Skip to content
Topic Contested in court

Transparency

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Openness about data processing activities

645 linked items 50 Laws104 Case Law159 Guidance178 Enforcement81 News

Overview

24 sources · Jul 23, 2026

Legal Framework

Transparency is established as a foundational data protection principle under Article 5(1)(a) GDPR, requiring that personal data be:

This principle operates not in isolation but as an enabling condition: without transparent information provision, other GDPR rights — including consent withdrawal and access — become functionally inaccessible. The EDPB has framed this in stark terms:

"If the controller does not provide accessible information, user control becomes illusory and consent will be an invalid basis for processing."
— EDPB Guidelines 05/2020 §62

In the employment context, Article 88(2) GDPR requires member states to adopt specific measures safeguarding the transparency of processing alongside data transfers and workplace monitoring — recognizing that power imbalances in employment demand heightened transparency obligations.

The AI Act extends transparency obligations beyond traditional data protection. Article 1(2)(d) establishes "harmonised transparency rules for certain AI systems," while Article 112(2)(b) provides for periodic review of which AI systems require additional transparency measures under Article 50 of the AI Act.

Key Developments

The CJEU's jurisprudence reveals that transparency is not an absolute value but must be balanced against competing fundamental rights. In Client Earth v. EFSA, the Court established a critical baseline:

"no automatic priority can be conferred on the objective of transparency over the right to protection of personal data"
— Client Earth ¶51

Yet the same case affirmed transparency's democratic function:

"The transparency of the process followed by a public authority for the adoption of a measure of that nature contributes to that authority acquiring greater legitimacy"
— Client Earth ¶56

The Schrems litigation exposed how transparency deficits in international transfer frameworks — specifically "structural shortcomings related to transparency and enforcement" — can invalidate entire adequacy mechanisms. The Schecke ruling grounded transparency obligations in the European Transparency Initiative, linking public fund disclosure to sound financial management.

Italian DPA enforcement illustrates practical failure modes: the Garante fined a health authority €20,000 for publishing personal data in a resolution, and €50,000 against an agency whose remote work policy lacked adequate transparency.

Status of the Debate

This topic is actively contested in court. The core tension — transparency versus data protection — has been addressed at the principle level in Client Earth, but operational boundaries remain unresolved. Courts diverge on how to weigh transparency interests when disclosure would expose personal data, particularly in institutional decision-making involving expert advisors with vested interests. No definitive court split is on record, but the balancing test lacks granular criteria. Resolution will likely require further CJEU guidance on proportionality assessment — specifically, whether the necessity test for transparency disclosure should require consideration of anonymization alternatives before raw personal data is exposed.

Practical Guidance

  • Implement layered information architecture: EDPB guidance endorses "layered and granular information" to reconcile completeness with accessibility — provide concise summaries with drill-down capability for full details.
  • Conduct transparency-by-design assessments: For each processing activity, document what information is provided, when, and through what channel, mapping directly to Article 5(1)(a) requirements.
  • Apply heightened transparency in employment contexts: Under Article 88(2), implement specific measures addressing workplace monitoring, data transfers within corporate groups, and employee dignity — go beyond generic privacy notices.
  • Assess AI system transparency obligations early: With the AI Act's harmonised transparency rules under Article 1(2)(d) and periodic review under Article 112(2)(b), classify AI systems proactively and prepare disclosure mechanisms for affected individuals.
  • Document the transparency–privacy balance: When transparency obligations intersect with personal data protection, record the proportionality analysis — including consideration of anonymization or partial disclosure — to demonstrate compliance with the Client Earth balancing standard.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
2018 Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) Guidelines on transparency EDPB Guidance EDPB Apr 2018 Transparency principle definition and requirements
why this is here
The transparency requirements in the GDPR apply irrespective of the legal basis for processing and throughout the life cycle of processing.

The document is the primary guidance on the transparency obligation, defining its scope and elements in detail.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 03/2022 Deceptive design patterns in social media platform interfaces: how to recognise and avoid them Guidelines ·EDPB Guidance EDPB Feb 2023 Transparency principle
why this is here
The principle of fair processing laid down in Article 5 (1) (a) GDPR is a starting point for an assessment of existence of deceptive design patterns.

The document explicitly connects transparency principles to the evaluation of deceptive design patterns.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 8/2020 targeting of social media users Guidelines ·EDPB Guidance EDPB Apr 2021 Transparency obligations
why this is here
From a data protection perspective, many risks relate to the possible lack of transparency and user control.

Transparency is a key concern but not the central focus.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 01/2022 data subject rights - Right of access Guidelines ·EDPB Guidance EDPB Apr 2023 Transparency in information provision
why this is here
The communication of data and other information about the processing must be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language.

The document requires transparency as a quality of access responses, but the main topic is access, not transparency generally.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 07/2022 certification as a tool for transfers Guidelines on certification and identifying certification criteria Guidelines ·EDPB Guidance EDPB Feb 2023 Information provision to data subjects
why this is here
Require that information on the processing activities should be provided to data subjects, including, where relevant, on the transfer of personal data to a third country

Certification criteria include transparency obligations toward data subjects regarding transfers, aligning with the transparency principle.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 05/2020 consent under Regulation 2016/679 Guidelines on consent Guidelines ·EDPB Guidance EDPB May 2020 informed consent and transparency
why this is here
informed and unambiguous indication of the data subject's wishes

Consent requires informed indication, which relates to transparency but is not the main focus.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Transparency as a principle
why this is here
each of the aforementioned principles

Transparency is one of the Article 5 principles, but the document does not specifically discuss transparency obligations.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 information obligations
why this is here
Since the controller will have to inform the data subject about all the purposes of the processing -including any processing following the aforementioned operations -when seeking consent

Transparency is touched upon only as a corollary of consent requirements, not as an independent principle or detailed obligation.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 159 Guidance · all 104 Case Law · all 50 Laws · all 178 Enforcement · all 72 Literature · all 81 News