Data Protection HubIndividual TopicsTransparency Obligations

Information to Be Provided Where Personal Data Have Not Been Obtained from the Data Subject (Article 14 GDPR)

Which items a privacy notice must contain where personal data are not collected from the data subject: the additional items on categories of data and source, the time at which the information is to be provided and the four exceptions in Article 14(5) GDPR, with examples.

Where personal data are obtained not from the data subject but from other sources, Article 14 GDPR applies. The mandatory items largely correspond to those applicable to collection from the data subject, but two further items are added (categories of data and source). What is regulated differently is, above all, the time at which the information is to be provided and the exceptions.

Key takeaways

  • Article 14 GDPR applies where data are obtained from other sources: from third parties, from publicly accessible sources, from data brokers.
  • In addition to the items required by Article 13, the categories of data (paragraph 1, point (d)) and the source of the data (paragraph 2, point (f)) must be communicated.
  • The information must be provided within a reasonable period, at the latest within one month, and earlier where there is communication or disclosure (paragraph 3).
  • Article 14 contains four exceptions (paragraph 5): the information is already available, impossibility or disproportionate effort, a statutory provision, professional secrecy.
  • The exceptions are to be construed narrowly; anyone relying on them must set out and document that the conditions are met.

1. Overview

1.1 Collection from other sources

Article 14 GDPR presupposes that the data subject is not themselves the source. It covers in particular:

  • collection from third parties (another body transmits data);
  • collection from publicly accessible sources (registers, directories, social networks, including where the person has published the data themselves);
  • collection from data brokers and credit reference agencies.

What matters is the perspective of the collecting controller: even where another body has already informed the person on an earlier occasion, the recipient collects the data anew and is itself subject to the duty to inform. This also applies to an unsolicited (spontaneous) transmission as soon as the recipient further processes the transmitted data in a targeted manner: the collection then lies in the first targeted processing operation. The obligation always falls on the controller that collects the data.

1.2 Relationship to Article 13

The requirements of Article 12 GDPR as to form, language and active provision of the information apply in the same way. Here too, the catalogs of paragraphs 1 and 2 must in principle be complied with in full.

2. Mandatory information

2.1 Items shared with Article 13

Identical in substance to collection from the data subject, the following must be stated: the controller and the representative (paragraph 1, point (a)), the data protection officer (paragraph 1, point (b)), the purposes and the legal basis (paragraph 1, point (c)), the legitimate interests (paragraph 2, point (b)), the recipients or categories of recipients (paragraph 1, point (e)), transfers to third countries and safeguards (paragraph 1, point (f)), the storage period (paragraph 2, point (a)), the data subject rights and the right to lodge a complaint (paragraph 2, points (c) and (e)), the withdrawal of consent (paragraph 2, point (d)) as well as automated decision-making and the logic involved (paragraph 2, point (g)). As regards content and examples, what has been said on collection from the data subject applies. Here too: where the processing is based on legitimate interests, the interest pursued must be named, otherwise reliance on Article 6(1)(f) GDPR is precluded (CJEU, judgment of 9 January 2025, C-394/23, Mousse).

2.2 Categories of data (paragraph 1, point (d))

New as compared with Article 13 is the obligation to name the categories of data processed. It is necessary because the person does not know which data the controller has obtained about them. The statement must be precise enough for the person to be able to assess the risks. Example: where an employer obtains information about an applicant, the blanket communication that one has "obtained information" is not sufficient. Sufficiently specific is stating which characteristics, abilities or particulars the employer wished to inform itself about or which particulars it has verified.

In the case of ongoing business relationships, it is advisable to bundle the data into meaningful categories, for example master data (name, address), contact details (email, telephone), contract and performance data or correspondence data. The category must be specific enough for the person to assess the nature and the risk of the processing; a collective label such as "business data" does not achieve this. The more sensitive the data, the more precisely the category must be framed.

2.3 Source of the data (paragraph 2, point (f))

It must be stated from which source the data originate and, where applicable, whether they come from publicly accessible sources. This information enables the person to review the lawfulness of the collection and to address incorrect data at the root. It comprises two aspects:

  • Subject matter of the collection: the person or body that transmitted the data, a publication or a trace. Where possible, the specific source must be named (name and contact details of the transmitting body, the place where a publication may be found).
  • Means of collection: an additional statement is called for where the means does not follow from the subject matter and gives rise to particular risks, for example covert surveillance or a complex statistical analysis of public posts.

Where the data originate from publicly accessible sources, this must be communicated expressly (for example where they are collected from a public register or by reading out a website). Where there are several sources, all of them must in principle be named; only where individual data can no longer be attributed to a particular source, for example because they arose only from the combination of several data sets, may the statement be kept general. The mere fact that several sources were used does not exempt the controller; where the origin can be traced back with reasonable effort, it must be named.

The main practical case is collection from generally accessible sources such as public registers (for example the commercial register, the register of associations or the land register), directories, the press and other publications on the internet, as well as information from credit reference agencies and business information services. In these cases the specific source must be named in so far as it can be determined with reasonable effort, and it must be expressly stated that the data originate from publicly accessible sources. In the case of a credit reference agency, this includes which body provided the information, so that the person can also have incorrect data rectified there.

2.4 No information on an obligation to provide the data

The obligation to inform about an obligation to provide the data and its consequences (Article 13(2)(e) GDPR) is absent from Article 14, because the person typically does not participate in the collection. Where, exceptionally, the collection does depend on the person's will, the necessary information follows, in the case of a collection based on consent, already from the conditions for the validity of that consent; in the case of a contract-related collection, Article 13(2)(e) GDPR applies by analogy.

3. Time at which the information is to be provided (paragraph 3)

Article 14(3) GDPR sets out a graduated scheme for the latest point in time:

  • General period (point (a)): within a reasonable period after obtaining the data, having regard to the circumstances, but at the latest within one month. Where the controller collects large volumes of data via the internet which deliberately also contain contact details, the processing must be arranged in such a way that the data subjects are informed immediately after the collection.
  • Communication with the person (point (b)): where the data are to be used for communication with the data subject, at the latest at the time of the first communication. Where, for instance, the controller uses the data obtained to prepare a decision on an application, the information must be provided at the latest when contact is first made.
  • Disclosure to third parties (point (c)): where a disclosure to another recipient is envisaged, at the latest at the time of the first disclosure. Where the controller intends to publish the data, the person must be informed beforehand and given time to react.

Points (b) and (c) shorten the one-month period but do not replace it; the maximum limit of one month remains in place in any event.

Two lines of authority on the timing. The supervisory authorities require that, so far as possible, information be provided well before the periods expire and before the processing takes effect (Article 29 Working Party, WP 260 rev.01, Guidelines on transparency, adopted on 11 April 2018, para. 28). The legal position is more open: Article 14(3)(a) GDPR permits the information to be provided in principle after the collection, within the reasonable period. Information before the processing begins is required only where the collection depends on the person's will (consent or a contract-related collection). Practical line: where the processing interferes with the person's rights or is surprising for them, inform early; a general obligation always to inform before the processing cannot, however, be derived from Article 14.

4. Change of purpose (paragraph 4)

Where the controller intends to further process the data for a purpose other than that for which they were collected, it must inform the person, prior to that further processing, of the new purpose and of the further relevant items referred to in paragraph 2 (Article 14(4) GDPR). The rule corresponds to Article 13(3) GDPR (see change of purpose).

5. Exceptions (paragraph 5)

Article 14(5) GDPR contains four exceptions. They are to be construed narrowly; the burden of proof lies with the controller.

5.1 Information already available (point (a))

As with collection from the data subject, the obligation does not apply in so far as the person already has the information. This is relevant in practice above all in the case of transmissions where the transmitting body has already informed the person. Since, however, usually only part of the items is known, the obligation remains in place for the rest.

5.2 Impossibility or disproportionate effort (point (b))

The obligation does not apply where providing the information proves impossible or would involve a disproportionate effort; likewise where it would seriously impair the objectives of the processing.

Impossibility requires a clear yes or no; the controller must set out the factors that actually prevent the information from being provided. It is rarely present: where, for example, the controller obtains creditworthiness data about a new customer whose address and email address it does not know, providing the information is not impossible if it can point out on its website, before registration, that credit reference data are collected (WP 260 rev.01, para. 59).

Disproportionate effort requires a balancing of the effort involved in providing the information against the interest of the person; the greater the risks of the processing, the higher the effort that can reasonably be expected. Indicators are the number of data subjects, the age of the data and the safeguards in place (Recital 62 GDPR). Examples: where a hospital requires every patient to provide details of two relatives, it would, given a high volume of patients, be disproportionate to inform all the relatives named on a daily basis (WP 260 rev.01, para. 62). Where historical researchers receive a 50-year-old data set without contact details covering 20,000 persons, the attempt to locate all of them individually would be disproportionate (WP 260 rev.01, para. 63). Archiving, research and statistical purposes under Article 89(1) GDPR are singled out; here there is a presumption of disproportionality, which may be rebutted in the individual case.

Serious impairment of the objectives exists where the very provision of the information would frustrate the objective of the processing. Example: where a bank reports a suspicion of money laundering to the authorities, informing the customer would impair the objectives of combating money laundering, because the law prohibits such a tip-off (WP 260 rev.01, para. 65). Likewise, a private investigator who covertly investigates misconduct may withhold the information until the investigation is concluded, but must provide it at the latest when confronting the person with the outcome.

Two lines of authority on disproportionate effort. The supervisory authorities construe the exception very narrowly; one authority, for instance, required television advertisements in order to inform millions of data subjects about a database built up from public sources (WP 260 rev.01, para. 61). The legal position is more nuanced: in the case of mass collection from publicly accessible sources without risk-laden analysis, the effort involved in individual notification may be disproportionate, provided that the number of data subjects is high and the impairment slight.

In all cases falling under point (b), the controller must take appropriate safeguards, in particular make the information publicly available (for example on its website), and document its decision (Article 14(5)(b), second sentence, GDPR).

The obligation does not apply in so far as the obtaining or the disclosure is expressly laid down by Union or Member State law and that law provides appropriate safeguards. What is required is a sufficiently specific provision that prescribes the type of data, the conditions and the purpose; an authorization in the manner of a general clause is not sufficient (CJEU, judgment of 1 October 2015, C-201/14, Bara). The main area of application is statutory reporting obligations to public authorities. Example: where a tax authority is required by law to obtain particulars of employees' salaries from employers, its duty to inform does not apply to that extent (WP 260 rev.01, para. 66).

5.4 Professional secrecy (point (d))

The obligation does not apply in so far as the data are subject to an obligation of professional secrecy and must therefore be kept confidential. The exception concerns triangular constellations: it protects the relationship of trust vis-à-vis third parties whose data the person bound by the obligation of secrecy processes. Example: a doctor receives health data from a patient about relatives who are ill. If the doctor were to inform those relatives under Article 14, they would breach the obligation of professional secrecy; the exception therefore relieves them of the duty to inform those relatives (WP 260 rev.01, para. 67). Vis-à-vis the beneficiary of the professional secrecy themselves, the exception does not apply.

6. Consequences of an infringement

Where the information is not provided, is incomplete or is incorrect, this is subject to fines under Article 83(5)(b) GDPR; in addition, compensation under Article 82 GDPR may come into consideration. Unlike in the case of collection from the data subject, an infringement does not, as a rule, render the collection unlawful, because the information is in any event to be provided only after the collection; the information must then be provided subsequently. It is otherwise only where the collection exceptionally depends on the person's will (consent or a contract-related collection); in that case the failure to inform may render the processing unlawful.

7. Primary sources

Über den Autor

Über den Autor

Dieser Beitrag wurde von Dr. Thomas Helbing, Fachanwalt für IT-Recht in München, verfasst.

Dr. Helbing wird seit 2020 durchgehend bis heute (2026) vom Handelsblatt als einer der „Deutschlands besten Anwälte" im Bereich IT-Recht und Datenschutzrecht ausgezeichnet.

Laut Kanzleimonitor.de (Ausgaben 2024–2026) zählt er zu den führenden Anwälten für Datenschutz und IT-Recht und ist unter den Top-100 Anwälten in Deutschland (2024/25) gelistet. Kanzleimonitor gilt als besonders aussagekräftige Marktstudie, da sie ausschließlich auf persönlichen Empfehlungen von Unternehmensjuristen basiert.

Dr. Helbing verfügt über langjährige Beratungserfahrung im Datenschutz- und IT-Recht und berät Mandanten unterschiedlichster Größen, vom Startup über wachstumsstarke SaaS-Unternehmen und Unicorns bis hin zu internationalen Konzernen.

Sein beruflicher Hintergrund umfasst das gesamte Spektrum der Praxis im IT- und Technologierecht. Er begann seine Laufbahn in einer internationalen Großkanzlei, sammelte anschließend Inhouse-Erfahrung in einem DAX-Unternehmen und ist selbst Unternehmer und Gründer mehrerer digitaler Projekte. Darüber hinaus verfügt er über praktische Programmiererfahrung, wodurch er technische Systeme, Softwarearchitekturen und digitale Geschäftsmodelle nicht nur juristisch, sondern auch aus technischer Perspektive versteht.

Zu seinen Mandanten zählen seit vielen Jahren unter anderem Technologieunternehmen und SaaS-Anbieter, führende deutsche Forschungseinrichtungen sowie eine systemrelevante deutsche Großbank. Seine Beratungsschwerpunkte liegen insbesondere in den Bereichen DSGVO-Compliance, Datenökonomie, SaaS, KI-Regulierung und IT-Vertragsrecht.