The timing depends on where the data came from. If it comes directly from the person, organisations should provide the information at the same time. If it comes from elsewhere, they should do so within a reasonable period and no later than one month. If they plan to use the data for communication or disclosure, they must tell people at the first communication or first disclosure.
When people give organisations their personal information directly, the timing is immediate because the information is being collected from the individual at that point. When the information comes from another source, the duty shifts to a later but still prompt notification window, with additional timing triggers if the organisation plans to use the data for communication or disclosure.
When the duty to inform is triggered
The key distinction is the source of the data. Direct collection normally means the person is interacting with the organisation, so the explanation of how their information will be used should travel with the collection itself. Indirect collection creates more room for delay, but not much: the organisation still needs to communicate the required information within a reasonable period and should not wait beyond one month.
That timing rule is designed to make privacy information usable, not just technically compliant. If people are told long after data was gathered, they lose the chance to understand the purpose, challenge the collection, or adjust their expectations before the information starts circulating inside the organisation.
How communication and disclosure change the timing
Some uses create a separate deadline because they are the first point at which the individual may reasonably learn that the organisation has that data. If the organisation intends to use the information for communication, it must provide the notice at the first communication. If the organisation intends to disclose the information to someone else, the notice must be given at the first disclosure.
Those triggers matter because they prevent organisations from treating privacy information as a back-office exercise. The disclosure or communication itself is often the moment when the individual experiences the processing in practice, so the timing of the notice has to match that operational reality.
In practice, the organisation should map its collection paths and downstream uses before deciding when the notice is due. A direct form submission, a referral from another source, and a planned disclosure each create a different timing obligation, even if the underlying personal information is the same.
What good notice timing looks like in practice
Good practice is to tie the privacy notice to the business process that first captures or uses the data, rather than leaving it to a separate compliance workflow. That means the notice should be embedded in intake, onboarding, or first-use workflows so staff do not need to remember a later manual step.
It also helps to keep records of which timing rule applied to each data set. If the source was indirect, the organisation should be able to show when the reasonable-period clock started and why the final notice date was still within the permitted window. If the first-use trigger applied, the record should show the first communication or disclosure event.
Where notices are layered or long, the practical test is whether the person gets the essential information at the moment it matters. A technically complete notice that arrives too late is usually worse than a shorter notice delivered on time.
Risk and Threat Considerations
Late notice creates privacy exposure because people may not know their information is being processed until after it has already been used, shared, or acted on. That can undermine trust, increase complaint handling, and create avoidable regulatory risk where the organisation cannot show that timing obligations were built into the process.
Failure mechanism: The organisation separates data collection from privacy notification, or lets a downstream team trigger disclosure without confirming that the notice deadline has been met. In indirect collection cases, this often happens when ownership of the data source is unclear or when the first communication event is not logged.
Impact: People receive information too late to understand the use of their data, and the organisation may be unable to prove that it met the relevant timing rule. That can lead to compliance findings, remediation work, and a wider loss of confidence in how personal information is handled.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
GDPR provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art. 14 — Information to be provided where personal data have not been obtained from the data subject | Sets the timing rule for indirect collection of personal data. |
| Art. 13 — Information to be provided where personal data are collected from the data subject | Requires notice at the time personal data is collected directly from the person. | |
| Art. 12 — Transparent information, communication and modalities for the exercise of the rights of the data subject | Supports clear, timely communication of privacy information in an intelligible form. | |
| Recommendation — Provide the required information within one month or at first disclosure/communication where Article 14 applies. Present the privacy information at the point of direct collection under Article 13. Deliver privacy information in a clear, timely, and accessible way that people can actually use. | ||
Practitioner Guidance
What to verify: Confirm the collection path before deciding on timing, because direct collection, indirect collection, first communication, and first disclosure can all produce different deadlines. The common failure is assuming that one privacy notice process fits every intake route.
Decision rule: If the data comes from the person, the notice belongs with the collection step; if it comes from elsewhere, set a hard internal deadline well before one month and track the first disclosure or communication separately. That makes the timing rule operational rather than aspirational.
Practitioner takeaway: The real control is not just having a privacy notice, but making sure the notice is triggered by the event that first makes the processing real for the individual.
Related resources from NHI Mgmt Group
- What do organisations get wrong when they use a personal Apple Account with a work email?
- What should people do when they want to share personal information online but still protect themselves?
- Why does PIPEDA require organisations to limit collection and use of personal information to identified purposes?
- How do organisations operationalise NHI ownership at scale?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org