When should we provide privacy information? (2024)

In detail

  • At what point do we have to provide the privacy information?
  • How long do we have if we obtain personal data from other sources?
  • Can we put privacy information on our website for people to find?

At what point do we have to provide the privacy information?

When you collect personal data from the individual it relates to, Article 13 of the UKGDPR says that you must provide them with privacy information:

“…at the time when personal data are obtained…”

This applies when you collect personal data:

  • directly from an individual (eg when they fill-in a form); or
  • by observation (eg when you use CCTV or track people online).

Example

A bank collects personal data from an individual in branch when they fill in a form to apply for a current account. The bank provides information to the individual on the application form to let them know why they need the data and what they do with it. The individual can review this information as they fill in the form.

Example

The bank provides its customers with a mobile-banking app so they can manage their current account on the move. The app uses an individual’s location on their smartphone to inform them of nearby offers they can benefit from if they use their debit card. The app provides individuals with information about location tracking at the time of first log-in. App users can choose to accept or decline this use of their personal data.

Further reading –European Data Protection Board

The European Data Protection Board (EDPB), which has replaced the Article 29 Working Party (WP29), includes representatives from the data protection authorities of each EU member state. It adopts guidelines for complying with the requirements of the GDPR. EDPB guidelines are no longer directly relevant to the UK regime and are not binding under the UK regime. However, they may still provide helpful guidance on certain issues.

WP29adoptedguidelines on Transparency, which have been endorsed by the EDPB.

How long do we have if we obtain personal data from other sources?

When you obtain personal data from a source other than the individual it relates to, Article 14 of the UKGDPR says you must provide them with privacy information:

“…within a reasonable period after obtaining the personal data, but at the latest within one month…”

This applies when you obtain personal data:

  • from another individual or organisation (eg if you buy in personal data, or it is shared with you); or
  • from a publicly accessible source (eg the open electoral register).

The UKGDPR further clarifies that if you plan to use the personal data you obtain to communicate with the individual it relates to, or to disclose to someone else, the latest point at which you must provide the information is when you first communicate with the individual or disclose their data to someone else. Bear in mind that the one month time limit still applies in these situations. If, for instance, you plan on disclosing an individual’s personal data to someone else two months after obtaining it, you must still provide that individual with privacy information within a month of obtaining the data.

Whatever the situation, you must consider the specific circ*mstances of your use of the personal data in deciding when it would be reasonable to provide privacy information to an individual. You are accountable for demonstrating that what you did was fair. In practice this means that you need to think carefully about the reasonable expectations of individuals and what effects your use of their data may have on them.

The need to provide people with privacy information as soon as possible after obtaining their personal data is strongest where:

  • your use of the data is likely to be unexpected or unwelcome;
  • your use of the data is likely to have a significant effect on individuals; or
  • you have obtained special categories of personal data or criminal conviction and offence data.

Example

A council obtains the names and contact details of the members of several voluntary groups in its area, from each group’s secretary. It intends to send letters to the members to invite them to a training event it is running on child safeguarding. The council assesses that the voluntary group members are unlikely to be significantly affected by, or object to, this use of their data. As such, it provides the members with the appropriate privacy information at the point at which it first communicates with them about the training event, two weeks after obtaining their data.

Example

The council also obtains the names and contact details of members of other voluntary groups in its area. It intends to disclose their details to a market research company that is conducting a survey on the council’s behalf to gauge public opinion on council services. The council assesses that the voluntary group members are less likely to expect their data to be used in this way and may object to being contacted by the market research company. As such, it decides to provide the voluntary group members with information about its intention to pass their details on to the market research company as soon as it obtains their personal data, and well in advance of any disclosures actually taking place. The council also uses this opportunity to seek the consent of the voluntary group members to use their data for the new purpose.

Prior to obtaining personal data, it is good practice to use a data protection impact assessment (DPIA) to identify the risks of what you plan to do, and then build in appropriate measures and safeguards, including deciding when to provide individuals with privacy information and what your lawful basis is for a further use of personal data. The use of a DPIA is a legal requirement when what you plan to do with personal data is likely to result in a high risk to individuals’ rights and freedoms, particularly when new technologies are involved.

Further reading – ICO guidance

Principles

Data protection impact assessments

Further reading – European Data Protection Board

The European Data Protection Board (EDPB), which has replaced the Article 29 Working Party (WP29), includes representatives from the data protection authorities of each EU member state. It adopts guidelines for complying with the requirements of the GDPR. EDPB guidelines are l no longer directly relevant to the UK regime and are not binding under the UK regime. However, they may still provide helpful guidance on certain issues.

WP29 published the following guidelines which have been endorsed by the EDPB:

Guidelines on Transparency

Guidelines on Data Protection Impact Assessments (DPIA)

Can we put privacy information on our website for people to find?

The UKGDPR says that you must “provide” individuals with the necessary information in an “easily accessible form”. This applies equally if you collect personal data from the individual it relates to or if you obtain personal data from another source.

You can meet this requirement by putting the information on your website (this is often how organisations deliver privacy information), however you must proactively make individuals aware of this information and you need to give them an easy way to access it. Simply putting it on your website, in case people happen to look there, is not enough.

In practice, the way in which you provide privacy information to individuals will depend on the circ*mstances of how you collect or obtain their personal data. Some of the different techniques you can use to deliver this information are covered later in this guidance in the section ‘What methods can we use to provide privacy information?

When should we provide privacy information? (2024)

FAQs

When should we provide privacy information? ›

The use of a DPIA is a legal requirement when what you plan to do with personal data is likely to result in a high risk to individuals' rights and freedoms, particularly when new technologies are involved.

When should you provide privacy information to individuals? ›

You must provide privacy information to individuals at the time you collect their personal data from them.

Why should we have a privacy notice? ›

A privacy notice should identify who the data controller is, with contact details for its Data Protection Officer. It should also explain the purposes for which personal data are collected and used, how the data are used and disclosed, how long it is kept, and the controller's legal basis for processing.

Which of the following are reasons an organisation should provide a privacy notice? ›

9 Reasons Why You Need a Privacy Policy
  • 1.) It's the Law. ...
  • 2.) Third-Party Apps and Services Require It. ...
  • 3.) It Builds Trust With Your Customers. ...
  • 4.) It Helps Keep Your Customers Informed. ...
  • 5.) It Shows a Security-First Stance. ...
  • 6.) It Helps You Avoid Legal Battles and Fines. ...
  • 7.) It Has SEO and Marketing Benefits. ...
  • 8.)
Nov 20, 2023

Why is it important to be aware of data privacy? ›

Preserving Individual Autonomy: Data privacy empowers individuals to maintain control over their personal information. It allows them to decide how their data is collected, used, and shared. By respecting individuals' autonomy, data privacy ensures that personal information is not exploited or misused without consent.

What information should be kept private? ›

The most sensitive information to protect includes your bank account numbers, social security number, pin numbers, credit card numbers, and passwords.

What is the privacy Act on personal information? ›

The Privacy Act of 1974, 5 U.S.C. 552a, as amended, allows individuals to gain access to their own personal records subject to certain exemptions, and to seek correction or amendment of records maintained by Federal agencies that are inaccurate, incomplete, untimely, or irrelevant.

Who gives a privacy notice? ›

A privacy notice is a document that organisations give to individuals to explain how their personal data is processed.

What is the general Privacy Policy? ›

A Privacy Policy will describe the types of personal data you collect, how you collect the data, how you keep it safe, what you use it for, and if you share any of that personal information with other parties.

What are the three types of privacy notices? ›

There are three types of privacy notices defined in the regulations: an initial notice, an annual notice, and a revised notice. The regulation specifies when and to whom a bank is required to give each type of privacy notification. Let's look at the when and who for each type of privacy notice.

What should a privacy notice include? ›

How to write a privacy notice and what goes in it
  • your full contact details;
  • the types of personal data you collect;
  • where you got people's data from, if it wasn't from them;
  • why you have people's information and what you're doing with it;
  • your lawful basis and your legitimate interests where relevant;

What is required regarding the privacy notice? ›

The Privacy Notice must be written in plain language and must: Explain how the health plan may use and disclose an individual's PHI; • Describe the individual's rights with respect to his or her PHI; and • Summarize the health plan's legal duties with respect to the PHI.

What are disadvantages of privacy? ›

Too much privacy can result in failure to exchange ideas and to learn from others. For example: Suppose a person never discussed his or her thoughts with others. It would be difficult for the person to become aware of errors in his or her thinking.

What is an example of data privacy? ›

One example of data privacy is ensuring that sensitive data, such as financial information or medical records, is only accessed by authorized personnel. This can be achieved through access control measures, such as usernames and passwords, or biometric authentication. Encrypting data is another example of data privacy.

How do you ensure data privacy and security? ›

Performing strong identity verification to ensure devices are not compromised. Limiting the use of third-party software and browsing to unsafe websites. Encrypting data on the device to protect against device compromise and theft. Perform regular audits of endpoints to discover threats and security issues.

What are two of the purposes of the notice of privacy practice? ›

The notice must describe: How the Privacy Rule allows provider to use and disclose protected health information. It must also explain that your permission (authorization) is necessary before your health records are shared for any other reason.

What are the five 5 privacy issues an Organisation must manage through their privacy policies? ›

As a business owner, you may be required under the Privacy Act 1988 (Privacy Act) to protect your customers' personal information from:
  • theft.
  • misuse.
  • interference.
  • loss.
  • unauthorised access.
  • modification.
  • disclosure.
Mar 21, 2024

Which of the following must be included in a notice of privacy practices quizlet? ›

A notice of privacy practices should include a statement explaining that individuals may complain to the Secretary of the Department of Health and Human Services if they believe that their privacy rights have been violated.

Top Articles
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 6036

Rating: 4.1 / 5 (72 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.