Skip to content
Legiscope
Menu
Data Privacy

How to Write a GDPR-Compliant Privacy Policy

Step-by-step guide to writing a GDPR-compliant privacy policy, covering mandatory content, transparency requirements, and common mistakes to avoid.

Also available in:Français·Deutsch

A GDPR privacy policy is far more than a legal formality tucked away in a website footer. It is the primary instrument through which organisations fulfil their transparency obligations under European data protection law. Articles 13 and 14 of the GDPR set out detailed requirements for the information that must be provided to data subjects, and failure to meet these requirements is one of the most frequent grounds for regulatory enforcement actions across the European Economic Area.

This guide walks through what a GDPR-compliant privacy policy must contain, how to structure it for clarity, and what pitfalls to avoid so your policy genuinely serves its legal purpose.

The Importance of Transparency Under the GDPR

Transparency is one of the core data protection principles enshrined in Article 5(1)(a) of the GDPR. It requires that personal data be processed lawfully, fairly, and in a transparent manner in relation to the data subject. Your privacy policy is the most visible expression of this principle.

In 2026, transparency is under the regulatory spotlight: the EDPB’s 2026 Coordinated Enforcement Framework specifically targets compliance with Articles 12-14, with 25 participating data protection authorities using questionnaires and/or investigations to assess whether privacy notices are genuinely informative rather than boilerplate disclosures.

The practical consequences of getting it wrong are significant. According to the EDPB’s transparency guidelines, a privacy policy that is unclear, incomplete, or difficult to find may itself constitute a breach of the regulation. Supervisory authorities have imposed fines specifically for transparency failures – the French CNIL fined Google EUR 50 million in 2019 partly because its privacy information was spread across multiple documents and required several clicks to access. The CNIL’s Google decision illustrates why the accessibility and specificity of information must be reviewed together.

What Must a GDPR Privacy Policy Contain?

Articles 13 and 14 of the GDPR prescribe the specific information that must be provided to data subjects. The requirements differ slightly depending on whether data is collected directly from the individual (Article 13) or obtained from a third party (Article 14).

Identity, contact details, and purposes

Your policy must clearly identify the data controller, and provide its contact details and those of its representative where applicable. Use details that enable people to identify and reach the responsible legal entity. If you have appointed a Data Protection Officer, their contact information must also be included. Our guide to the DPO definition and missions explains when this appointment is mandatory. For each processing activity, you must state both the specific purpose and the legal basis relied upon. The GDPR provides six legal bases, and simply listing them generically is not sufficient. If you rely on legitimate interest, you must also describe the legitimate interest pursued. If you rely on consent, you must explain how consent can be withdrawn.

Retention periods and data subject rights

The storage limitation principle requires that personal data be kept no longer than necessary for the stated purposes. Your privacy policy must specify the retention period for each category of data, or the criteria used to determine that period. Vague statements such as “we retain data as long as necessary” have been specifically criticised by supervisory authorities as non-compliant.

Your policy must also inform individuals of their rights under the GDPR, including applicable rights to restriction, portability and objection as well as the right of access, the right to erasure, the right to rectification, and the right to lodge a complaint with a supervisory authority. You should explain the procedure for exercising these rights, including how to submit a data subject access request.

International transfers and automated decisions

If you transfer personal data outside the EEA, you must disclose this fact and explain the existence or absence of an adequacy decision or, for relevant safeguarded transfers, refer to the safeguards such as Standard Contractual Clauses and explain how to obtain a copy or where they are available. According to the CNIL’s guidance on international transfers, this information must be specific enough for the data subject to understand the level of protection applied to their data.

Additionally, if your organisation uses automated decision-making, including profiling that produces legal or similarly significant effects, Article 13(2)(f) requires you to disclose this fact, provide meaningful information about the logic involved, and explain the significance and envisaged consequences for the data subject.

Choose the Correct Notice and Delivery Time

A website footer alone does not meet every information duty. Build a notice inventory for customers, applicants, staff, suppliers and other affected groups, then map each collection route:

Route Required timing and additional content
Person completes a signup form Article 13 information when the data is obtained; explain whether provision is statutory or contractual, whether it is required for a contract and the consequences of not providing it
Employer receives an applicant profile from a recruiter Article 14 information within a reasonable period, at most one month; if communicating earlier, at the first communication; if disclosing earlier, at the first disclosure
Information comes from a public directory Article 14 still needs assessment, including categories of data and source, and whether it was publicly accessible
An existing dataset will serve a new purpose Provide the further-purpose information before that processing under Article 13(3) or 14(4), and separately assess its lawfulness

Both articles require recipients or categories of recipients where applicable. Article 14 adds data categories and source information; it is not satisfied by copying a direct-collection notice without those details. Article 13(4) and Article 14(5) contain exceptions, but they differ. Document the particular exception and its conditions before relying on it. For example, public availability does not by itself exempt a controller from Article 14.

The notice provides information; it does not create consent. Avoid an “I agree to the privacy policy” checkbox that mixes acknowledgement with an optional consent request. If consent is the basis, present a separate, specific choice and retain evidence of it.

How Should You Structure the Policy for Clarity?

The GDPR requires that information be provided in a concise, transparent, intelligible, and easily accessible form, using clear and plain language. This is not a stylistic preference; it is a legal requirement under Article 12(1).

Practical formatting recommendations

  • Use layered notices. Consider a short summary layer with links to the full policy for each topic. The ICO’s privacy notice code of practice recommends this approach for complex processing environments.
  • Organise by purpose. Rather than listing all legal bases in one section and all data categories in another, group information by processing activity so readers can find the details most relevant to them.
  • Avoid legal jargon. Phrases like “legitimate interest pursuant to Article 6(1)(f)” are meaningless to most readers. Explain the concept in plain language, then reference the legal provision if needed.
  • Include a table of contents. For longer policies, a clickable table of contents significantly improves navigation.

Test the draft with someone unfamiliar with the service: can they find who receives their data, why it is used, how long it is retained and how to exercise a right? A short summary helps only if it leads clearly to the complete information rather than hiding material effects in later layers.

Common Mistakes That Undermine Compliance

Even organisations that invest effort in their privacy policy often fall into recurring traps that create compliance gaps.

Vague language and missing updates

Statements like “we may share your data with third parties for business purposes” fail the specificity test. You must identify the categories of recipients and the purposes for each sharing arrangement. The accountability principle requires you to demonstrate, with documentation, that your policy accurately reflects your actual processing activities.

A privacy policy is not a static document. When activities, recipients, retention or other relevant facts change, check whether the notice remains accurate and update it as needed. A new supplier within a correctly described recipient category may not require a named-supplier edit, but its actual uses and transfers still need assessment. Under Article 13(3), if you intend to process data for a purpose other than the one for which it was originally collected, you must inform the data subject before that further processing takes place.

How Does a Privacy Policy Fit into Broader GDPR Compliance?

A privacy policy does not operate in isolation. It is one component of a wider compliance framework that must be coherent and mutually reinforcing.

Your GDPR compliance checklist should include a periodic review of all information notices to ensure they remain accurate. A Data Protection Impact Assessment may identify new processing activities that require updates to your privacy policy. The internal processes you build to respond to data subject rights requests must be consistent with the procedures described in your policy.

The privacy by design principle also has a direct bearing on your policy: if data protection is embedded into the design of your systems and processes from the outset, your privacy policy will naturally be more accurate and easier to maintain because the underlying processing is better controlled and documented.

Steps to Take After Publishing

Publishing the policy is only the beginning. Ongoing management is essential to maintaining compliance.

Assign each notice an owner and review it when processing changes, with a periodic check suited to the service. Keep the version, effective date, affected audiences and delivery evidence. A notice update does not itself make a new purpose lawful or obtain fresh consent where needed.

Verify the Notice Against One Live Journey

For a contact form, compare the published notice with the actual fields, recipient inbox, CRM integration and retention setting. Ask the service owner to confirm each purpose and recipient, the legal owner to confirm the basis, and the operational owner to demonstrate deletion and rights handling. Then test the notice link before submission on mobile as well as desktop.

Record discrepancies in a short acceptance table: missing disclosure, underlying process owner, correction, and evidence. For example, a form that says “answer your enquiry” but also adds people to marketing needs a lawful marketing design and accurate information; adding broader words to the notice alone is insufficient. Preserve the notice version shown at the time so a later complaint can be assessed against what the person actually received.

FAQ

Does a privacy policy need to cover every processing activity?

People must receive the information required for the processing concerning them, subject to the relevant exceptions. You can use separate, linked notices for customers, staff or recruitment instead of putting every activity in one public website policy. Ensure each audience receives complete information at the applicable time.

A privacy policy and a cookie notice serve different legal requirements. Cookie consent is governed primarily by the ePrivacy Directive, which imposes specific consent obligations before placing non-essential cookies. While you can include cookie information within your privacy policy, most organisations find it clearer to maintain a separate cookie notice that links to the privacy policy for broader data processing details.

How often should a privacy policy be reviewed?

There is no fixed statutory frequency, but best practice is to review the policy at least once a year and after any material change to your processing activities, data recipients, or legal bases. The key test is whether the policy accurately reflects current processing at all times. An outdated policy that no longer matches your actual data practices creates both a transparency violation and an accountability gap.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

International transfers require the appropriate Chapter V route. Adequacy decisions, including the EU–US Data Privacy Framework for covered recipients, fall under Article 45. Standard Contractual…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — a useful reminder to examine whether the organisation supports the DPO’s actual tasks and…

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

Cassie (Syrenis) is positioned by its maker around consent and preference management, with publicly advertised ROPA and data-subject rights capabilities as well. If you are looking for an…

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Audit: How to Map Your Website's Cookies

A cookie audit is the foundational step for any website's GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your…

March 28, 2026