← All GDPR articles

Art.13

Information to be provided where data collected from the data subject

Mandatory disclosures when collecting personal data directly — identity of controller, processing purposes, legal basis, retention period, data subject rights, and cross-border transfer safeguards.

Why it matters for SaaS exits

Art.13 is the most frequently violated article in SaaS — most privacy policies are incomplete. Buyers' lawyers run an Art.13 checklist: does the policy state the legal basis? Does it list third-country transfers? Does it mention retention periods? A policy missing 3+ Art.13 items is a red flag that the seller hasn't done a proper privacy audit.

What we scan for

We scan the privacy policy for 7 mandatory Art.13 disclosures: controller identity, contact/DPO, processing purposes, legal basis, third-party recipients, retention period, data subject rights. Each missing item is a separate finding.

Automated checks (0)

No automated checks map to this article yet.

Buyer due-diligence checklist

  • Does the privacy policy state the controller's identity and contact?
  • Does it list all third-party processors (analytics, email, payments)?
  • Does it mention data retention periods (not just 'as long as necessary')?
  • Does it explain cross-border transfer safeguards (SCCs, adequacy decisions)?
  • Does it tell users their rights (access, erasure, portability)?

Run this scan on your site

See exactly where your site stands on Art.13 before a buyer asks.

Scan free →