Privacy notice
The statement in which an organisation tells people what personal data it collects, why, who it shares it with and what rights they have (GDPR Articles 13 and 14).
The GDPR lists what it must say, including the controller’s identity, the purposes and legal bases, the recipients, transfers outside the EU, how long data is kept and the rights people can exercise. A vendor’s privacy notice mostly covers its own processing as a controller, such as website visitors and account data; the DPA covers the data it processes for customers.
Source: GDPR Arts. 13–14 ↗
Related terms
ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.