Business guide

GDPR Privacy Policy Requirements

GDPR Articles 13 and 14 require transparent privacy information at the point of collection — usually your website privacy policy and in-app notices.

Required elements (controller collecting directly — Art. 13)

  1. Identity and contact of controller; DPO contact if appointed
  2. Purposes and legal bases for each processing activity
  3. Legitimate interests pursued (if relying on legitimate interest)
  4. Recipients or categories of recipients
  5. International transfers and safeguards (SCCs, adequacy)
  6. Retention periods or criteria
  7. Data subject rights — access, rectification, erasure, restriction, portability, objection, complaint to supervisory authority
  8. Whether provision is statutory/contractual and consequences of not providing data
  9. Automated decision-making/profiling — logic and significance
  10. Source of data (if not collected from individual — Art. 14)

Legal bases (Article 6)

Common bases: consent, contract, legal obligation, vital interests, public task, legitimate interests. Your policy should map activities to bases — not list "we process for business purposes" alone.

Subprocessors and Article 28

When using processors (cloud hosts, email tools), contracts (DPAs) are required. Privacy policy should name or categorize subprocessors customers care about.

Consumer-readable structure

Regulators expect clarity, not boilerplate walls. Clerica rubric scores:

  • Named vendors vs vague "service providers"
  • Specific retention vs "as long as necessary"
  • Clear rights exercise instructions

GDPR cookie rules overlap ePrivacy. Cookie consent/CMP is not Clerica's focus today — use dedicated CMP if required; ensure privacy policy aligns with actual cookie practices.

Implementation checklist

  • [ ] Controller legal entity and contact published
  • [ ] Purposes and legal bases per activity
  • [ ] Subprocessor list maintained
  • [ ] Transfer mechanisms documented if non-EEA processing
  • [ ] Rights request channel monitored
  • [ ] Policy updated when processing changes

Use GDPR template guide or generator. Related: What is GDPR? · GDPR checklist · GDPR compliance hub

Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.

Publish with proof

Generate policies customers can verify

Use Clerica's free generator for privacy and terms, see your clarity rubric score, and upgrade to Certified when you want Verified directory placement and integrity monitoring.

Generate a policy free
← All guides