Law guide
GDPR privacy policy: scope and required contents
A GDPR privacy policy must tell people who the controller is, why and on what legal basis their data is processed, who receives it, whether it leaves the EU, how long it is kept, and which rights they can use, including the right to complain to a supervisory authority. Articles 13 and 14 set the list of required information, and Article 12 requires it to be concise, transparent, intelligible, easily accessible, and written in clear and plain language.
Who this law applies to
Article 3(1) applies the GDPR to processing in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing itself takes place in the Union. Article 3(2) extends it to controllers and processors without an EU establishment when the processing relates to offering goods or services to people in the Union, whether or not payment is required, or to monitoring their behaviour as far as that behaviour takes place in the Union. A website that can merely be reached from Europe is not automatically offering services there. Indicators such as EU languages or currencies, delivery to EU countries, or marketing aimed at EU audiences point toward targeting, while tracking and profiling people in the Union points toward monitoring. There is no revenue or user-count threshold for transparency duties: a sole trader and a multinational follow the same articles. Controllers outside the Union that are caught by Article 3(2) generally need to designate a representative in the Union under Article 27, subject to a narrow exception for occasional, lower-risk processing. The GDPR has applied since May 25, 2018. The EEA countries outside the EU apply it through the EEA Agreement, while the United Kingdom now runs its own UK GDPR, which has a separate page.
What your privacy policy must include
When data is collected from the person, Article 13(1) requires the identity and contact details of the controller and any representative; the contact details of the data protection officer where one is designated; the purposes of each processing activity and its legal basis; the legitimate interests pursued where Article 6(1)(f) is relied on; the recipients or categories of recipients; and any intention to transfer data to a third country or international organisation, with a reference to the adequacy decision or appropriate safeguards and how to obtain a copy. Article 13(2) adds the retention period or the criteria used to set it; the rights of access, rectification, erasure, restriction, objection, and data portability; the right to withdraw consent at any time where processing relies on consent; the right to lodge a complaint with a supervisory authority; whether providing data is a statutory or contractual requirement and the consequences of not providing it; and the existence of automated decision-making, including profiling, with meaningful information about the logic involved and the envisaged consequences. When data comes from another source, Article 14 requires the same information plus the categories of personal data concerned and their source, including whether it came from publicly accessible sources, provided within a reasonable period and at the latest within one month. A single web page can serve both articles when it separates information collected directly from information received from partners, platforms, or public sources, and the information must be provided free of charge.
Legal bases, recipients, and transfers
Article 6 offers six legal bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. A notice that lists all six without saying which applies to which purpose tells readers little, so map each purpose to the basis actually relied on, such as contract for providing an account, legal obligation for tax records, consent for non-essential cookies or marketing where consent is required, and legitimate interests for security, with the specific interest named. Special category data under Article 9, such as health or biometric data, needs an additional condition and deserves a clear separate statement. Recipients may be described by category, but naming the providers used for hosting, email, payments, analytics, support, and AI usually tells readers more. Processors act on your documented instructions under an Article 28 contract, while independent controllers, such as some payment providers, apply their own privacy notices, which the policy can reference. For each transfer outside the EU or EEA, state the mechanism relied on, such as an adequacy decision or standard contractual clauses, and how people can obtain a copy of the safeguards. Data received from a sign-in provider, a data broker, an advertising partner, or a customer who uploads contacts falls under Article 14, which has exemptions where informing people is impossible or would involve disproportionate effort.
How Legal Policy Generator handles it
Selecting EU or EEA GDPR in the questionnaire adds two regional clauses to an otherwise shared document: an EU legal-bases clause placed after the general uses section, and an EEA rights clause placed with the other regional disclosures. The international-transfers clause also becomes active whenever an EU or UK GDPR module is selected, even when no other international processing is reported. Wording comes from versioned Markdown clauses kept in the repository, values you enter are substituted as escaped text, and no language model writes wording at generation time. The list below is read from the clause library each time this page is rendered, so the identifiers, versions, review dates, and sources match what the generator currently uses.
Privacy Policy clauses for this law
Clauses in the current library that carry this jurisdiction in their metadata: 2
Identifiers, versions, required answers, review dates, and sources below are read from the clause files when this page is generated.
gdpr-bases v1.2.0 · Privacy Policy · EU legal bases for processing
Required answers: legal_bases, basis_mapping, eu_transfer. Reviewed . Official source: eur-lex.europa.eu.
… Consent can be withdrawn for future processing at any time without affecting processing that was lawful before withdrawal.
Excerpt from clause gdpr-bases v1.2.0gdpr-rights v1.2.0 · Privacy Policy · European Economic Area privacy rights
Required answers: legal_bases, rights_methods. Reviewed . Official source: eur-lex.europa.eu.
The EU GDPR has applied since May 25, 2018. Where it applies, people may request access, rectification, erasure, restriction, and portability; object to processing; withdraw consent for future processing; and complain to the competent supervisory authority.
Excerpt from clause gdpr-rights v1.2.0
Related Terms of Use clauses for the same region
These clauses belong to the separate Terms of Use generator. They address consumer or platform rules for the region, not privacy notices, and activate only from Terms questionnaire answers.
terms-eu-consumer v1.1.0 · Terms of Service · EU consumer rights
Reviewed . Official source: eur-lex.europa.eu, eur-lex.europa.eu.
terms-eu-dsa v1.2.0 · Terms of Service · EU platform rights
Reviewed . Official source: eur-lex.europa.eu.
Questionnaire answers that switch it on
The EU clauses activate only when the jurisdiction answer includes EU or EEA GDPR; the generator never infers the GDPR from a country or a domain name. Once the module is selected, validation requires at least one legal basis other than the UK-only recognised legitimate interest option, a purpose-to-basis mapping whenever more than one basis is chosen, an answer on whether EU information is transferred internationally, and confirmations about sensitive information and significant solely automated decisions. Reporting a transfer requires a description of the locations and the safeguard, and the generator will not guess an adequacy decision or standard contractual clauses from a provider's name. Optional answers add a data protection officer contact, an EU representative contact, and a description of legitimate interests. When sensitive information or significant automated decisions are confirmed, the rights clause adds sentences on special-category conditions and on human intervention. Privacy request methods such as a privacy email, account settings, a web form, or a preference tool must be selected before they can appear in the policy.
Common mistakes
Listing every Article 6 basis without tying bases to purposes tells readers nothing and invites challenge. Naming legitimate interests without saying what the interest is fails Article 13(1)(d). Claiming standard contractual clauses or an adequacy decision that was never checked creates a false statement in a public document. Copying a rights catalogue that promises unconditional erasure or portability overstates rights that depend on the legal basis and statutory exceptions. Omitting the supervisory-authority complaint right or the consent-withdrawal right leaves out mandatory items. Forgetting information received from partners, marketplaces, or enrichment services misses the Article 14 source disclosure. Writing that data is kept for as long as necessary, without criteria, does not describe retention. Finally, a notice that differs from the cookie banner, processor contracts, or records of processing is inaccurate even if each document looks complete on its own. A privacy policy is one part of compliance; lawful processing, security, records, contracts, and working request handling have to exist in practice.
Official sources checked for this guide
Platform rules and legislation can change. Verify the current text before publishing or making a high-risk decision.
Common questions
Does a business outside the EU need a GDPR privacy policy?
It does when Article 3(2) applies, meaning it offers goods or services to people in the Union or monitors their behaviour there. Being reachable from Europe is not decisive on its own; targeting and monitoring facts are.
Do I have to name every recipient of personal data?
Article 13 allows recipients or categories of recipients. European transparency guidance treats naming the actual recipients as the default, and category descriptions should be specific enough to be meaningful.
Is a GDPR privacy policy the same as cookie consent?
No. Consent for non-essential cookies and similar technologies comes from national ePrivacy rules, while the privacy policy explains the processing. Both need to describe the same technologies and providers.
Can one policy cover EU, UK, and US users?
Yes. The generator combines each selected regional module into one document with separate regional sections, so EU wording is not presented as a global standard.
Does a generated GDPR policy guarantee compliance?
No. The generated wording reflects the facts you supply and is not legal advice. Compliance also depends on lawful processing, security, contracts, records, and how requests are handled.