Information obligations

Data protection glossary · 1 minute read

Information obligations require controllers to inform data subjects transparently about who processes their data, for what purpose and on what basis.

When and how information must be provided

Where data is collected from the data subject, information must be provided at the time of collection. Where it comes from other sources, the information must be provided within a reasonable period, at the latest after one month, or at the time of first contact.

The information must be concise, intelligible and easily accessible. A layered approach with brief initial information and a reference to the full privacy information has proven effective.

Exemptions

No information needs to be provided where and insofar as the person already has it. Further exemptions apply where data is collected from other sources, for example where this would involve a disproportionate effort or where statutory secrecy obligations apply. The BDSG provides for additional restrictions.

Art. 12 GDPR
Transparency, form and modalities.
Art. 13 GDPR
Information obligation where data is collected from the data subject.
Art. 14 GDPR
Information obligation where data is obtained from other sources.
Sections 32 and 33 BDSG
National exemptions from the information obligations.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.