Art.13
Information to be provided where data collected from the data subject
Mandatory disclosures when collecting personal data directly — identity of controller, processing purposes, legal basis, retention period, data subject rights, and cross-border transfer safeguards.
Why it matters for SaaS exits
Art.13 is the most frequently violated article in SaaS — most privacy policies are incomplete. Buyers' lawyers run an Art.13 checklist: does the policy state the legal basis? Does it list third-country transfers? Does it mention retention periods? A policy missing 3+ Art.13 items is a red flag that the seller hasn't done a proper privacy audit.
What we scan for
We scan the privacy policy for 7 mandatory Art.13 disclosures: controller identity, contact/DPO, processing purposes, legal basis, third-party recipients, retention period, data subject rights. Each missing item is a separate finding.
Automated checks (0)
No automated checks map to this article yet.
Buyer due-diligence checklist
- ▸Does the privacy policy state the controller's identity and contact?
- ▸Does it list all third-party processors (analytics, email, payments)?
- ▸Does it mention data retention periods (not just 'as long as necessary')?
- ▸Does it explain cross-border transfer safeguards (SCCs, adequacy decisions)?
- ▸Does it tell users their rights (access, erasure, portability)?
Run this scan on your site
See exactly where your site stands on Art.13 before a buyer asks.
Scan free →