Obligation to provide information as part of the responsibility principle
Which information should the controller provide ?
The level of information to be provided depends on whether information is obtained from the registered individual himself or from another person:
What needs to be informed? | Information is obtained from the registered | Information is obtained from others |
Name and contact details of the controller and the data protection officer | X | X |
Purpose of processing and permission for processing | X | X |
Legitimate interests (if processing is based on that source) | X | X |
Types of personal data | X | |
Recipients | X | X |
Mediation to third countries and precautions | X | X |
Shelf life | X | X |
Information on the rights of individuals | X | X |
Revocation of approval, if applicable | X | X |
Right to lodge a complaint with the Data Protection Authority | X | X |
Where the information comes from | X | |
Obligation to provide information under law or contract | X | |
Automatic decision-making | X | X |