Article 13 requires that the privacy notice should include the following information:
- the identity and the contact details of the controller
- the contact details of the data protection officer
- the purposes and legal basis for the processing
- where the processing is based on legitimate interests, details of what these are
- the recipients or categories of recipients of the personal data
- details of any transfer to a third country and details of the safeguards and the means by which to obtain a copy of them or where they have been made available
- the retention periods or the criteria used to determine that period
- details on rights of access to and rectification/deletion of personal data. Rights to object to processing and the right to data portability
- if processing is based on consent, the right to withdraw consent
- the right to lodge a complaint with the supervisory authority
- details on whether the data subject is obliged to provide the personal data and the consequences of failure to provide it
- details of any automated decision making, including details of the logic used and potential consequences for the individual