← GDPR · Data subject rights
Art.14 — Information when data is not obtained from the data subject
Requirement
Where personal data is obtained from another source, the controller must provide the Article 13 information plus the categories of data and their source, within a reasonable period and at the latest within one month — or at first communication or first disclosure to another recipient, if earlier — unless an Article 14(5) exception applies.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| CCPA/CPRA | 1798.100(a)-(b) | Notice at collection | privacy-notice |
| CCPA/CPRA | 1798.100(d) | Contracts with service providers, contractors and third parties | third-party |
| CCPA/CPRA | 1798.130(a)(5) | Privacy policy content and annual update | privacy-notice |
| CCPA/CPRA | 1798.135 | "Do Not Sell or Share" and "Limit the Use" links | privacy-notice |
| SOC 2 | CC2.3 | External communication | privacy-notice |
| SOC 2 | CC9.2 | Vendor and business partner risk management | third-party |
| SOC 2 | P1.1 | Notice and communication of privacy commitments | privacy-notice |
| ISO 27001 | A.5.19 | Information security in supplier relationships | third-party |