STARTUPS, LEARN HOW TO INFORM YOUR USERS!
Informing data subjects is mandatory if your startup processes personal data. The GDPR requires clear and precise information. How do I inform the people whose personal data I process? What information do I need to pass on?
1. WHAT OBLIGATIONS DOES THE GDPR IMPOSE?
Pursuant to Articles 13 (direct collection) and 14 (indirect collection) of the GDPR, the data controller has an obligation to inform data subjects of the processing(s) carried out on their personal data when such data is collected directly from the data subject or when the data is collected indirectly (example: public data or on social networks).
2. WHAT INFORMATION MUST THE COMPANY PASS ON TO THE PERSONS CONCERNED?
Pursuant to the GDPR, the information that must appear within an information notice is as follows:
- Identity and contact details of the data controller
- Where applicable, identity and contact details of the data controller’s representative
- If applicable, contact details of the Data Protection Officer (“DPO”)
- Purposes of processing
- Legal basis for processing (consent, performance of a contract, compliance with a legal obligation, etc.)
- Whether the collection of personal data is mandatory or optional and the consequences for the individual in the event of failure to provide data
- Where applicable, the legitimate interests of the controller or third party, if the processing is necessary for the purposes of those legitimate interests.
- Recipients or categories of recipients of personal data, if any
- Details of data transfers to third countries and associated guarantees
- Length of time personal data is kept, or criteria for determining this length of time
- Mention of each of the rights of data subjects (access, rectification, erasure, limitation of processing, opposition and portability, etc.).
- Right to withdraw consent at any time, if applicable
- Mention of the right to lodge a complaint with a supervisory authority
- Mention of automated decision-making, if any, including profiling
- In the case of indirect data collection: categories and source of data collected
Warning : Startups processing the personal data of individuals located in France: beware of the application of article 116 of the French Data Protection Act. This article imposes an information notice on the bottom of forms and questionnaires. This information, often found below contact forms on websites, must specify :
- whether answers are mandatory or optional;
- the identity of the data controller and, where applicable, that of its representative;
- the purpose(s) of the processing for which the data is intended;
- the rights of data subjects (e.g., the right to access, rectify and delete their personal data).