General Data Protection Regulation

Article 14

Information to be provided where personal data have not been obtained from the data subject

1. Where personal data have not been obtained from the data subject, the controller shall provide the data subject with the following information:

2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing in respect of the data subject:

3. The controller shall provide the information referred to in paragraphs 1 and 2:

4. Where the controller intends to further process the personal data for a purpose other than that for which the personal data were obtained, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2.

5. Paragraphs 1 to 4 shall not apply where and insofar as:

Holdings

/
C-422/2418 Dec 2025

Integritetsskyddsmyndigheten v AB Storstockholms Lokaltrafik

When personal data are collected through a body camera worn by public-transport ticket inspectors, the information to be given to the data subjects is governed by Article 13 of Regulation (EU) 2016/679, not Article 14.

C-169/2328 Nov 2024

Nemzeti Adatvédelmi és Információszabadság Hatóság v UC

The exception in Article 14(5)(c) to the controller's duty to provide information to the data subject covers all personal data not collected directly from the data subject, whether the controller obtained those data from another person or generated them itself in performing its tasks.

C-169/2328 Nov 2024

Nemzeti Adatvédelmi és Információszabadság Hatóság v UC

In a complaint procedure, the supervisory authority may verify whether the Member State law applicable to the controller provides appropriate measures to protect the data subject's legitimate interests for the purposes of Article 14(5)(c). That verification does not cover whether the measures the controller must implement under Article 32 are appropriate to guarantee the security of personal-data processing.