Skip to content
Legiscope
Menu
Data Privacy

GDPR Article 14: Notice Content, Timing and Four Exceptions

Article 14 explained: indirectly collected data, first communication or disclosure, the one-month backstop, source information and four exceptions.

In one sentence. GDPR Article 14 governs the privacy notice when personal data is obtained from a source other than the data subject — data brokers, public registers, partners, lead enrichment, scraped sources. The information items mirror Article 13, but the timing is different: within a reasonable period and at the latest within one month of obtaining the data, OR at the moment of first communication to the data subject, whichever is earlier. Four lettered exceptions appear in Article 14(5). Earlier disclosure to another recipient can also advance the information deadline.

Article 14 creates a duty for the controller obtaining the data. A broker’s assurance that its list is lawful does not establish that the new controller has informed the people concerned. Map the source, intended use and first onward disclosure before starting the new processing.

Key takeaways

  • Public availability and a professional email address do not remove the information obligation. Check marketing-channel rules separately.

1. When Article 14 applies

Whenever personal data is collected from any source other than the data subject:

  • Data brokers (LeadIQ, ZoomInfo, Cognism, etc.)
  • Lead-enrichment APIs (Clearbit, Hunter.io)
  • Public registers (commercial register, LinkedIn-scraped data)
  • Partners sharing customer lists
  • Mailing list purchases
  • Scraped data
  • Data inherited from acquired companies
  • Data about a person supplied by someone else within an organisation

If your processing combines direct + indirect collection (most B2B SaaS), both Articles 13 and 14 apply — to different data flows.

2. Information items (Article 14(1)-(2))

The following checklist groups the information required by Article 14(1)–(2). Apply conditional items where relevant, including representative details, safeguards and meaningful information about qualifying automated decisions:

# Item Article
1 Controller identity/contact and representative where applicable 14(1)(a)
2 DPO contact if designated 14(1)(b)
3 Purposes and lawful basis 14(1)©
4 Categories of personal data (added vs Article 13) 14(1)(d)
5 Recipients 14(1)(e)
6 International transfers + safeguards 14(1)(f)
7 Storage period or criteria used to determine it 14(2)(a)
8 Legitimate interests pursued (if applicable) 14(2)(b)
9 Rights (access, rectification, erasure, etc.) 14(2)©
10 Right to withdraw consent 14(2)(d)
11 Right to lodge complaint with DPA 14(2)(e)
12 From which source the data originates, including public sources (added vs Article 13) 14(2)(f)
13 Qualifying automated decisions, meaningful logic information, significance and envisaged consequences 14(2)(g)

The two key additions vs Article 13: categories of data and source of data.

3. Timing (Article 14(3))

The notice must be provided:

  • Within a reasonable period after obtaining the data
  • At the latest within one month, OR
  • At the time of first communication with the data subject (if earlier), OR
  • At the time of first disclosure to another recipient (if earlier)

Common practice: send a “transparency email” within one month of obtaining the data, OR include the notice in the first marketing email.

Critical: the deadline is from when YOU obtained the data, not from when the data subject becomes a customer. A vendor who scraped emails in January and emails them in March is already late.

4. The four exceptions (Article 14(5))

Article 14(5) lifts the obligation if:

Exemption Practical scope
(a) Data subject already has the information Narrow — must be provable
(b) Information is impossible, entails disproportionate effort, or would make the specified processing objectives impossible or seriously impair them Assess the actual conditions and appropriate safeguards; this is not a blanket policy
© Obtaining or disclosure is expressly laid down by applicable EU/Member State law The law must provide appropriate measures protecting legitimate interests
(d) Data must remain confidential under professional secrecy regulated by EU/Member State law Identify the actual statutory secrecy obligation

The most common is (b) disproportionate effort. The EDPB requires:

  • Number of data subjects affected
  • Age of the data
  • Appropriate safeguards (e.g., publication on a website where data subjects can find the notice)
  • The CJEU and EDPB have rejected blanket invocations — each batch of data needs assessment

5. B2B prospecting and source checks

An Article 14 notice does not make an otherwise unlawful marketing campaign lawful. Assess the Article 6 basis, the fairness of collection and the national rules applying to the communication channel. Where consent is required for an email or tracking operation, a legitimate-interest assessment cannot replace it.

Record the named supplier, the acquisition date, the categories delivered and the evidence received about collection. Test whether a sample individual could understand why your organisation now has their data. Check the right to object, especially the unconditional stop rule for direct marketing, and ensure suppression instructions reach the teams sending messages.

6. The source of data requirement

Article 14(2)(f) requires information about the source and whether it was publicly accessible. Give the specific source where possible. If several sources were combined and an individual source cannot be identified, explain the situation and provide meaningful source information rather than using an unexplained reference to partners.

Public availability does not remove transparency duties, but it does not make every reuse automatically unlawful either. Determine the actual source, collection context, lawful basis and safeguards. The transparency guidelines WP260rev.01 address both source disclosure and the timing rules.

7. Privacy notice template for Article 14 scenarios

We obtained your data from [Specific Source — name and type]. We process it
because [purpose] under our [lawful basis — typically legitimate interest
with documented LIA].

Categories of data we hold: [name, professional email, employer, role,
LinkedIn URL, etc.]

You can:
- Request access to your data: privacy@company.com
- Object to our processing: [one-click link]
- Lodge a complaint with the CNIL: cnil.fr/plaintes

Retention: [period]. International transfers: [details + safeguards].
Full notice: [link to layer 2].

8. A hypothetical timing decision

A company receives a professional contact list on 3 September. It plans its first direct message on 9 September and a disclosure to a service partner on 7 September. Assuming Article 14 applies and no exception is justified, the first disclosure is the earlier relevant event. The company cannot wait until the end of the general one-month period or until the first marketing email.

The operational file should record all three dates, the chosen notice route and the version delivered. If the first disclosure is postponed, review the schedule against the reasonable-period requirement as well as the one-month maximum. The maximum is a backstop, not a standard waiting period for every source.

If the company obtains the same person’s data later from another source, check whether the person already has all the relevant information. A previous notice about a different controller, purpose or data category is not proof that Article 14(5)(a) applies to the new situation.

9. Practical implementation

For organizations that obtain data from third parties:

  • ☐ Inventory all third-party data sources in the record of processing activities
  • ☐ Article 14 notice prepared per source
  • ☐ Notice delivered within one month OR at first communication
  • ☐ Source named specifically (not “partners”)
  • ☐ Disproportionate-effort exemption assessed per batch (if invoked)
  • ☐ Right to object included with one-click mechanism
  • ☐ Notice version and delivery evidence retained under a justified evidence-retention rule

10. An exception assessment that can be reviewed

For Article 14(5)(a), identify the exact information already provided and how the controller knows the person has it. A general privacy policy on a supplier’s website is not enough by itself. For paragraph (b), specify the practical obstacle, assess its scale and explain why alternative means of informing people do not solve it. Cost or inconvenience should not be turned into a universal exemption.

Where paragraph (b) applies, appropriate measures must protect people’s rights and legitimate interests, including making the information publicly available. Record where it is published, how people could realistically find it and what further safeguards the processing needs. For paragraphs © and (d), identify the applicable law and its actual conditions rather than relying on a contractual confidentiality clause.

Assign a review trigger: a new contact channel, a changed source, a different purpose or better identifying information may change the assessment. Keep the exception analysis with the relevant processing record and give the operational team a clear instruction about what may proceed.

For related drafting work, use the Article 13 guide, Article 12 communication guide, information-notice guide and legitimate-interest assessment guide. The controlling legal source is Article 14 GDPR; the CNIL publication of Chapter III also reproduces the provision.

Conclusion

Article 14 requires a specific notice assessment when a B2B vendor obtains personal data indirectly. The duty doesn’t end with the upstream source’s compliance — your acquisition triggers a fresh obligation. Build the notice + delivery workflow as part of every data-acquisition process; assess the disproportionate-effort exemption per batch with documentation, not as a blanket excuse.

FAQ

When does GDPR Article 14 apply?

Whenever personal data is obtained from a source other than the data subject: data brokers, public registers, partners, lead-enrichment APIs, scraped sources, acquired company data, etc.

What’s the deadline to provide Article 14 information?

Within a reasonable period after obtaining the data, at the latest within one month, OR at the time of first communication with the data subject (if earlier), OR at the time of first disclosure to another recipient (if earlier). The deadline runs from when YOU obtained the data.

Can I invoke “disproportionate effort” to skip Article 14?

Only after a documented assessment per Article 14(5)(b) considering: number of data subjects, age of data, appropriate safeguards. The EDPB rejects blanket invocations — each batch needs assessment, with proportionate compensating measures (e.g., notice on a website where data subjects can reasonably find it).

Do I need to name the source of the data?

Article 14(2)(f) requires information about the source, including whether it was public. Identify it specifically where possible; where combined sources cannot be disentangled, explain the situation and provide meaningful available detail.

Is B2B cold prospecting allowed under GDPR?

It depends on the source, purpose, channel and applicable national rules. Article 14 transparency, an appropriate lawful basis and effective objection handling are separate requirements. A notice alone is not permission to send unsolicited marketing.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

International transfers require the appropriate Chapter V route. Adequacy decisions, including the EU–US Data Privacy Framework for covered recipients, fall under Article 45. Standard Contractual…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — a useful reminder to examine whether the organisation supports the DPO’s actual tasks and…

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

For a regulated-industry DPO, that distinction is the whole decision. Consent is one lawful basis under Art. 6(1)(a) GDPR; a compliance program is everything around it.

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Audit: How to Map Your Website's Cookies

A cookie audit is the foundational step for any website's GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your…

March 28, 2026