Privacy notice for research participants: GDPR template (Article 13/14)
Every research project that processes personal data has to tell participants what happens to their data. This guide sets out what Articles 12 to 14 GDPR require, how a research privacy notice differs from the participant information sheet and the consent form, which research exemptions really apply to transparency, and the mistakes we see most often. A free Word template is included.
The short version
- Article 13 GDPR applies when you collect data from participants (interviews, surveys, tests). Article 14 applies when you obtain it from elsewhere (registries, other researchers, public sources).
- The notice must name the controller and the lawful basis, and give recipients, transfers, retention, rights and the right to complain. For research the hard parts are usually the lawful basis, retention and transfers.
- A signed consent form is often an ethical safeguard, not the GDPR lawful basis. Say clearly which basis you rely on.
- The research exemption in Article 14(5)(b) does not exist under Article 13. If you collect data from participants directly, you must inform them.
- Download the free research participant privacy notice template (Word), with a short first layer, a full notice, an Article 14 variant and a completion checklist. A Finnish version of this guide is available: tietosuojaseloste ja tietosuojailmoitus.
Contents
- Article 13 or Article 14?
- What the notice must contain
- Lawful basis: consent, public task or legitimate interest
- Research exemptions that affect transparency
- How to write it: layers, language and timing
- A worked example
- Common mistakes
- Tools, vendors and transfers
- The template
- Sources
- About this page
1. Article 13 or Article 14?
The GDPR has two information duties, and research projects often trigger both.
- Article 13 applies "where personal data relating to a data subject are collected from the data subject". The information must be given at the time the data is obtained. Typical cases: interviews, focus groups, surveys, experiments, diaries, observation where participants know they are being recorded.
- Article 14 applies where data has not been obtained from the person. Typical cases: data from national registries, patient records, school records, a dataset shared by another research group, social media posts collected by scraping, or information participants give about third parties (for example, family members mentioned in an interview).
Under Article 14(3) the information must be given within a reasonable period and at the latest within one month, or earlier at the first communication with the person, or when the data is first disclosed to another recipient. The Article 29 Working Party's transparency guidelines (WP260 rev.01, endorsed by the EDPB) confirm that one month is the maximum in every case, and that controllers should still consider people's reasonable expectations when deciding the timing.
2. What the notice must contain
The table below lists the items from Articles 13 and 14. The right-hand column is what tends to need most thought in a research setting.
| Information | Art. 13 | Art. 14 | Research note |
|---|---|---|---|
| Identity and contact details of the controller (and representative) | 13(1)(a) | 14(1)(a) | Usually the university, not the researcher. Name joint controllers in consortium projects. |
| Contact details of the DPO | 13(1)(b) | 14(1)(b) | Give the DPO's functional address as well as the project contact. |
| Purposes and the legal basis | 13(1)(c) | 14(1)(c) | Describe the study's actual purpose. Name the Article 6 basis and, for special category data, the Article 9 condition. |
| Legitimate interests pursued, if Art. 6(1)(f) is used | 13(1)(d) | 14(2)(b) | Only for controllers that can rely on legitimate interests (see section 3). |
| Categories of personal data | Not required | 14(1)(d) | Required when data comes from elsewhere, because the person cannot know what was obtained. |
| Recipients or categories of recipients | 13(1)(e) | 14(1)(e) | Partner institutions, transcription and survey vendors, data repositories, journals receiving data. |
| Transfers to third countries and safeguards | 13(1)(f) | 14(1)(f) | Adequacy decision or other safeguard, and how to obtain a copy. |
| Storage period or criteria | 13(2)(a) | 14(2)(a) | Separate periods for consent records, raw recordings, pseudonymised data and archived data. |
| Rights of access, rectification, erasure, restriction, objection, portability | 13(2)(b) | 14(2)(c) | State any national research derogations that limit these rights, if you rely on them. |
| Right to withdraw consent, where consent is the basis | 13(2)(c) | 14(2)(d) | Explain what happens to data already collected. |
| Right to complain to a supervisory authority | 13(2)(d) | 14(2)(e) | Name the authority in the country where the university is established. |
| Whether providing data is required, and consequences of not providing it | 13(2)(e) | Not required | Participation in research is normally voluntary: say so. |
| Source of the data, and whether publicly accessible | Not required | 14(2)(f) | Name the registry, dataset or platform. |
| Automated decision-making, including profiling | 13(2)(f) | 14(2)(g) | Rare in research, but state it if it applies. |
If you later want to use the data for a different purpose, Articles 13(3) and 14(4) require you to inform people before that further processing starts.
3. Lawful basis: consent, public task or legitimate interest
This is the section that most often goes wrong. Research ethics and data protection both use the word "consent", but they mean different things.
The EDPB's Guidelines 05/2020 on consent say that when consent is the legal basis for research, it should be distinguished from consent requirements that serve as "an ethical standard or procedural obligation". The same guidelines note that the GDPR does not limit research to consent: with appropriate safeguards, other bases such as Article 6(1)(e) or (f) "may be available", and Article 9(2)(j) can apply to special category data.
- Task in the public interest (Article 6(1)(e)). Common at public universities whose research mandate is set in law. The UK Health Research Authority's patient leaflet, for example, explains that UK universities and the NHS use data for research as "a task in the public interest". In Sweden, Stockholm University describes Article 6(1)(e) as its most common legal basis. Article 6(3) requires that basis to be laid down in Union or member state law.
- Consent (Article 6(1)(a)). Possible, but the EDPB stresses that withdrawal must be possible at any time and that there is no research exemption from this: on withdrawal the controller must in principle delete the data if it wishes to continue the research. The EDPB also notes that Recital 33 allows consent to "certain areas of scientific research" only as a limited exception where purposes cannot be specified at the outset.
- Legitimate interests (Article 6(1)(f)). Not available to public authorities for processing in the performance of their tasks (last subparagraph of Article 6(1)). Private universities, foundations and companies may be able to use it after a documented assessment. See our legitimate interest assessment template.
Validemic's analysis A useful sentence for many notices is: "You have given your consent to take part in this study. That consent is an ethical requirement. The legal basis under data protection law for processing your personal data is [basis]." It avoids the impression that withdrawing from the study automatically erases all data, when the actual consequences depend on the lawful basis and on national law. Always check the wording your institution and ethics committee expect.
4. Research exemptions that affect transparency
Researchers often assume that "research is exempt". For transparency, the exemptions are narrower than that.
No research exemption under Article 13
Article 13(4) lifts the duty only where and insofar as the person "already has the information". WP260 points out that there are no comparable exemptions under Article 13 to the ones in Article 14(5), and that impossibility or disproportionate effort must be directly connected to the fact that the data was not obtained from the person. If you interview someone, you can inform them.
Article 14(5)(b): impossible, disproportionate or seriously impairing
When data comes from elsewhere, Article 14(5)(b) allows an exception where informing people proves impossible, would involve a disproportionate effort (in particular for research with Article 89(1) safeguards), or would make the objectives impossible or seriously impair them. WP260 adds several conditions:
- The exception should not be routinely relied on outside archiving, research and statistics.
- The controller should carry out and document a balancing exercise: the effort of informing people against the impact on them of not being informed. Recital 62 points to the number of people, the age of the data and the safeguards adopted.
- Making the information publicly available, for example on a project website, is a measure the controller must always take. Other measures may include a DPIA, pseudonymisation, minimisation and strong security.
- The "seriously impair" limb requires the controller to show that providing the information alone would nullify the objectives of the processing.
Article 89 safeguards and national derogations
Article 89(1) requires safeguards for research, in particular data minimisation, and says that if the purpose can be achieved without identifying people, it must be. Article 89(2) lets Union or member state law limit the rights of access, rectification, restriction and objection for research, subject to conditions. Those derogations come from national law, so the notice should only mention limits that your national law actually provides. The Finnish version of this guide shows how one country's data protection act does this.
5. How to write it: layers, language and timing
Article 12(1) requires information in a "concise, transparent, intelligible and easily accessible form, using clear and plain language". WP260 gives practical rules that matter for research:
- Layering. WP260 recommends a first layer containing the purposes, the identity of the controller and the data subject's rights, plus the processing with most impact or that could surprise people. For research, a short data protection box in the information sheet works well as the first layer, with a link or appendix for the full notice.
- No vague qualifiers. WP260 says words such as "may", "might", "some", "often" and "possible" should be avoided. "Your data may be shared with partners" tells participants nothing.
- Specific retention. According to WP260 it is not sufficient to say that data will be kept "as long as necessary". Give periods per data category or the criteria used.
- Name the countries. WP260 says information on transfers should be as meaningful as possible, which generally means naming the third countries.
- Children and other groups. Article 12(1) requires particular care for information addressed to children. Write a separate version for each audience where needed, for example pupils and their parents.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
6. A worked example
The example below is an illustration written by Validemic, not a statement about any real study. Values in square brackets are placeholders.
| Study | Interviews with secondary school teachers about workload, audio-recorded and transcribed. |
|---|---|
| Controller | [University name, address]. DPO: [dpo@university.example]. |
| Purpose | To understand how teachers experience workload after a curriculum reform, for publication in academic journals and a report to [funder]. |
| Lawful basis | Article 6(1)(e) GDPR, task in the public interest, based on [national higher education law]. Consent to take part is an ethical requirement, not the legal basis. |
| Data | Name and email (for scheduling and consent records); audio recording; transcript; job title and school type. No special category data is requested; if mentioned, it is removed from the transcript. |
| Recipients | The research team; [transcription service] as processor under a data processing agreement; [partner university] as joint controller under an arrangement available on request. |
| Transfers | None. [Or: the transcription service's subprocessor in [country]; safeguard: [adequacy decision / standard contractual clauses], copy available from the DPO.] |
| Retention | Audio deleted after the transcript is checked, at the latest [X months] after the interview. Contact details deleted at the end of the project ([date]). Pseudonymised transcripts kept for [X years] for verification, then [archived in [repository] / deleted] in line with [policy or archives rules]. |
| Rights | Access, rectification, erasure, restriction and objection under Articles 15 to 21, subject to [any national research derogation]. Complaints: [supervisory authority]. |
7. Common mistakes
- Naming the researcher as controller. In most universities the institution is the controller and the researcher acts on its behalf. Check your institution's policy.
- Mixing ethical and GDPR consent. Stating consent as the legal basis when the university in fact relies on public task, or the reverse.
- "May share with third parties". Vague recipients fail the WP260 test. Name categories precisely, and name processors where it matters to participants.
- Forgetting the tools. Survey platforms, transcription services, video conferencing and AI assistants are recipients. Their hosting and subprocessors decide the transfers section.
- One retention period for everything. Recordings, consent forms, pseudonymised data and archived datasets usually have different periods.
- Promising what you cannot deliver. "All data will be destroyed after the project" conflicts with archiving duties and data sharing plans. See our retention schedule guide.
- Silently relying on Article 14(5)(b). Without a documented balancing exercise and public information, the exception is hard to defend.
- Copying an old "register description". Pre-GDPR formats often miss the lawful basis, retention and complaint information.
8. Tools, vendors and transfers
The recipients and transfers sections can only be as accurate as your knowledge of the tools used. If a researcher records interviews in a cloud transcription service, the notice has to reflect where that service processes data and which subprocessors it uses. Our guide to GDPR for researchers using AI and cloud tools explains what to check, and the transfer mechanism tool helps identify the right safeguard to name. If the project involves monitoring, vulnerable participants or large-scale special category data, run the DPIA screening tool before finalising the notice, and make sure the project is recorded in your record of processing activities.
9. The template
The research participant privacy notice template is a Word document containing:
- Instructions on when Article 13 and Article 14 apply, timing, and layering.
- Part A: a short first layer to place in the participant information sheet.
- Part B: the full privacy notice, with every Article 13 item and alternative wording for public task, consent and legitimate interests.
- Part C: additional sections for data obtained from other sources (Article 14), including a record of any Article 14(5)(b) assessment.
- Part D: a completion checklist mapped to the articles.
The template follows the text of Articles 12 to 14 GDPR and WP260 rev.01 as read on 7 October 2026. National law, your ethics committee and your institution's policies may require more or different wording. It is not legal advice.
Sources
- Regulation (EU) 2016/679 (GDPR), Articles 5, 6, 9, 12, 13, 14, 21 and 89 and Recitals 33 and 62, Official Journal text (retrieved 7 October 2026).
- Article 29 Working Party, Guidelines on transparency under Regulation 2016/679 (WP260 rev.01), endorsed by the EDPB, in particular paragraphs 13, 27, 28, 35, 36 and 61 to 65 and the Annex (retrieved 7 October 2026).
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679, section 7.2 (paragraphs 153 to 163) (retrieved 7 October 2026).
- EDPB Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR, version 1.0 for public consultation, paragraphs 98 and 99 (retrieved 7 October 2026).
- Health Research Authority: Patient data and research leaflet (retrieved 7 October 2026).
- Stockholm University: Personuppgiftsbehandling vid Stockholms universitet (retrieved 7 October 2026).
About this page
Sources checked on 7 October 2026. The legal text was read in its Official Journal version and the guidance in the published EDPB and Working Party documents; institutional examples come from the organisations' own pages. The worked example is an illustration written by Validemic, and statements labelled as Validemic's analysis are our interpretation. This page is not legal advice. If you spot an error, or something has changed, please contact us and we will correct it.
Frequently asked questions
Is the privacy notice the same as the participant information sheet?
Not necessarily. The information sheet explains the study so that people can decide whether to take part. The privacy notice gives the information that Articles 13 or 14 GDPR require. Many universities combine them, or put a short data protection section in the information sheet and link to a full notice. Either works if every required item reaches the participant at the right time.
Is consent the lawful basis if participants sign a consent form?
Not automatically. The EDPB distinguishes consent under the GDPR from consent that serves as an ethical standard or procedural obligation. Many public universities use task in the public interest (Article 6(1)(e)) as the lawful basis for research and treat the signed consent as an ethical safeguard. The notice must state which basis is actually used.
Can we skip the privacy notice for research?
Not when data is collected from participants themselves: Article 13(4) only exempts information the person already has. When data comes from elsewhere, Article 14(5)(b) allows an exception where informing people is impossible, would involve disproportionate effort or would seriously impair the research, but the controller must then protect their rights, including by making the information publicly available.
How long can research data be kept?
As long as necessary for the purpose, and longer only for archiving, research or statistics with Article 89(1) safeguards (Article 5(1)(e)). The notice must give the period or the criteria for setting it. WP29 says it is not sufficient to state generically that data will be kept as long as necessary.
When must the information be given if data is obtained from a registry or another researcher?
Within a reasonable period and at the latest within one month, or earlier at the first communication with the person or the first disclosure to another recipient (Article 14(3)).
Do we need to name the countries data is transferred to?
Article 13(1)(f) and 14(1)(f) require the fact of a transfer, whether there is an adequacy decision, and a reference to the safeguards. WP29 says that, in line with fairness, the information should generally name the third countries.