Legislation in motion
Proposal: no information duty in clear, non data-intensive relationships (Article 13(4) GDPR)
- Date
- Status
- proposal
- Body
- Europese Commissie
- Reference
- COM(2025) 837 final, artikel 3, punt 5 (wijziging artikel 13, lid 4 AVG); ST 15698/25; 2025/0360 (COD)
What it is about
Controllers would not need to provide Article 13 information where data are collected in a clear and circumscribed relationship, the activity is not data-intensive and there are reasonable grounds to assume the data subject already has the controller's identity and contact details and the purposes. The exemption would not apply where data are transmitted to other recipients or a third country, automated decision-making including profiling is carried out or the processing is likely to result in a high risk within the meaning of Article 35. Recital 36 gives a craftsman and their clients, and associations and sports clubs, as examples. In Joint Opinion 2/2026 of 10 February 2026 the EDPB and EDPS support the direction but ask for sharper definitions of not data-intensive activity and clear and circumscribed relationship, removal of reasonable grounds to assume, and a right to receive the full information on request. As of 15 September 2026 this is still a proposal: the European Parliament committee vote has not taken place and the Council has no mandate yet.
What this means in practice
If adopted, small service providers such as a craftsman or a plumber could omit a privacy notice for simple customer contacts. As soon as you share data with other recipients, transfer it outside the EU, profile or carry out high risk processing, you would still have to inform. The Article 15 right of access remains. The threshold of not data-intensive is still unclear, and according to Recital 36 employment relationships do not qualify.
The GDPR articles concerned
Source: Raad van de EU, register (COM(2025) 837 final als ST 15698/25); EDPB-EDPS Joint Opinion 2/2026, par. 60 tot 64checked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Part of the file
Themes where this returns
The counterpart in the other law
Case law
- EDPS v SRB: pseudonymised data are not always personal data for everyone, but the information duty applies from collection
2025-09-04 · final, Hof van Justitie van de EU (Eerste kamer), Europese Toezichthouder voor gegevensbescherming (EDPS) tegen Gemeenschappelijke Afwikkelingsraad (SRB)
- SCHUFA: a credit score on which third parties draw strongly is automated decision-making
2023-12-07 · final, Hof van Justitie van de EU (Eerste kamer), OQ tegen Land Hessen, met SCHUFA Holding AG als interveniënt
Guidelines
- Guidelines on transparency under Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
2024-10-08 · adopted, European Data Protection Board (EDPB)
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Guidelines 1/2026 on processing of personal data for scientific research purposes
2026-04-15 · adopted, European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
- European Economic and Social Committee adopts opinion on the Digital Omnibus
2026-03-18 · final, Europees Economisch en Sociaal Comité
- European Central Bank issues opinion on the Digital Omnibus
2026-03-10 · final, Europese Centrale Bank
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
Enforcement and fines
- 10 million euro fine for Uber over unclear retention and transfer information, objection rejected
2023-12-11 · under appeal, Autoriteit Persoonsgegevens
- Dutch DPA fines Uber 824.99 million euros for automated driver deactivation
2026-08-21 · under appeal, Autoriteit Persoonsgegevens
- Netflix fined 4.75 million euros for failing to properly inform customers
2024-11-26 · under appeal, Autoriteit Persoonsgegevens
Legislation in motion6 of 17
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
2026-06-22 · under negotiation, Europees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)
- Committee of the Regions adopts opinion on the Digital Omnibus
2026-05-07 · final, Europees Comité van de Regio's