Skip to content
GDPR Recital 39 EN
LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this law. Contains: the full text of every article, recital and provision of this law. Everything links back to its source on overview.legal — legal information, not advice.

Recital 39 — lawful fair transparent personal data processing

In force — consolidated2016-05-04 · CELEX 02016R0679-20160504 · ELI ↗
Version history 2
  • 2016-05-04in force CELEX 02016R0679-20160504
  • 2016-04-27 CELEX 32016R0679

Any processing of personal data should be lawful and fair. It should be transparent to natural persons that personal data concerning them are collected, used, consulted or otherwise processed and to what extent the personal data are or will be processed. The principle of transparency requires that any information and communication relating to the processing of those personal data be easily accessible and easy to understand, and that clear and plain language be used. That principle concerns, in particular, information to the data subjects on the identity of the controller and the purposes of the processing and further information to ensure fair and transparent processing in respect of the natural persons concerned and their right to obtain confirmation and communication of personal data concerning them which are being processed. Natural persons should be made aware of risks, rules, safeguards and rights in relation to the processing of personal data and how to exercise their rights in relation to such processing. In particular, the specific purposes for which personal data are processed should be explicit and legitimate and determined at the time of the collection of the personal data. The personal data should be adequate, relevant and limited to what is necessary for the purposes for which they are processed. This requires, in particular, ensuring that the period for which the personal data are stored is limited to a strict minimum. Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means. In order to ensure that the personal data are not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review. Every reasonable step should be taken to ensure that personal data which are inaccurate are rectified or deleted. Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including for preventing unauthorised access to or use of personal data and the equipment used for the processing.

Related across sources

C-579/21 Proceedings brought by J.M In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland)… CJEU ·First Chamber Jun 22, 2023 Right of Access Right of Access Procedures Personal Data
C-757/22 Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V In a preliminary ruling requested by the German Federal Court of Justice (Bundesgerichtshof), the Court of Justice of the European Union interpreted Article 80(2) GDPR in the… CJEU ·Fourth Chamber Jul 11, 2024 Personal Data Controllers Processors
C-203/22 CK v Magistrat der Stadt Wien In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien… CJEU ·First Chamber Feb 27, 2025 Profiling Automated Decision-Making Marketing
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… CJEU ·First Chamber Jan 12, 2023 Right of Access Personal Data Right of Access Procedures
W 108 2284491-1 The data subject visited a website operated by a media company (the controller) Upon opening the website a cookie banner showed up. This cookie banner was designed in such a way that a reject button was “hidden” in a second layer. The cookie banner’s first… BVwG - W 108 2284491-1 ·Federal Administrative Court Jul 31, 2024 Consent Personal Data Supervisory Authorities