Endereço
Rio de Janeiro, Brasil
+55 21 99688-0164
+55 21 99688-0164

As Mark Twain once famously said:
“Anybody can have ideas – the difficulty is to express them without squandering a quire of paper on an idea that ought to be reduced to one glittering paragraph.”
Today, using clear and transparent communication has become a requirement in various national laws. In the United States for example, the Plain Writing Act of 2010 (signed on October 13, 2010) requires that federal agencies use clear communication that the public can understand and use.
An interesting case study is the concept of ‘Clear and Plain Language’ contained in the EU’s General Data Protection Regulation (GDPR). While there is no specific definition of these terms in EU law (indeed it may be argued that the GDPR itself unnecessarily complex in its wording), it is possible to look at the decisions of the EU courts and the national regulatory agencies to get an idea how these obligations are enforced in practice.
As discussed below, the EU legislature clearly intended to regulate the use of complex and unclear information by controllers of personal data and to reduce the use of legal jargon (or so called ‘legalese’) in communications between companies and their customers.
Plain language and the law – some background
Today plain language is often used as an approach to simplify the language used by lawyers and academics in the legal field (see, for example, the books written by authors like Bryan Garner on the subject). The goal of Plain Language is to help the reader find information, and also to understand it.
An example of a plain language project in the legal sector is Shawn Burton and his project at GE Aviation. In this process, together with his team, Burton set out to replace their unit’s seven excruciatingly complicated contracts with one that even a ‘high schooler’ could understand. It was claimed that the time to read these documents was reduced by 60% as a result of the project.
As the language we use has become increasingly digital, those in the legal industry are witnessing first-hand how communicating clearly can save them time and cost. In addition, other disciplines are tackling the challenge of making the legal world more accessible (such as information design, legal design and visual law).
Such areas apply techniques of delineating legal text units and hierarchy and seek new and creative ways for user access (e.g., through interface design, using timelines, summaries, lists or tables, etc.).
Critically, applying plain language to legal texts necessarily involves understanding the reader’s difficulty in terms of accessing such texts and tailoring the language used to their level of understanding (e.g., through assessing directness, avoiding ambiguity and wordiness, analysing the average number of syllables per word and sentence length).
Such considerations are also addressed by the GDPR drafters, as we discuss further below.
Clear and Plain Language’ in the GDPR
While there is some obvious overlap, the concept of ‘Clear and Plain Language’ in the GDPR is distinct from the general topic on plain language discussed above. While there are references to plain language type requirements in other EU legislation (for example in the e-Privacy Directive 2002 and the Directive on Unfair Terms in Consumer Contracts 1993), the wording in the GDPR is unique.
The term “Clear and Plain language” is mentioned 7 times in the GDPR (3 times within the main text and 4 times in the Preamble). Specifically, it is mentioned in the provisions dealing with:
(1) conditions for consent,
(2) transparent information and communication, and
(3) communication of a data breach to the data subject.
Let’s look at one example on Transparency requirements. Article 12(1) of the GDPR states:
“The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication under Articles 15 to 22 and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. The information shall be provided in writing, or by other means, including, where appropriate, by electronic means…”
The Article 12 requirement is also supported by the wording in the GDPR’s Preamble (in Points 39 and 58), which stress that “any information addressed to the public or data subject should be concise, easily accessible, and easy to understand, and using Clear and Plain Language”.
These sections again reiterate the special position of children in relation to such information (that is, in such communications with children, there is a requirement of using clear and plain language that the child can understand).
In a well-known judgement by the European Court of Justice concerning a large French supermarket chain, the French DPA (CNIL) found that the data controller had not complied with its obligations under Article 12 GDPR. Among various other violations (for example, here there was also a failure to provide mandatory information to the data subject), the CNIL found that the controller had breached the Article 12 requirements by spreading out key information over numerous webpages, and also because the information provided was unnecessarily long.
The authority expressly alluded to the fact that the text was not written in Plain and Clear language, since it used unclear and imprecise language (for more discussion on this case, see for example Brendan Quinn below).
Conclusion
From the above analysis, it is clear that the drafters of the GDPR wanted to stop the use of complex and unclear information and the use of legalese in communications between companies and their customers.
Unfortunately, there is no definition of the terms ‘Clear and Plain Language’ under EU law). However, it is possible to look at the decisions of the EU courts and different regulatory bodies for guidance of how these provisions are being enforced in practice. From the above example of the ruling by the CNIL, we can see that an assessment will consider both the type of language used (words, phrases, ambiguity etc.) and also how such language is presented to the reader (i.e., in this case, the information was spread over various documents making it inaccessible to the reader). We have also seen that children are afforded a special status under the law.
Following the GDPR, other jurisdictions have also made clear and transparent communication a requirement under their data protection laws.
In Brazil, for example, the national data protection law (LGPD) (which is inspired by the GDPR), aims to guarantee to data subjects the right to have “… clear, accurate and easily accessible information about the performance of the treatment and the respective treatment agents, observing commercial and industrial secrets” (LGPD – Lei Geral de Proteção de Dados Pessoais, Article 6, VI)
As a result of these provisions, companies must ensure that they communicate with their customers clearly and concisely, don’t leave substantial doubts or hide critical information (in a future post, we will specifically examine the topic of Transparency in Privacy Contracts).
Enjoyed this content? We hope it was useful. If you have any questions or comments about the topics raised please reach out to us. Also, if interested in our approach, please sign up for our newsletter to receive our monthly materials.