Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Data Subject Rights

Right to be Informed

Also known as: Transparency right, Right to information
Simply put

The right to be informed means that individuals are entitled to receive clear, concise, and transparent information about how organisations collect and use their personal data. It is one of the core transparency requirements under data protection law and applies whenever an organisation processes people's personal information.

Formal definition

The right to be informed is an individual right and transparency obligation under the UK GDPR (and, correspondingly, the EU GDPR) that requires controllers to provide data subjects with clear and concise information about the collection and processing of their personal data. It is generally regarded as a key transparency requirement and a fundamental obligation for organisations that collect and use personal data. This entry does not detail the specific information that must be provided, the timing of provision, or applicable exemptions, which vary and should be verified against the current authoritative text and guidance. It should not be conflated with the distinct right of access, which concerns a data subject obtaining a copy of and information about their processed data. Application to particular circumstances requires professional judgment.

Why it matters

Transparency sits at the foundation of data protection law. The right to be informed operationalises this principle by requiring organisations to tell individuals, in clear and concise terms, how their personal data is collected and used. Without this baseline of disclosure, the other individual rights under the UK GDPR and the corresponding EU GDPR become difficult to exercise: a person who does not know their data is being processed, or for what purpose, cannot meaningfully object, seek access, or challenge how that data is handled. For this reason the right is generally regarded as a fundamental obligation for any organisation that collects and uses personal data.

For compliance teams, the right to be informed is often the most visible expression of an organisation's data practices, typically surfaced through privacy notices and similar communications. Because it covers key transparency requirements, gaps here can indicate broader weaknesses in how processing is documented and governed. It is worth distinguishing this right from the separate right of access: being informed concerns the proactive provision of clear information about collection and use, whereas the right of access concerns an individual obtaining a copy of, and information about, data already being processed. Conflating the two can lead to incomplete compliance.

The specific information that must be provided, the timing of provision, and any applicable exemptions vary and are not addressed here. Requirements and regulatory guidance are periodically updated, and enforcement interpretation continues to develop, so organisations should verify their obligations against the current authoritative text and the guidance issued by the relevant supervisory authority.

Who it's relevant to

Data Protection Officers and Privacy Teams
Those responsible for privacy programmes rely on the right to be informed when drafting and maintaining privacy notices and other transparency communications. Because it is a fundamental obligation for organisations that collect and use personal data, it is a recurring focus of privacy governance, though the specific content and timing requirements should be confirmed against current guidance.
Controllers Processing Personal Data
The obligation to provide clear and concise information about the collection and use of personal data falls on controllers. Any organisation acting in this capacity should ensure its disclosures meet the transparency expectations of the UK GDPR and, where applicable, the EU GDPR, recognising that the applicable details depend on the processing in question.
Data Subjects
Individuals are the beneficiaries of this right, being entitled to transparent information about how their personal data is used and processed. Understanding this right helps individuals recognise what organisations should be telling them, while noting it is distinct from the separate right of access to their processed data.
Compliance and Audit Professionals
Those reviewing an organisation's data protection posture often treat transparency disclosures as a visible indicator of underlying practices. Assessing whether the right to be informed is satisfied requires reference to the current authoritative text and guidance, as requirements and enforcement interpretation continue to evolve.

Inside Right to be Informed

Transparency Obligation
At its core, the right to be informed reflects the transparency principle, generally requiring that organizations proactively tell individuals how and why their personal data is processed. Under the EU and UK GDPR frameworks this is typically operationalized through privacy notices provided at or before the point of data collection.
Information Collected Directly from the Individual
Where data is obtained directly from the data subject, the applicable rules generally require that the required information be supplied at the time the data is collected. Readers should verify the specific timing and content requirements against the current text of the relevant regulation.
Information Obtained from Other Sources
Where data is not obtained directly from the individual, the information obligation still generally applies, but the timing and the possibility of exemptions may differ. The precise conditions and any exceptions should be checked against the applicable regulatory text.
Content of the Notice
Privacy notices typically cover matters such as the identity of the controller, the purposes and legal basis for processing, categories of data and recipients, retention considerations, and the rights available to individuals. The exact mandatory elements are specified in the applicable regulation and should be confirmed against the current official text.
Accessibility and Clarity
The information is generally expected to be provided in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. This is a qualitative standard whose application depends on the audience and context.

Common questions

Answers to the questions practitioners most commonly ask about Right to be Informed.

Does the right to be informed mean the same thing as obtaining consent from a data subject?
No. The right to be informed and consent are distinct concepts and should not be conflated. The right to be informed is a transparency obligation requiring the controller to provide individuals with certain information about how their personal data is processed, and it generally applies regardless of the lawful basis relied upon. Consent, by contrast, is one of several possible lawful bases for processing. An organisation may satisfy the right to be informed while relying on a lawful basis other than consent, such as legitimate interests or legal obligation. Providing transparency information does not itself constitute obtaining consent, and obtaining consent does not remove the separate duty to inform. Application to particular circumstances requires professional judgement, and readers should verify obligations against the current official text of the applicable regulation.
Is the right to be informed a universal requirement that applies identically in every jurisdiction?
No. Transparency obligations differ across jurisdictions and should not be presented as a single universal rule. The specific formulation associated with the 'right to be informed' arises under EU data protection law and, in similar form, under the UK regime, and its precise scope, wording, and enforcement practice can differ from comparable transparency requirements in the United States or other territories. Extraterritorial reach may apply in certain cases where a regime governs the processing of data relating to individuals in its territory, but the details are fact-specific. Because requirements vary by jurisdiction and by sector, and because regimes are periodically amended, readers should confirm the applicable obligations against the latest authoritative source for the relevant territory.
What categories of information generally need to be provided to satisfy the right to be informed?
Transparency provisions generally require that individuals be given information about the identity of the controller, the purposes and lawful basis of the processing, the categories of data involved where relevant, any recipients or categories of recipients, retention periods or the criteria used to set them, the individual's rights, and how to exercise them, among other elements. The precise list and its presentation depend on the applicable regime and on whether the data was collected directly from the individual or obtained from another source, which may affect what must be provided and when. This is an informational summary rather than an exhaustive checklist, and organisations should verify the required content against the current official text and apply professional judgement to their specific processing activities.
How is the required information typically communicated to individuals in practice?
In most cases the information is provided through a privacy notice or similar communication that is intended to be concise, transparent, intelligible, and easily accessible, using clear and plain language. The appropriate delivery method depends on context; for example, information may be presented at the point of data collection, layered so that key points appear first with further detail available on request, or delivered through just-in-time notices at relevant moments in a user journey. The suitability of a given approach is fact-specific and may depend on the audience, including whether information is directed at children or other groups requiring particular clarity. Organisations should assess their own circumstances and, where appropriate, seek professional input.
When does the information generally need to be provided?
Timing generally differs depending on the source of the data. Where personal data is collected directly from the individual, the information is typically expected to be provided at the time of collection. Where data is obtained from another source, the information is generally expected to be provided within a reasonable period, or at other trigger points such as the first communication with the individual or the first disclosure to another recipient, subject to the conditions set out in the applicable regime. Certain limited exceptions may apply, for instance where provision would involve disproportionate effort or where an exemption is available. Because these timing rules and exceptions are subject to specific conditions, readers should verify them against the current official text.
How does the right to be informed relate to demonstrating accountability and compliance?
Providing transparency information is one element of a broader accountability posture and is not, on its own, sufficient to demonstrate overall compliance. Organisations generally support their position by maintaining records that show what information was provided, when, and how, and by keeping privacy notices aligned with actual processing activities as those activities change. Because compliance obligations are fact-specific and depend on factors such as the nature of the data and the processing context, satisfying the right to be informed should be treated as part of a wider set of duties rather than a standalone control. Application to particular situations requires professional judgement, and requirements should be verified against the latest authoritative source.

Common misconceptions

The right to be informed is a universal legal requirement that applies the same way everywhere.
The right as commonly discussed arises under specific data protection regimes such as the EU and UK GDPR, and it carries legal force only within their scope. Other jurisdictions, including various US frameworks, address transparency differently, so the precise obligations depend on which law governs the processing.
Publishing a privacy policy on a website satisfies the obligation in all cases.
A published notice can be part of compliance, but the obligation generally concerns whether individuals actually receive the required information at the appropriate time and in an intelligible form. Merely making a document available does not by itself guarantee the transparency standard is met, and application is fact-specific.
The right to be informed is the same as obtaining consent.
Informing individuals and obtaining consent are distinct concepts. The right to be informed concerns transparency about processing regardless of the legal basis used, whereas consent is one possible legal basis among several. Providing information does not, on its own, establish a valid legal basis.

Best practices

Provide transparency information at or before the point of data collection where data is obtained directly, and address separately how and when individuals are informed when data is obtained from other sources.
Draft privacy notices in concise, plain language appropriate to the intended audience, avoiding legalistic phrasing that undermines intelligibility.
Map the specific elements your notice must contain against the current text of the regulation that governs your processing, rather than relying on generic templates.
Confirm the jurisdiction and scope that applies to each processing activity, since transparency obligations differ across the EU, the UK, the US, and other regions.
Keep the right to be informed distinct from consent and other legal bases in your documentation, ensuring the notice explains processing regardless of which basis is relied upon.
Review and update privacy notices periodically, and verify against the latest authoritative regulatory source, because obligations and interpretations may change over time.
Promotional banner for the Penetration Report Template Kit