, however, that the data subject must also prospectively have clarity about future processing of data. Only in that way can the data subject retain control over their data (Recital 7, second sentence, GDPR) and decide whether they are willing to accept individual processing operations.
2.2 Substantive minimum requirements
From the information, the data subject must at least be able to identify who the controller is and for what purposes their data are processed. Further information may be added where it is necessary to ensure fair and transparent processing (Recital 39, fourth sentence, GDPR). In this context, Recital 39, fifth sentence, GDPR emphasizes the risks of the processing: the data subject must be able to assess the effects a processing operation has on them, which means that its most significant consequences must also be brought home to them.
The former Article 29 Working Party gave concrete expression to these requirements in its transparency guidelines (subsequently endorsed by the EDPB) (Article 29 Working Party, WP 260 rev.01, Guidelines on transparency under Regulation 2016/679, adopted on 11 April 2018).
2.3 Linguistic requirements
Under Recital 39, third sentence, GDPR, the information provided to the data subject must be "easily accessible and easy to understand" and drafted "in clear and plain language". At the same time, that wording calls for an audience-appropriate presentation: where an offering is addressed to children, the information must be geared to their knowledge and abilities and not merely to those of their parents.
3 Interplay with the other principles
The interlocking of the principles in point (a) is apparent from Article 13(2) and Article 14(2) GDPR. Those provisions make the obligation to provide additional information conditional on the criterion of "fair and transparent processing": fairness and transparency are here brought together terminologically.
Transparency is also a precondition for the effective exercise of data subject rights under Articles 15 et seq. GDPR. Without knowledge of a processing operation, a right of access under Article 15 GDPR or a right to object under Article 21 GDPR cannot, in practical terms, be asserted.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Fairness (Article 5(1)(a) GDPR)
The fairness principle of the GDPR: the controller's duty of consideration, the prohibition of manipulative design (dark patterns) and the priority of open, direct collection.
Purpose Limitation (Article 5(1)(b) GDPR)
Purpose limitation as a principle of the GDPR: the duty to specify the purpose, the prohibition of incompatible further processing, exceptions for archiving, research and statistical purposes, and the relationship to Article 6(4) GDPR.