Skip to main content

Written for the Person

The supplementary information describes how the organisation processes the person's own data, not only what its general privacy notice says.

Criterion
E13
Level
Level 2
Domain
Supplementary Information
Reflects
Article 12(1)

Intent

A general privacy notice describes how the organisation treats data in principle. The person asked what happened to their own.

How to test it

An assessor scores the criterion against a single response:

Score 2
The supplementary information describes how the organisation processes this person's data.
Score 1
The response combines general privacy notice text with some detail specific to the person.
Score 0
The response reproduces the general privacy notice and adds nothing about this person, or gives no supplementary information at all.

The law it reflects

This criterion reflects Article 12(1) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See E13 in context in the full standard.