
ICO privacy notice: missing UK GDPR Art. 13/14 items
At a glance
UK-07MediumUK GDPR Arts. 13-14; maximum penalty under Art. 83(5)(b) and DPA 2018 s. 157
Peeky reads the privacy notice your site links to and notes which of the items UK GDPR Articles 13 and 14 list it covers, covers only in part, or leaves out.
Last checked against the source:
The rule
Article 13 of the UK GDPR applies “where personal data relating to a data subject are collected from the data subject”, and the controller must provide the information “at the time when personal data are obtained”. Paragraph 1 lists six items: the identity and contact details of the controller and any representative; the data protection officer’s contact details, where applicable; the purposes of the processing and its legal basis; the legitimate interests pursued, where that basis is used; the recipients or categories of recipients; and, where applicable, the intention to transfer data to a third country with the safeguards relied on and how to obtain a copy of them. Paragraph 2 adds the storage period or the criteria for it; the rights to access, rectification, erasure, restriction, objection and portability; the right to withdraw consent where consent is the basis; the right to complain; whether providing the data is a statutory or contractual requirement; and automated decision-making that is subject to the safeguards in Article 22C, with meaningful information about the logic involved.
The complaint items changed in 2026, and the UK text now differs from the EU text. Article 13(2)(ca), inserted from 19 June 2026, adds “the right to make a complaint to the controller under section 164A of the 2018 Act”. Article 13(2)(d) now refers to the right to make a complaint to “the Commission under section 165 of the 2018 Act”, with the wording in force from 30 September 2026. A notice written before those dates, or copied from an EU template, may only say “lodge a complaint with a supervisory authority”. The complaint route itself is read by UK-08.
Article 14 is the companion for data not obtained from the person: it asks for the categories of data and, in paragraph 2, the source, and requires the information within a reasonable period and at the latest one month after the data is obtained, at first communication or at first disclosure to another recipient, whichever comes first.
Article 12(1) governs delivery. The controller must provide the information “in a concise, transparent, intelligible and easily accessible form, using clear and plain language”.
The ICO’s guidance turns the articles into a checklist. For data collected from the person it lists the organisation’s name and contact details, the representative and data protection officer where there is one, the purposes, the lawful basis, legitimate interests, recipients, transfers, retention periods, the individual’s rights, consent withdrawal, the right to complain, the statutory or contractual position and automated decisions. On recipients it says to “be as specific as possible if you only tell people the categories of organisations”, and on sources to “name the individual source(s)”.
Maximum penalties sit in the upper tier. Article 83(5)(b) of the UK GDPR, which covers the rights of data subjects, sets a ceiling of £17,500,000 or 4% of total worldwide annual turnover, whichever is higher, and section 157 of the Data Protection Act 2018 sets the same “higher maximum amount”.
What PeekWell checks and how
UK-07 asks one question: does the privacy notice the site links to say what Articles 13 and 14 list? The method is the same as for EU-08. Only the rubric wording and the rules it is read against change.
The scan finds the privacy notice linked from the public pages it visited and fetches it. A language model reads the text and maps it to a twelve-item rubric, written with UK phrasing, and marks each item present, partial or missing with the sentence it relied on. Code scores the coverage. The items that carry the most signal are weighted highest.
The decision is made by code from that evidence. The model reads and quotes, and a partial mark always shows the sentence behind it. Severity starts at medium and is reported as corroboration, because the rubric needs judgment about wording.
The scan has limits, and the report says so. It reads the notice as written and cannot see what your systems actually collect, who really receives the data or how long it is kept, so it cannot say whether a notice is accurate. Mismatches between the notice and the site are the job of other checks, such as UK-06. It does not read your contracts, and a notice behind a sign-in or inside an app is outside what it sees. A Passed means the expected items were found on the pages scanned. It does not say the notice is complete in law.
Why it matters for a company
In the TikTok decision the ICO found that users, and particularly children, were not given clear information about how their data was collected, used and shared. The penalty was £12.7 million, and the ICO announced on 24 September 2026 that TikTok had withdrawn its appeal. The information failure was one of several findings.
The smaller-company record is thinner, and the case is not a typical one. Doorstep Dispensaree, a pharmacy, was penalised mainly for how it stored and destroyed paper records. Among the facts the First-tier Tribunal recorded was that the company “did not provide data subjects with the information required by Articles 13 and/or 14”, and it noted that the company accepted its privacy notice was inadequate. The tribunal cut the penalty from £275,000 to £92,000, and upheld the enforcement notice issued in December 2019. The tribunal recorded that the company accepted its data protection policies, particularly its privacy notice and its retention and destruction policies, were inadequate in August 2018, and found that its policies still did not fully comply as of September 2019. The Court of Appeal rejected the company’s further appeal in December 2024.
Notice gaps tend to surface when something else has already drawn the regulator’s attention, so they are cited alongside other findings. An enforcement notice can require the notice to be rewritten, as in the pharmacy’s case. And since mid-2026 an old complaints line or an EU law reference is an easy gap to leave.
Smaller companies and larger companies
The duty has no size threshold. A sole trader with a contact form and a platform with millions of users are both within Articles 13 and 14.
In a small company the notice is usually a template or a generator’s output, adapted once. The common gaps are the ones the UK text now makes easier to hit: a notice that still describes complaints only to a supervisory authority, no named recipients, a retention line that says “as long as necessary”, and an EU reference where the UK law applies. Nobody has the job of rereading the notice.
In a larger company the problem is spread across teams. Legal owns the purposes, marketing adds a tracker, and a new supplier changes the recipients without anyone updating the text. Articles 13 and 14 both apply, because the company collects some data directly and receives other data from partners, and the Article 14 source and timing items are easy to miss. When children use the service, Article 12 asks for language they can follow.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
TikTok
The ICO found that TikTok failed to give users clear information about how their data was being collected, used and shared, so users, particularly children, were unlikely to be able to make informed decisions. TikTok appealed, and the ICO announced on 24 September 2026 that TikTok had withdrawn its appeal.
Read the ICO (UK) publication about TikTok
Smaller companies
Doorstep Dispensaree Limited
A pharmacy supplying care homes. The First-tier Tribunal recorded that the company had not given people the information Articles 13 and 14 require, and that it accepted its privacy notice was inadequate. The penalty was imposed mainly for failures in how paper records were stored and destroyed. The tribunal upheld the enforcement notice on its data protection policies, and recorded the company's acceptance that its privacy notice was inadequate in August 2018.
Read the ICO (UK), First-tier Tribunal on appeal publication about Doorstep Dispensaree Limited
How to fix it
The steps below follow the ICO’s guidance, which says privacy information must be provided at the time the data is collected, or within a month where it comes from elsewhere, and in concise, plain language.
- Write down what you actually do with personal data. List each purpose, the data used, who receives it, where it goes and how long you keep it. The notice can only be as accurate as this list.
- Tick your notice against the Article 13 list. Check each item, from controller contact details to automated decisions. If you receive data from others, tick Article 14 as well, including the source and the categories of data.
- Update the complaint wording. Say that people can complain to you, and say how. Say that they can complain to the regulator, using the UK wording.
- Be specific. Tie each legal basis to a purpose, name the recipients or their categories as precisely as you can, and replace “as long as necessary” with a period or the rule you use to set one.
- Check the transfer wording. Name the countries data goes to and the safeguard relied on, using UK rather than EU terms.
- Link it where you collect. Put the notice on the form or checkout and in the footer. Where there are many organisations to describe, the ICO’s common issues page suggests a layered approach.
- Keep it current. When you add a supplier or a purpose, update the notice the same week.
- Re-scan. Run a scan again. Each missing or partial item shows the sentence behind it, so you can see what changed.
Whether a notice satisfies the ICO is a question for your legal adviser, and Peeky reports only what it reads.
Questions
What does Article 13 of the UK GDPR require in a privacy notice?
Information about who you are, why you use the data and on what legal basis, who receives it, any transfers abroad, how long you keep it, the rights people have, and how to complain. Article 13 applies when you collect data from the person. Since 19 June 2026 the list also includes the right to complain to you directly.
What should a privacy notice include?
The ICO's guidance lists the organisation's name and contact details, the purposes, the lawful basis, the recipients, any international transfers, retention periods, the individual's rights and the right to complain. It adds the data protection officer's details, legitimate interests, and details of automated decisions where those apply.
Is there an ICO privacy notice checklist?
Yes. The ICO's right to be informed guidance has a checklists section. Peeky's rubric follows the same articles, and marks each one present, partial or missing on the notice it reads.
Can I use an ICO privacy notice template?
A template can show which items to cover, but the text has to describe your own processing. The ICO says to be as specific as possible about recipients and sources. A template cannot know who your suppliers are or how long you keep each kind of data.
What is the difference between Article 13 and Article 14 in the UK?
Article 13 covers data you collect from the person. Article 14 covers data you got from somewhere else, and it requires you to say where it came from. For Article 14 data the ICO says to give the information within a reasonable period and no later than one month.
Filed with
The rule
UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law), Arts. 12, 13 and 14, as amended to 30 September 2026
Read the rule (UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law), Arts. 12, 13 and 14, as amended to 30 September 2026)Sources
- UK GDPR, Art. 13, as amended to 30 September 2026, legislation.gov.uk
- UK GDPR, Art. 14, as amended, legislation.gov.uk
- UK GDPR, Art. 12, as amended, legislation.gov.uk
- UK GDPR, Art. 83, as amended, legislation.gov.uk
- Data Protection Act 2018, s. 157 (maximum amount of penalty), legislation.gov.uk
- ICO, The right to be informed
- ICO, What privacy information should we provide?
- ICO, What common issues might come up in practice?
- ICO, TikTok withdraws two appeals in children's privacy action and accepts 12.7m fine, 24 September 2026
- First-tier Tribunal (General Regulatory Chamber), Doorstep Dispensaree Limited v The Information Commissioner, EA/2020/0065/V, decision dated 9 August 2021
- ICO, Court of Appeal rejects appeal against UK Information Commissioner's monetary penalty notice, December 2024
Last checked against the source:
For information only. Not legal advice.


