Skip to content
PeekWellThe Rulebook
Join now

Article 13 GDPR: privacy notice missing required items

At a glance

EU-08MediumGDPR Art. 13(1)-(2); Art. 14; fines under Art. 83(5)(b)

Peeky reads the privacy notice your site links to and notes which of the items Article 13 lists it covers, which it covers only in part, and which it leaves out.

Last checked against the source:

I need to fix thisI need the rule

The rule

Article 13 applies where personal data “are collected from the data subject”, which is what happens when a visitor fills in a contact form, creates an account or checks out. The controller must provide the information “at the time when personal data are obtained”. Paragraph 1 lists six items: the identity and contact details of the controller and any representative; the contact details of the data protection officer, where there is one; the purposes of the processing and the legal basis; the legitimate interests pursued, where that basis is used; the recipients or categories of recipients; and, where applicable, the intention to transfer data to a third country with the safeguards relied on. Paragraph 2 adds six more “necessary to ensure fair and transparent processing”: the storage period or the criteria for setting it; the rights of access, rectification, erasure, restriction, objection and portability; the right to withdraw consent, where consent is the basis; “the right to lodge a complaint with a supervisory authority”; whether providing the data is a statutory or contractual requirement and what follows if it is not provided; and the existence of automated decision-making, with meaningful information about the logic involved.

That is twelve lettered items, which is the rubric the scan uses. Paragraph 4 removes the duty “where and insofar as the data subject already has the information”, so a notice does not have to repeat what a person was already told.

Article 12(1) governs how the information is delivered. It must be given “in a concise, transparent, intelligible and easily accessible form, using clear and plain language”. A notice can contain every item and still fall short of this paragraph if it is hard to find or hard to read.

Article 14 is the companion for data “not obtained from the data subject”. It repeats most of the list, adds the categories of data and the source, and sets a deadline of at most one month. The UK article, UK-07, reads the UK text of both.

The Article 29 Working Party’s transparency guidelines set out what authorities look for. They say that “language qualifiers such as ‘may’, ‘might’, ‘some’, ‘often’ and ‘possible’ should also be avoided”, and give “We may use your personal data to develop new services” as an example of a purpose that is not clear enough. On retention they say it “is not sufficient for the data controller to generically state that personal data will be kept as long as necessary for the legitimate purposes of the processing”.

Enforcement has followed the same line. In the WhatsApp decision the Irish DPC, applying the Board’s binding decision, wrote that the information on Article 13(1)(c) “does not enable the reader, upon any objective review of the material, to receive the information prescribed”, because the notice pointed to every legal basis in Article 6(1) without tying them to purposes. It called the recipients and transfers information “generalised and vague” and “completely inadequate”, and it found the retention information “vague and misleading”. The decision lists fines of EUR 90 million for Article 5(1)(a), 30 million for Article 12, 30 million for Article 13 and 75 million for Article 14.

Penalties sit in the upper tier. Article 83(5)(b) covers “the data subjects’ rights pursuant to Articles 12 to 22”, with a ceiling of EUR 20 million or 4% of worldwide annual turnover, whichever is higher. The ceiling comes from Article 83(5)(b); the content list itself sits in Article 13.

What PeekWell checks and how

EU-08 asks one question: does the privacy notice the site links to say what Article 13 lists? The scan answers it from the text of the notice, not from what the company does.

The scan finds the privacy notice linked from the public pages it visited and fetches it. A language model reads the text and maps it to the twelve-item rubric. For each item it records present, partial or missing, with the sentence it relied on. Code then scores the coverage. Three items carry the most weight because they are the ones regulators tend to look at first: the right to complain to a regulator, the legal basis for each purpose, and the transfer mechanism.

The decision is made by code from that evidence. The model reads and quotes, and a partial mark always shows the sentence behind it. Severity starts at medium, because the rubric needs judgment about wording, and the report treats the finding as corroboration. The three first-filter items weigh most in the coverage score.

The scan has limits, and the report says so. It reads the notice as written. It cannot see what data your systems actually collect, who really receives it or how long it is kept, so it cannot say whether a notice is accurate. Those mismatches belong to other checks, such as EU-05 and EU-04. It does not read your contracts, and a notice that sits behind a sign-in or in a separate app is outside what it sees. A Passed means the expected items were found on the pages scanned. It does not say the notice is complete in law.

Why it matters for a company

Authorities have treated a thin notice as a problem on its own, and also as a first thing they check when a complaint arrives. The WhatsApp decision is the clearest example: the information on legal basis, recipients, transfers and retention was examined item by item, and the fines were split across Articles 5(1)(a), 12, 13 and 14.

Smaller companies appear in the record too. The Garante inspected Confalonieri’s website and recorded a privacy notice that cited rules no longer in force, and a cookie policy that cited repealed provisions and did not identify the recipients. It ordered the cookie banner reconfigured and the privacy notice supplemented with the cookie processing, and issued a warning, with no fine. In Romania, the ANSPDCP warned a company that did not show who operated its site and ordered the policy completed with the Article 13(1)(a) information. In the Romanian decision the policy was ordered completed; in the Italian one the notice was ordered supplemented for cookies.

A missing item is easy to see from outside, since the notice is public. In both smaller-company decisions the notice finding came together with a cookie finding, which is why EU-08 is often read alongside EU-01.

Smaller companies and larger companies

The duty has no size threshold. Article 13 applies to a sole trader with a contact form in the same way as to a listed group. What differs is how the gaps arise.

In a small company the notice is usually a template or a generator’s output, pasted in once and never revisited. It names no recipients because nobody listed them, it cites a law that has since changed, or it says nothing about retention. The Garante’s record of a privacy notice citing rules no longer in force, and of a cookie policy that cited repealed provisions and did not identify recipients, fits this pattern.

In a larger company the notice is long and has many authors. Legal writes the purposes, marketing adds a tracker, and a vendor change alters the recipients without anyone updating the text. The risk is vagueness: every legal basis listed, “may” in every sentence, the same rights described in three places. The WhatsApp decision criticised exactly this, including information on the right to withdraw consent set out in slightly different words in three areas of the Privacy Policy, and retention information scattered across sections and documents.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • WhatsApp Ireland Limited

    DPC (Ireland), 2021€225 million

    The DPC found that WhatsApp's information left it unable to tell which legal basis applied to which purpose (Article 13(1)(c)), that the legitimate interests, recipients and transfers were described in general terms, and that the retention information was vague. The decision records separate fines for Articles 5(1)(a), 12, 13 and 14, together with a reprimand and an order to bring the processing into compliance.

    Read the DPC (Ireland) publication about WhatsApp Ireland Limited

Smaller companies

  • Confalonieri S.r.l.

    Garante (Italy), 2025No fine (warning and order to comply)

    The Garante recorded that the privacy notice referred to data protection rules no longer in force and to the COVID-19 emergency, and that the cookie policy cited repealed provisions and did not identify the recipients of the data. It ordered the cookie banner reconfigured and the general privacy notice supplemented with the cookie processing, and issued a warning for the cookie and tracking handling. No fine.

    Read the Garante (Italy) publication about Confalonieri S.r.l.
  • Urban Home Development S.R.L.

    ANSPDCP (Romania), 202410,000 lei (cookie finding); warning (Article 13)

    The authority found that the website did not show the operator's identity, an Article 13(1)(a) item, and issued a warning under the GDPR for it. It ordered the privacy policy completed with the information Article 13(1)(a) requires. The 10,000 lei fine in the same decision was for cookies, under national law.

    Read the ANSPDCP (Romania) publication about Urban Home Development S.R.L.

How to fix it

The order of the work matters more than the wording tool. These steps follow Article 13 and the Working Party’s guidance on specific, plain language.

  1. Write down what you actually do with personal data. List each purpose, such as orders, newsletters, analytics and support, the data used for each, who receives it and where it goes. A notice can only be as accurate as this list.
  2. Match the notice to the twelve items. Open Article 13 and tick each item against your text, from controller contact details through to automated decisions.
  3. Tie each legal basis to a purpose. A table with purpose, basis and retention in each row is easier to read and to check than a paragraph that names every basis.
  4. Replace vague wording. Swap “may use your data to improve our services” for what you do. Replace “as long as necessary” with a period or the rule you use to set it.
  5. Name recipients and transfers. Name each processor or group of processors by category at least, and say which countries data goes to and what safeguard covers it.
  6. Make it easy to reach. Link the notice at the point where data is collected, such as a form or checkout, and from the footer of every page. Keep it in the language of the site.
  7. Keep it current. When you add a vendor or a purpose, update the notice the same week.
  8. Re-scan. Run a scan again and check the item list. Each missing or partial item shows the sentence behind it, so you can see what changed.

Whether a notice satisfies a given authority is a question for your legal adviser, and Peeky reports only what it reads.

Questions

What must a privacy notice include under Article 13 GDPR?

Twelve items, six in each of the first two paragraphs. Who you are, the purposes and legal basis, who receives the data, any transfers abroad, how long you keep it, the rights people have, the right to complain to a regulator, and whether giving the data is required.

Paragraph 1 covers the first six and paragraph 2 the rest. The rule lists them.

What is the difference between Article 13 and Article 14?

Article 13 applies when you collect data from the person. Article 14 applies when it came from somewhere else. The lists are close, but Article 14 adds the categories of data and where it came from, and it sets a deadline of one month at most.

Does a privacy notice have to name the legal basis for each purpose?

Yes, Article 13(1)(c) asks for the purposes and the legal basis for the processing. The Irish regulator found a notice short when it could not tell which basis went with which purpose. Listing every basis in one block does not do the job.

Can I use a free privacy notice template?

You can start from one, but the notice has to describe what your company actually does. A template tells you which items to cover. It cannot know your recipients, your transfers or your retention periods, so those parts have to be filled in with your own facts.

How does Peeky check a privacy notice?

Peeky finds the privacy notice linked from your public pages, reads it, and marks each of the twelve items as present, partial or missing, with the sentence it relied on. Code does the scoring. Peeky does not know what you do with data behind the scenes. How a scan works has the full path.

Filed with

The rule

GDPR (Regulation (EU) 2016/679), Arts. 12, 13 and 14, text as published at legislation.gov.uk (version as at 25 May 2018)

Read the rule (GDPR (Regulation (EU) 2016/679), Arts. 12, 13 and 14, text as published at legislation.gov.uk (version as at 25 May 2018))

A case

WhatsApp Ireland Limited

DPC (Ireland), 2021

Read the decision (WhatsApp Ireland Limited)

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. Regulation (EU) 2016/679, Art. 13 (version as at 25 May 2018), legislation.gov.uk
  2. Regulation (EU) 2016/679, Art. 12 (version as at 25 May 2018), legislation.gov.uk
  3. Regulation (EU) 2016/679, Art. 14 (version as at 25 May 2018), legislation.gov.uk
  4. Regulation (EU) 2016/679, Art. 83 (version as at 25 May 2018), legislation.gov.uk
  5. Article 29 Working Party, Guidelines on transparency under Regulation 2016/679 (WP260 rev.01), last revised and adopted 11 April 2018
  6. DPC (Ireland), Decision concerning WhatsApp Ireland Ltd, inquiry IN-18-12-2, dated 20 August 2021
  7. DPC (Ireland), WhatsApp Ireland Limited decision of 20 August 2021 (full text, as sent to the EDPB)
  8. Garante (Italy), Provvedimento del 4 giugno 2025 [10152729], Confalonieri S.r.l.
  9. ANSPDCP (Romania), press release of 27 May 2024 on Urban Home Development S.R.L.

Last checked against the source:

For information only. Not legal advice.