Skip to main content

Provide processed data information

Requirement#

The system must provide information about the personal data that it processes. Additionally, this information should be presented to the user before requesting their consent for its collection or processing.

Description#

Systems usually request information from their users, obtain it from third parties or collect it based on their interactions with the application. They should have a mechanism that allows users to find out about the following aspects of the personal information that they process:

  1. The purpose of the processing of the data.
  2. The categories of processed data.
  3. The actors who will have access to the information.
  4. If possible, the time for which the data will be managed/processed.
  5. The possibility to request erasure or rectification.
  6. If the data was obtained from a third party, information about the third party.

Furthermore, the data should be presented in a clear manner, in a structured format and using easily understandable language.

Exceptions#

  1. If the system is able to demonstrate that it is not possible to individually identify user based on the information collected from them, this requirement is not applicable.

  2. The processing of the personal information might have scientific, historical research or statistical purposes. If the system properly safeguards this information and if complying with this requirement seriously impairs these purposes, this requirement is not applicable.

  3. The processing of personal information might have archiving purposes in the public interest. If the system properly safeguards this information and if complying with this requirement seriously impairs these purposes, this requirement is not applicable.

References#