Fast Track Bootcamps
 Crafted For Career-Ready Skills

CIPP/E Domain 3: GDPR Information Provision Obligations: Transparency and Privacy Notices

Quick Insights:

The GDPR requires organizations to clearly explain how personal data is collected, used, stored, shared, and safeguarded. Articles 13 and 14 set out the information that must be provided to individuals, including the processing purpose, lawful basis, retention period, recipients, international transfers, and available rights. Privacy information must be clear, concise, easily accessible, and provided at the correct time. Layered notices, just-in-time messages, and privacy dashboards can improve understanding, but they must not hide or replace mandatory disclosures.

In today’s digital economy, personal data supports digital services, innovation, and business decision-making. However, collecting and using personal data must be accompanied by safeguards that protect individuals’ rights. One of the GDPR’s most important safeguards is transparency.

CIPPE Domain 3 Explained GDPR Information Provision & Transparency

Transparency enables individuals to understand how, why and by whom their personal data is processed. It also helps them make informed decisions and exercise their rights under the GDPR.

Within the current CIPP/E Body of Knowledge, Domain III.C covers information provision obligations, including the transparency principle, the key components of privacy notices, and the purpose of layered privacy notices. This domain explains what information must be disclosed, when it must be provided, and how organizations should present it.

The Transparency Principle

Article 5 of the GDPR requires personal data to be processed lawfully, fairly and transparently. Article 12 further requires controllers to provide privacy information in a form that is:

  • Concise
  • Transparent
  • Intelligible
  • Easily accessible
  • Written in clear and plain language

Particular attention must be given to information addressed specifically to children. The information should be appropriate for the knowledge and understanding of the intended audience.

Transparency requires individuals to be able to understand:

  • Who is processing their data
  • What data is being processed
  • Why it is being processed
  • The legal basis for processing
  • Who may receive the data
  • How long the data will be retained
  • Whether it may be transferred internationally
  • What rights the individual may exercise

Transparency directly supports fairness, accountability and the meaningful exercise of data-subject rights. It is especially important where the controller relies on informed consent or legitimate interests.

Failure to meet transparency obligations may constitute a separate GDPR infringement and undermine the fairness of processing. In consent-based processing, insufficient information may also prevent consent from being validly informed.

Privacy Notices (Articles 13 & 14)

Privacy notices are the main tool for delivering required information to data subjects. The required content varies based on the source of the data:

  • Article 13: Article 13 applies when personal data is collected directly from the data subject, such as through:
    • Registration forms
    • Online orders
    • Employment applications
    • Customer enquiries
    • Account creation

The information must be provided when the personal data is obtained.

  • Article 14: Article 14 applies when personal data was not collected directly from the individual, such as where it was obtained from:
    • A business partner
    • A public register
    • A data provider
    • Another group company
    • A third-party platform

The CJEU has clarified that Article 14 may also apply to personal data generated by the controller itself where the underlying data was not collected directly from the data subject.

Key Components of Privacy Notices:

Depending on whether Article 13 or Article 14 applies, the required information may include:

  • The identity and contact details of the controller
  • The controller’s representative, where applicable
  • The DPO’s contact details, where applicable
  • The purposes of processing
  • The lawful basis relied upon
  • The legitimate interests pursued, where Article 6(1)(f) is used
  • Recipients or categories of recipients
  • Details of international transfers and applicable safeguards
  • The retention period or the criteria used to determine it
  • The individual’s applicable data-protection rights
  • The right to withdraw consent at any time when consent is the lawful basis for processing
  • The right to file a complaint with the relevant supervisory authority
  • The existence of qualifying automated decision-making or profiling

The European Data Protection Board (EDPB) has issued guidelines clarifying how organizations should implement transparency requirements.

According to these guidelines, information provided to individuals must be:

  • Concise
  • Transparent
  • Intelligible
  • Easily accessible
  • Written in clear and plain language

Especially when addressing children or vulnerable individuals.

Layered Privacy Notices

Privacy notices can contain a significant amount of information. The EDPB-endorsed transparency guidance therefore recommends a layered approach, particularly in digital environments.

A layered notice presents essential information in the first layer and allows users to access more detailed information through clearly labeled sections or links.

The first layer should give individuals a meaningful overview of:

  • The controller’s identity
  • The purposes of processing
  • Their data-protection rights
  • Any processing that may significantly affect or surprise them

Layered notices must not hide important information behind unnecessary clicks. Information provided across the different layers must be complete and consistent.

Additional Transparency Tools

Depending on the context, controllers may supplement privacy notices with:

  • Just-in-Time Notices: Display relevant information at the moment it’s needed (e.g., near form fields)
  • Privacy Dashboards: Allow users to view and manage their privacy settings in one place
  • Icons and Visuals: Use symbols or graphics to highlight key points and improve clarity
  • Oral or Written Delivery: Tailor the format based on context or audience needs, including accessibility for children or vulnerable individuals

Exemptions from Information Provision

Article 13: Article 13 information does not need to be repeated where and insofar as the individual already has it.

Article 14: The broader Article 14 obligations may not apply where:

  • The individual already has the information.
  • Providing the information is impossible or would involve disproportionate effort under the conditions established by the GDPR.
  • Providing it would make the relevant processing objectives impossible or seriously impair them.
  • Obtaining or disclosure is expressly established by EU or Member State law that protects the individual’s legitimate interests.
  • The personal data must remain confidential under a legally regulated obligation of professional secrecy.

These exemptions must be interpreted carefully. Where the disproportionate-effort or serious-impairment exception is used, the controller must take appropriate alternative measures to protect individuals, which may include making the information publicly available.

To be continued with this domain: International Data Transfers

The next section of Domain III addresses international data transfers, which ensures that personal data remains protected when transferred outside the European Union.

Conclusion

Transparency is a core GDPR requirement that helps individuals understand and control the use of their personal data. Organizations should provide accurate, timely, and easy-to-understand privacy information through notices, layered formats, and contextual tools. Strong transparency practices support fairness, accountability, and regulatory compliance.

CIPP/E Certification Training with InfosecTrain

Enroll in InfosecTrain’s CIPP/E European Privacy Training to gain a strong understanding of GDPR transparency obligations and international data transfer rules. Through practical examples, regulatory insights, and exam-focused learning, the course prepares you to confidently navigate EU data protection requirements and succeed in the CIPP/E certification exam. Enhance your privacy expertise and gain the skills needed to manage real-world data protection challenges in today’s evolving digital landscape.

Cipp

TRAINING CALENDAR of Upcoming Batches For CIPP/E Training

Start Date End Date Start - End Time Batch Type Training Mode Batch Status
07-Sep-2026 22-Sep-2026 20:00 - 22:00 IST Weekday Online [ Open ]
10-Oct-2026 25-Oct-2026 09:00 - 13:00 IST Weekend Online [ Open ]
16-Nov-2026 01-Dec-2026 20:00 - 22:00 IST Weekday Online [ Open ]
05-Dec-2026 20-Dec-2026 09:00 - 13:00 IST Weekend Online [ Open ]
04-Jan-2027 19-Jan-2027 20:00 - 22:00 IST Weekday Online [ Open ]
06-Feb-2027 21-Feb-2027 19:00 - 23:00 IST Weekend Online [ Open ]
01-Mar-2027 16-Mar-2027 20:00 - 22:00 IST Weekday Online [ Open ]

Frequently Asked Questions

 What is a GDPR privacy notice?

A privacy notice explains how an organization collects, uses, stores, and shares personal data.

 What is the difference between Articles 13 and 14?

Article 13 applies when an organization collects personal data directly from the data subject.

Article 14 applies when data is obtained from another source or generated indirectly.

 When must privacy information be provided?

Article 13 information must be provided when data is collected. Article 14 information must generally be provided within one month or earlier in certain situations.

 What is a layered privacy notice?

It presents essential information first and provides links or sections containing more detailed information.

 Are there exemptions from providing privacy information?

Yes. Limited exemptions apply, particularly under Article 14, such as where the individual already has the information or disclosure is legally restricted.

TOP