Data Protection HubIndividual TopicsTransparency Obligations

Information to Be Provided Where Data Are Collected from the Data Subject (Article 13 GDPR)

Which mandatory items a privacy notice must contain where personal data are collected from the data subject: the catalogs of Article 13(1) and (2) GDPR with examples, purposes and legal basis, legitimate interests (Mousse), information on a change of purpose and the exception for information the data subject already has.

Where personal data are collected from the data subject, Article 13 GDPR applies. The provision contains two catalogs of mandatory information (paragraphs 1 and 2), the duty to inform in the event of a subsequent change of purpose (paragraph 3) and an exception where the data subject already has the information (paragraph 4). How the information is to be prepared and presented is set out under General requirements.

Key takeaways

  • Article 13 GDPR applies where the data subject is themselves the source of the data (form, registration, observation).
  • The items required under paragraphs 1 and 2 rank equally and must in principle both be provided in full; neither takes precedence.
  • Purposes and legal basis must be specific and assigned to one another; merely citing a provision or naming a purpose is often not sufficient.
  • Where the processing is based on legitimate interests, the interest must be stated in the notice; otherwise reliance on that ground is precluded.
  • The only exception provided directly by the Regulation is that the data subject already has the information (paragraph 4); it is to be construed narrowly.

1. Overview

1.1 Collection from the data subject

Article 13 GDPR presupposes that the data are collected from the data subject, that is, that the data subject is the immediate source. This is the case in two constellations:

  • The data subject knowingly provides the data, for example when filling in a form, when registering or in a conversation.
  • The controller obtains the data by observing the data subject's behavior, for example through video surveillance, sensors, RFID or the tracking of website use.

Active participation is not required: a person who is observed without noticing it is also covered as the source within the meaning of Article 13 GDPR. Where, by contrast, the data are obtained from other sources, Article 14 GDPR applies. Where the controller uses a form to collect, at the same time, data about third persons (for example relatives), those third persons must be informed under Article 14 GDPR, and the person completing the form under Article 13 GDPR.

It follows from the duty to inform that a covert collection from the data subject is permissible only exceptionally: it requires a restricting measure under Article 23 GDPR. Anyone who, for example, instructs a private investigator to carry out covert surveillance can rely only on such a statutory basis; without it, the covert collection is unlawful.

1.2 Addressee of the obligation and structure of the provision

The obligation falls on the controller who collects the data (Article 4(7) GDPR; see controller). Where several bodies are joint controllers, they determine in their arrangement which of them provides the information (Article 26(1) GDPR). Sometimes only one body is factually able to inform in good time: where a website embeds a third-party service, only the website operator can provide the information before the collection takes place (CJEU, judgment of 29 July 2019, C-40/17, Fashion ID).

The division of the mandatory items between paragraphs 1 and 2 does not create any order of precedence. Both catalogs must be complied with in full alike. Recital 60 GDPR may sound like a risk-based approach under which some items would have to be provided only where there is a particular need; the wording of the provision does not support this. In practice, the entire catalog must always be worked through, if only because of the risk of fines.

2. Mandatory information under paragraph 1

2.1 Controller and representative (point (a))

The identity and the contact details of the controller must be given in such a way that contact can be made without difficulty. At a minimum, the full designation (name or company name) and an address at which service can be effected are required. Where the collection takes place over the internet, an online means of contact must be included so that the data subject can reach the controller without a change of medium (email address or web form). Where the controller must designate a representative in the Union (Article 27 GDPR), that representative's details must also be stated.

2.2 Data protection officer (point (b))

Where the controller has designated a data protection officer, that officer's contact details must be given, irrespective of whether the designation was mandatory or voluntary. The name need not be stated; from the data subject's perspective, what matters is the function that can be reached, not the individual.

This item is the core of the notice. It requires two things: the purpose or purposes, and the legal basis for each of them.

Purposes. What the data are processed for must be communicated, and in terms specific enough for the data subject to form a picture of what to expect. "Specific" means that the type of data, the actual use and the consequences for the data subject must be discernible. Where several purposes are pursued, each must be named individually. By providing this information, the controller at the same time binds itself to that purpose vis-à-vis the data subject; this is where purpose limitation attaches. Information that is too general fails the transparency requirement: "for business processing" says nothing, whereas "for delivery of the order, for invoicing and for a credit check prior to purchase on account" carries the point.

How to arrive at a specific statement of purpose becomes clear from looking at the processing itself. When a website is operated, for instance, access data are generated automatically with every request; their purpose can be captured in two steps: delivering the requested content (provision of functionality) and repelling attacks and other abusive access (security and protection against misuse). With a contact form, the purpose is handling the inquiry and communicating with the inquiring person; where the inquiry concerns a contract with the controller, performance of the contract is added as a further purpose. In both cases it becomes apparent which data are used for what, instead of merely naming a generic term.

Legal basis. What the processing is based on must be stated (Article 6(1) GDPR, and in the case of sensitive data additionally Article 9(2) GDPR). Merely citing the ground for lawful processing is not always sufficient: those grounds are worded openly, and in the case of a legal obligation or a public task (Article 6(1)(c) and (e) GDPR) the underlying Member State or Union law is additionally relevant. Where the legal position is complex or the data subject would otherwise be unable to place it, it must be explained by reference to the individual case. Where a public authority collects data, it must state the specific legal basis and the specific purpose of the collection; it is not sufficient that a statute permits the collection in general terms (CJEU, judgment of 1 October 2015, C-201/14, Bara).

ProcessingPurposeLegal basis
Online orderperformance of the contract, deliveryArticle 6(1)(b) GDPR
Retention of the invoicestatutory retentionArticle 6(1)(c) GDPR in conjunction with § 147 of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB)
Newsletterdirect marketing with consentArticle 6(1)(a) GDPR
Fraud prevention in the shopprotection against payment defaultArticle 6(1)(f) GDPR

A frequent mistake is to lose the link between the type of data, the purpose and the legal basis. Anyone who lists purposes and legal bases only in separate lists leaves open which data are processed for which purpose on which basis. The processing becomes non-transparent and difficult to defend in a dispute. It helps to present the type of data, the purpose, the legal basis and the storage period together for each processing operation.

2.4 Legitimate interests (point (d))

Where the processing is based on legitimate interests (Article 6(1)(f) GDPR), the specific interest must be named. This item goes beyond point (c): it is intended to enable the data subject to follow the balancing of interests and to raise substantiated objections. General boilerplate is not sufficient; the interest must be stated in tangible terms, for example "protection against theft" for video surveillance in a retail store or "own advertising to existing customers".

Which interests may come into consideration can be pinned down by reference to recurring case groups. Frequent ones are protection against fraud and other abuse (protection against misuse), ensuring IT security (security), advertising one's own similar products to existing customers (direct marketing), providing one's own services economically, for example by using specialized service providers (efficiency), improving one's own offering in line with demand (improvement), and the establishment and defense of legal claims (exercise of rights). What matters is to name the interest pursued in the specific case in such a way that the data subject can follow the balancing exercise: not "legitimate interests", but for example "protection of our retail store against theft" or "direct marketing to existing customers".

The interest must appear in the notice; otherwise it cannot be relied on. The information required by Article 13(1)(d) GDPR is not a mere formality but a condition of lawfulness: if the legitimate interest pursued is not communicated to the data subject directly at the time of collection, the processing can no longer be based on Article 6(1)(f) GDPR (CJEU, judgment of 9 January 2025, C-394/23, Mousse, paras. 46 and 52 and the operative part). Practical consequence: anyone wishing to base processing on point (f) must include the specific interest in the privacy notice from the outset; supplying the legal basis after the fact is not an option.

2.5 Recipients or categories of recipients (point (e))

The recipients or categories of recipients must be stated, in so far as a disclosure is foreseeable at the time of collection. A recipient is any body to which data are disclosed, including a processor and including an organizationally separate sub-unit of the same controller. An individual employee who accesses data in the course of their duties is not a recipient; their action is attributed to the controller. Publication, too, is a disclosure and must therefore be stated.

The obligation exists only in so far as the disclosure is foreseeable at the time of collection. Where specific recipients have been determined, they must be named; where only groups of recipients are foreseeable, meaningful categories suffice (type, sector, location). Example: if a trader obtains a credit score before a purchase on account, it should name the specific service provider where that provider has been determined; otherwise it is sufficient to state that application data are passed on to a credit reference agency for a credit check.

In practice, a hybrid approach has proven its worth: in the individual sections, the recipients are named by meaningful categories (for example technical service providers for operation and maintenance, providers of embedded content, payment and transport service providers, and public bodies where there is a statutory obligation), while a separate list that is easier to maintain sets out the specific service providers used. In this way the running text remains stable even if an individual provider changes, and the specific information is nevertheless available. This corresponds to the wording of Article 13(1)(e) GDPR, which places "recipients or categories of recipients" side by side.

Two lines of authority on naming recipients. The supervisory authorities require that, as a rule, the specific recipients be named. The CJEU points in the same direction for the right of access: the controller must in principle name the specific recipients, and categories suffice only as a narrowly defined exception (CJEU, judgment of 12 January 2023, C-154/21, Österreichische Post). That line cannot, however, simply be transposed to Article 13: the right of access concerns ongoing processing with recipients that have been determined, whereas the information under Article 13 is given at the time of collection, at which specific recipients are often not yet foreseeable. Practical line: where specific recipients have been determined at the time of collection, name them; otherwise use meaningful categories.

2.6 Transfers to third countries (point (f))

Where the controller intends to transfer data to a third country or to an international organization, it must inform the data subject of this expressly. It must also state what the transfer is based on: the existence or absence of an adequacy decision or, in the case of appropriate safeguards such as standard contractual clauses, a reference to where the data subject can inspect them or obtain a copy (for details see transfers to third countries). Example: where a US service is used, it must be stated whether the provider falls under an adequacy decision or whether the transfer is based on standard contractual clauses. Where, exceptionally, a transfer is based on compelling legitimate interests (Article 49(1), second sentence, GDPR), a separate duty to inform arises under Article 49(1), fourth sentence, GDPR.

3. Mandatory information under paragraph 2

3.1 Storage period (point (a))

The period for which the data will be stored must be stated or, where a fixed period is not possible, the criteria used to determine that period. The information must be precise enough for the data subject to be able to determine the period at least approximately themselves; this presupposes an erasure concept. It is advisable to give general criteria plus specific periods where these have been determined, for example ten years for accounting records (§ 257 HGB) or six months for application documents after a rejection. The statement is binding: once the stated period has expired, the data must in principle be erased (Article 17(1)(a) GDPR).

In practice, this item can be handled in the same way as the categories of data, by means of a term defined once: one may, for example, define a "storage period for access data" of [7 days] and refer to it throughout the document. It makes sense to distinguish three levels: the standard period, after which data are erased once the purpose ceases to apply; the statutory retention that blocks earlier erasure (for example ten years for accounting records under § 257 HGB and § 147 AO); and the limitation period for possible claims, for the duration of which retention for evidentiary purposes may come into consideration. Where a fixed period is not possible, the criteria must be stated, for example "until the end of the business relationship plus the statutory retention periods".

A blanket statement that the data will be "stored for as long as is necessary for the respective purpose" is not sufficient. It merely repeats the principle of storage limitation and tells the data subject nothing.

3.2 Data subject rights (point (b))

Information must be given about the rights of access, to rectification, to erasure, to restriction of processing, to data portability and to object. A general presentation suffices here, because at the time of collection it is not yet settled which claims will arise and when. Rights that are excluded from the outset in the specific case must not be listed (for example data portability where the processing is based neither on consent nor on a contract and is not carried out by automated means). The right to object must be brought explicitly to the attention of the data subject and presented separately from the other information, at the latest at the time of the first communication (Article 21(4) GDPR).

Where the processing is based on consent, information must be given about the right to withdraw it at any time with effect for the future, without affecting the lawfulness of the processing carried out up to that point. It must be as easy to withdraw consent as to give it.

3.4 Right to lodge a complaint (point (d))

The right to lodge a complaint with a supervisory authority must be stated (Article 77 GDPR). So that the data subject can exercise this right without difficulty, it is advisable to name a competent supervisory authority specifically, for example the authority at the controller's seat.

3.5 Obligation to provide the data and consequences (point (e))

Information must be given as to whether the provision of the data is required by statute or contract, whether there is an obligation to provide the data, and what the consequences of a failure to provide them would be. This item is of central importance, because only in this way can the data subject assess their situation. In practice, three case groups can be distinguished:

Case groupWhat must be saidExample
Obligation to provide (statutory or contractual)that, how and where applicable to what extent cooperation is required, plus any specific sanctionsstatements to tax or social security authorities
Duty in one's own interest or precondition for concluding a contractwhich items are required, a clear separation from voluntary fields, the consequence of refusalinsurance claim: submitting documents; mandatory fields in a registration form
Voluntary provisionreference to the voluntary natureadditional, non-required profile details

In the case of ongoing business relationships, this item is often framed as a general statement: only those data need be provided which are necessary for the establishment, performance and termination of the relationship or which there is a statutory obligation to collect; without them the contract cannot be concluded or continued. In an employment relationship there is the additional point that without the necessary information the employment relationship cannot be performed.

In the case of public authorities that interfere with rights, it must be made expressly clear that there is no obligation and that a refusal has no adverse consequences. In the case of private bodies, a reference to the voluntary nature is dispensable where it is obvious: a person entering a store under video surveillance need not be told separately that they could avoid it.

Practical tip. With online forms, it should be clearly apparent which fields are mandatory and which are voluntary, for example by marking the mandatory fields. Where voluntary items are requested in addition to the required ones, it must be made expressly clear which those are.

3.6 Automated decision-making and profiling (point (f))

Where automated individual decision-making including profiling within the meaning of Article 22(1) and (4) GDPR takes place, information must be given about it and, at least in those cases, the logic involved as well as the significance and the envisaged consequences must be set out. The logic involved means the methods and criteria of the processing, for example how a scoring procedure works, not disclosure of the source code; the explanation must make the mechanism comprehensible to the data subject (CJEU, judgment of 7 December 2023, C-634/21, SCHUFA Holding; on the scope of this in the context of the right of access see CJEU, judgment of 27 February 2025, C-203/22, Dun & Bradstreet). Significance and consequences relate to the decision that is being prepared: what is being decided and what effects the processing may have for the data subject. Where profiling without automated individual decision-making entails comparably serious risks, it is advisable, in case of doubt, to provide information about the logic in those cases as well. Where trade secrets stand in the way, they cannot be played off against the duty to inform; at most they can be accommodated by way of a statutory restriction (Article 23 GDPR).

4. Information on a change of purpose (paragraph 3)

Where the controller intends to further process the data for a purpose other than that for which they were collected, it must inform the data subject prior to that further processing of the new purpose and of the further relevant items referred to in paragraph 2 (on substantive admissibility see change of purpose under Article 6(4) GDPR). This also covers the legal basis of the further processing and, where the change consists in a transmission, the recipient. There is no need to provide information about the abstract rights again; what is required are the items that change as a result of the change of purpose, for example the storage period. Example: if customer data collected for the performance of a contract are later to be used for the controller's own advertising, information about this new purpose and about the right to object must be given beforehand.

5. Exception: information the data subject already has (paragraph 4)

The duty to inform does not apply in so far as the data subject already has the information (Article 13(4) GDPR). This is the only exception provided directly by the Regulation where data are collected from the data subject. It is to be understood narrowly:

  • It is required that the data subject has, in scope, precision and clarity, precisely the information that would have to be communicated. It is not sufficient that they could infer it from general knowledge.
  • The exception operates only "in so far as". Where the data subject has part of the information, the remaining items must still be provided. In the case of recurring business contact, the data subject will regularly know the basic items (controller, rights), but the case-specific items must be provided again.
  • The burden of proof lies with the controller (accountability). It should document what the data subject was already informed about and from what source.

6. Consequences of an infringement

Where the information is not provided, is incomplete or is incorrect, this is subject to fines under Article 83(5)(b) GDPR; in addition, compensation under Article 82 GDPR may come into consideration. Whether the collection itself becomes unlawful depends on whether it depended on the data subject's will:

  • Where the collection did not depend on that will, because the data subject had to tolerate it or to cooperate in it, it remains lawful; the information must be provided subsequently.
  • Where the collection did depend on that will (consent, or a collection that can factually be avoided, such as video surveillance in a public space), the failure to inform may render the collection unlawful. The data subject can, however, approve it after having been fully informed. Data collected unlawfully may in principle not be processed further (Article 17(1)(d) GDPR).

7. Primary sources

Über den Autor

Über den Autor

Dieser Beitrag wurde von Dr. Thomas Helbing, Fachanwalt für IT-Recht in München, verfasst.

Dr. Helbing wird seit 2020 durchgehend bis heute (2026) vom Handelsblatt als einer der „Deutschlands besten Anwälte" im Bereich IT-Recht und Datenschutzrecht ausgezeichnet.

Laut Kanzleimonitor.de (Ausgaben 2024–2026) zählt er zu den führenden Anwälten für Datenschutz und IT-Recht und ist unter den Top-100 Anwälten in Deutschland (2024/25) gelistet. Kanzleimonitor gilt als besonders aussagekräftige Marktstudie, da sie ausschließlich auf persönlichen Empfehlungen von Unternehmensjuristen basiert.

Dr. Helbing verfügt über langjährige Beratungserfahrung im Datenschutz- und IT-Recht und berät Mandanten unterschiedlichster Größen, vom Startup über wachstumsstarke SaaS-Unternehmen und Unicorns bis hin zu internationalen Konzernen.

Sein beruflicher Hintergrund umfasst das gesamte Spektrum der Praxis im IT- und Technologierecht. Er begann seine Laufbahn in einer internationalen Großkanzlei, sammelte anschließend Inhouse-Erfahrung in einem DAX-Unternehmen und ist selbst Unternehmer und Gründer mehrerer digitaler Projekte. Darüber hinaus verfügt er über praktische Programmiererfahrung, wodurch er technische Systeme, Softwarearchitekturen und digitale Geschäftsmodelle nicht nur juristisch, sondern auch aus technischer Perspektive versteht.

Zu seinen Mandanten zählen seit vielen Jahren unter anderem Technologieunternehmen und SaaS-Anbieter, führende deutsche Forschungseinrichtungen sowie eine systemrelevante deutsche Großbank. Seine Beratungsschwerpunkte liegen insbesondere in den Bereichen DSGVO-Compliance, Datenökonomie, SaaS, KI-Regulierung und IT-Vertragsrecht.