The Right to be Informed: GDPR explained

Demystifying the Right to be Informed under the GDPR: in this blog post, we’ll explore the nuances of this fundamental right, its implications for individuals and organisations, and practical tips for compliance.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Understanding the Right to be Informed

 

Definition and Scope

The Right to be Informed is set out in Articles 13 and 14 of the GDPR. It entitles individuals to have essential information about the processing of their personal data. It serves as a cornerstone of transparency and accountability in data protection.

The right applies whether or not you have received the information from the data subject directly.

 

Key Principles

 

To comply with the GDPR’s requirements the information you are obliged must meet these standards:

  • Transparency and Accessibility: Information should be provided in a clear, concise, and easily understandable manner, ensuring accessibility to all individuals.
  • Comprehensiveness: The information provided must cover all relevant aspects of data processing. This includes the purposes, legal basis, recipients, retention periods, and data subject rights.
    Timeliness: Information should be provided promptly. This is typically at the time of data collection, to enable individuals to make informed decisions regarding their personal data.

 

Core Components of the Right to be Informed

 

Identity and Contact Details of the Controller

Individuals have the right to know the identity of the organisation collecting and processing their data. They also need to know how to contact them for inquiries or requests. This organisation is known as the data controller. The data controller makes the decision about what personal data to collect and how it is used.

 

Purposes of Processing

Organisations must clearly specify the purposes for which personal data is being collected and used, ensuring transparency and accountability in data processing activities.

 

Legal Basis for Processing

Individuals have the right to know the legal basis for the processing of their personal data. It does not matter whether it is based on consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests.

 

Categories of Personal Data Collected

Organisations must disclose the types of personal data being collected. This is to ensure individuals are aware of the information being processed about them.

 

Recipients of Personal Data

Individuals have the right to know who their data will be shared with. This usually means third-parties, or other organisations, such as data processors or statutory/government bodies. Any transfers out of your organisation should be summarised in the information you give to data subjects.

 

Retention Period

Organisations must inform individuals about how long their data will be stored and the criteria used to determine the retention period. The retention period will be how long you intend to keep personal information in an identifiable form.

 

Data Subjects’ Rights

Individuals have the right to be informed about their data subject rights, including the right to access, rectify, erase, restrict processing, object to processing, and data portability.

 

Right to Lodge a Complaint

Organisations must inform individuals of their right to lodge a complaint with a supervisory authority if they believe their data protection rights have been violated. In the United Kingdom that is the Information Commissioner.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Practical Considerations for The Right to be Informed

 

Developing a Privacy Statement

Organisations can fulfill the Right to be Informed by creating a comprehensive privacy statement that addresses all the required information in a clear and concise manner. A privacy statement can be found on most organisations’ websites. This online publication is a relatively simple way of complying with this GDPR right. You can find out more about privacy statements here.

 

Considerations for Different Audiences

Organisations should tailor their communication strategies to ensure that information is accessible and understandable to individuals of all ages and backgrounds, including children and their parents or guardians.

 

Using Visual Aids

The use of images, diagrams, or other visual aids can enhance understanding and engagement with privacy information, making it more accessible to a wider audience.

 

Collaboration with Parents and Guardians

In cases involving children, organisations should work closely with parents or guardians to ensure that children understand the implications of data processing and their privacy rights. Remember – people’s GDPR rights apply from birth. That means if you process children’s data, your privacy statement must be written for them.

 

Top Tips for Compliance with the Right to be Informed

 

1. Map Your Data Flows: Understand what data you collect and why to ensure accuracy and relevance in your privacy statement.

2. Draft with Simplicity: Use clear, simple, and concise language, ensuring that children can understand the information provided. Consider whether video or animation might be a better way of communicating your privacy statement.

3. Consult with Stakeholders: Seek input from parents, guardians, and relevant stakeholders to ensure your privacy statement meets the needs of your audience.

4. Keep it Under Review: Regularly review and update your privacy statement to reflect changes in data processing activities and regulatory requirements.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial

Conclusion

In conclusion, the Right to be Informed is a fundamental aspect of data protection under the GDPR, empowering individuals with knowledge and transparency regarding the processing of their personal data. By embracing transparency, accessibility, and collaboration, organizations can ensure compliance with this essential right while fostering trust and accountability in their data processing practices.