GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-009 Privacy Notice and Transparency

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Individuals whose personal data is collected or processed are provided with a clear privacy notice at or before the point of collection. The notice discloses the identity of the data controller, the processing purposes, the legal basis, the data categories, the retention periods, third-party disclosures, the rights available to the individual and contact details for the data protection officer or privacy team. The notice and every communication about processing are given in a concise, transparent, intelligible and easily accessible form in clear and plain language, with a version addressed to children where the notice reaches them, in writing or by electronic means, and an oral route is available where the individual's identity is proven by other means. Where personal data is to be processed for a purpose other than the one disclosed at collection, the individual is given the new purpose and the related information before that processing starts.

Rationale

Transparency is a foundational principle and the condition on which individuals can exercise any control over their data; inadequate notices are a leading cause of enforcement action. The form requirement is separate from the content requirement and is failed differently: a notice that lists every required element in six thousand words of legal prose is complete and not intelligible. The further-processing notice is the AI case, where data collected to deliver a service is later used to train a model, and it is owed before the processing rather than at the next annual notice refresh.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (11)

GDPR-Art.12.1Transparent Information and Communication Modalitiesfull
GDPR-Art.13.1Privacy Notice — Data Collected Directly (Core Information)partial
GDPR-Art.13.2Privacy Notice — Data Collected Directly (Supplementary Information)partial
GDPR-Art.13.3Notice of Further Processingfull
GDPR-Art.14.1Privacy Notice — Data Not Collected Directlypartial
GDPR-Art.14.3Timing of Indirect Collection Noticepartial
GDPR-Art.5.1aLawfulness, Fairness and Transparency of Processingpartial
PM-20Dissemination of Privacy Program Informationpartial
PT-5Privacy Noticefull
P1.1Privacy Noticefull
P6.7Business Transferpartial

Evidence (4)

policydocumentmanual

Privacy notice (public-facing) disclosing all required GDPR Art.13 and Art.14 information to data subjects at or before the point of data collection.

Example: Privacy Policy / Privacy Notice published at https://[company].com/privacy, version dated within 12 months, including: controller identity, DPO contact, processing purposes, legal bases, data categories, retention periods, third-party disclosures, international transfer mechanisms, and data subject rights

Test: Review the published privacy notice. Verify it includes all GDPR Art.13 required elements: (1) controller identity and contact details, (2) DPO contact (if applicable), (3) processing purposes and legal bases for each purpose, (4) retention periods or criteria, (5) third-party recipients or categories of recipients, (6) details of any international transfers and safeguards, (7) all six data subject rights plus right to withdraw consent, (8) right to lodge a complaint with a supervisory authority, (9) notice is currently published and dated.

recorddocumentmanual

Privacy notice version history and change log demonstrating that the notice is kept current and material changes are communicated to data subjects.

Example: Privacy notice version log (Git history, CMS version history, or Confluence page history), showing the last 3 versions with: date published, summary of changes, and evidence of communication to existing users (email notification or in-product banner) for any material changes

Test: Request the privacy notice version history and any change communication records. Verify: (1) the current notice version is dated within the last 12 months, (2) a change log or version history is maintained, (3) for any material changes (new purposes, new third-party disclosures, changes to rights mechanisms), evidence exists that existing users were notified before the change took effect, (4) the DPO reviewed and approved the current version.

reportdocumentmanual

Plain-language and accessibility review of the privacy notice, recording the reading level reached, the structure and the route by which an individual can receive the information orally.

Example: Privacy notice readability review, v9, 2026-05-19

Test: Request the readability and accessibility review. Verify: (1) it records a measured reading level against a stated target rather than an opinion, (2) the notice is reachable within one step from each point of collection, (3) where the service reaches children, a version addressed to them exists and was reviewed on the same basis, (4) the oral route is named and a request made through it during the period was answered with the individual's identity proven by other means, (5) the review covers the rights communications as well as the notice itself.

recorddocumentmanual

Notice records for purposes added after collection, showing the individual was given the new purpose before the further processing began.

Example: Further-processing notice campaign record, model training purpose, sent 2026-02-03

Test: Request the notice records for purposes added since the last notice version. Verify: (1) every added purpose appears in a notification record, (2) the notification date precedes the date the further processing started, (3) the notification carried the new purpose and the supplementary information the original notice would have carried for it, (4) the population notified matches the population whose data the new purpose reaches, (5) individuals who could not be reached are identified and their data excluded from the new purpose or covered by a recorded decision.

Questions (3)

boolean

Is a current privacy notice published at or before the point of personal data collection, disclosing all information required by GDPR Articles 13 and 14?

The notice must include: controller identity and contact details, DPO contact (if applicable), processing purposes and legal bases, retention periods, third-party recipients, international transfer mechanisms, and all six data subject rights. It should be dated and reviewed within the last 12 months.

select

What process ensures the privacy notice remains current when processing activities change?

The privacy notice is updated as part of every product release or processing change that affects personal data, with DPO reviewThe privacy notice is reviewed on a fixed annual cycle regardless of changesThe notice is updated reactively when a change is flagged by the legal or privacy teamNo formal update process: the notice is updated on an ad hoc basis

The notice should be updated proactively when new purposes, new third-party recipients, or changes to data subject rights mechanisms are introduced. Annual review alone is insufficient for a product whose processing changes between releases.

multi

Which of the following apply to the way your privacy information is presented?

Concise, transparent and easily accessible formClear and plain language, tested against a stated reading levelA version addressed to children where the service reaches themAn oral route where the individual's identity is proven by other meansIndividuals are told of a new purpose before their data is processed for itNone of the above

Options run from the most commonly in place to the least. Form and content fail differently: a notice listing every required element in six thousand words of legal prose is complete and not intelligible. The further-processing notice is owed before the processing starts, not at the next annual refresh of the notice.