Privacy notice
What data subjects are told: who the controller is, why data is collected, on what basis, for how long, with whom it is shared and their rights.
How the register reads it
| Also called | privacy statement, fair processing notice |
|---|---|
| Family | Privacy |
| Document type | Record. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The data protection officer or privacy lead. |
| Review cadence | No fixed period: Articles 13 and 14 require the notice to be accurate at the time of collection, so it changes when the processing changes; the register's default check is annual. |
| On the gap list when | GDPR or ISO 27701 is ticked and no line resolves to it. |
| Template | Privacy notice template. |
Which standards require it, and what each expects it to contain
5 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27701:2025
ISO 27701 A.1.3.3 Determining information for PII principalsThe organization must determine and document what information is to be provided to individuals about the processing of their data and when it is to be provided, working out the legal, regulatory and business requirements for timing and content, which typically covers the purpose, the controller's contact details, the lawful basis, the source where data was not obtained from the individual, whether provision is statutory or contractual and the consequences of not providing it, the obligations owed and how to benefit from them including access, amendment, correction, erasure, obtaining a copy and objecting, how to withdraw consent, transfers, recipients or categories of recipients, the retention period, any automated decision making, the right to complain and how, and how often information is provided, updated whenever purposes change or extend.
Common gap: Notice content copied from a template, so elements that do not apply are present and elements that do are missing
Source: ISO/IEC 27701:2025
ISO 27701 A.1.3.4 Providing information to PII principalsThe organization must give individuals clear and easily accessible information identifying the controller and describing the processing of their data, delivered in a timely, concise, complete, transparent, intelligible and easily accessible form using clear and plain language suited to the audience, given at the time of collection where appropriate and permanently accessible thereafter.
Common gap: Notice legally complete and written at a reading level the audience cannot use, which fails the intelligibility requirement
Source: ISO/IEC 27701:2025
GDPR (Regulation (EU) 2016/679)
GDPR Art. 12 Transparent information, communication and modalities for rightsProvide the Article 13 and 14 information and every Article 15 to 22 and 34 communication in a concise, transparent, intelligible and easily accessible form, in clear and plain language, with particular care where the information is addressed to a child, normally in writing including by electronic means. Facilitate the exercise of data subject rights and do not refuse to act unless the controller demonstrates it cannot identify the data subject. Provide information on action taken without undue delay and in any event within one month of receipt, extendable by two further months where the complexity and number of requests requires it, with the data subject informed of the extension and its reasons within the first month. Where no action is taken, say so within one month with the reasons and inform the data subject of the right to lodge a complaint with a supervisory authority and to seek a judicial remedy. Act free of charge; a reasonable fee or refusal is available only for manifestly unfounded or excessive requests, and the controller bears the burden of demonstrating that character. Additional information may be requested only where there are reasonable doubts about the requester's identity.
Common gap: The one month clock started when the request reached the privacy team rather than when it reached the organisation
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 13 Information to be provided where personal data are collectedWhere personal data is collected from the data subject, provide at the time it is obtained the identity and contact details of the controller and any representative, the contact details of the data protection officer, the purposes and the legal basis, the legitimate interests where that is the basis, the recipients or categories of recipient, and any intention to transfer to a third country with the existence or absence of an adequacy decision and, for Article 46, 47 or 49(1) transfers, reference to the safeguards and how to obtain a copy. Provide in addition the storage period or the criteria used to determine it, the existence of the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent where consent is the basis, the right to lodge a complaint with a supervisory authority, whether providing the data is a statutory or contractual requirement and the consequences of not providing it, and the existence of automated decision-making including profiling with meaningful information about the logic involved and its significance and envisaged consequences. Before further processing for a new purpose, provide that purpose and the further information first.
Common gap: Recipients described only as third parties or trusted partners, which names neither a recipient nor a category
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 14 Information where personal data have not been obtained from the data subjectWhere personal data has not been obtained from the data subject, provide the same identity, contact, purpose, legal basis, recipient and transfer information as Article 13, plus the categories of personal data concerned and the source the data came from including whether it was a publicly accessible source. Provide it within a reasonable period and at the latest within one month of obtaining the data, or at the latest at the first communication with the data subject if the data is used to communicate with them, or at the latest when the data is first disclosed to another recipient. The obligation does not apply where the data subject already has the information, where provision proves impossible or would involve disproportionate effort in which case appropriate protective measures including making the information publicly available must be taken, where obtaining or disclosure is expressly laid down by Union or Member State law with appropriate safeguards, or where the data must remain confidential under an obligation of professional secrecy.
Common gap: Purchased or enriched marketing data used with no Article 14 notification at all, which is the most common finding in this area
Source: GDPR (Regulation (EU) 2016/679)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerPersonal data breach procedure · Record of processing activities