# GDPR privacy policy: scope and required contents

> What an EU GDPR privacy policy must contain under Articles 12 to 14, who the regulation reaches, and which library clauses cover it.

A GDPR privacy policy must tell people who the controller is, why and on what legal basis their data is processed, who receives it, whether it leaves the EU, how long it is kept, and which rights they can use, including the right to complain to a supervisory authority. Articles 13 and 14 set the list of required information, and Article 12 requires it to be concise, transparent, intelligible, easily accessible, and written in clear and plain language.

Canonical URL: https://legalpolicygenerator.com/laws/gdpr-privacy-policy

## Who this law applies to

Article 3(1) applies the GDPR to processing in the context of the activities of an establishment of a controller or processor in the Union, regardless of whether the processing itself takes place in the Union. Article 3(2) extends it to controllers and processors without an EU establishment when the processing relates to offering goods or services to people in the Union, whether or not payment is required, or to monitoring their behaviour as far as that behaviour takes place in the Union. A website that can merely be reached from Europe is not automatically offering services there. Indicators such as EU languages or currencies, delivery to EU countries, or marketing aimed at EU audiences point toward targeting, while tracking and profiling people in the Union points toward monitoring. There is no revenue or user-count threshold for transparency duties: a sole trader and a multinational follow the same articles. Controllers outside the Union that are caught by Article 3(2) generally need to designate a representative in the Union under Article 27, subject to a narrow exception for occasional, lower-risk processing. The GDPR has applied since May 25, 2018. The EEA countries outside the EU apply it through the EEA Agreement, while the United Kingdom now runs its own UK GDPR, which has a separate page.

## What your privacy policy must include

When data is collected from the person, Article 13(1) requires the identity and contact details of the controller and any representative; the contact details of the data protection officer where one is designated; the purposes of each processing activity and its legal basis; the legitimate interests pursued where Article 6(1)(f) is relied on; the recipients or categories of recipients; and any intention to transfer data to a third country or international organisation, with a reference to the adequacy decision or appropriate safeguards and how to obtain a copy. Article 13(2) adds the retention period or the criteria used to set it; the rights of access, rectification, erasure, restriction, objection, and data portability; the right to withdraw consent at any time where processing relies on consent; the right to lodge a complaint with a supervisory authority; whether providing data is a statutory or contractual requirement and the consequences of not providing it; and the existence of automated decision-making, including profiling, with meaningful information about the logic involved and the envisaged consequences. When data comes from another source, Article 14 requires the same information plus the categories of personal data concerned and their source, including whether it came from publicly accessible sources, provided within a reasonable period and at the latest within one month. A single web page can serve both articles when it separates information collected directly from information received from partners, platforms, or public sources, and the information must be provided free of charge.

## Legal bases, recipients, and transfers

Article 6 offers six legal bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. A notice that lists all six without saying which applies to which purpose tells readers little, so map each purpose to the basis actually relied on, such as contract for providing an account, legal obligation for tax records, consent for non-essential cookies or marketing where consent is required, and legitimate interests for security, with the specific interest named. Special category data under Article 9, such as health or biometric data, needs an additional condition and deserves a clear separate statement. Recipients may be described by category, but naming the providers used for hosting, email, payments, analytics, support, and AI usually tells readers more. Processors act on your documented instructions under an Article 28 contract, while independent controllers, such as some payment providers, apply their own privacy notices, which the policy can reference. For each transfer outside the EU or EEA, state the mechanism relied on, such as an adequacy decision or standard contractual clauses, and how people can obtain a copy of the safeguards. Data received from a sign-in provider, a data broker, an advertising partner, or a customer who uploads contacts falls under Article 14, which has exemptions where informing people is impossible or would involve disproportionate effort.

## How Legal Policy Generator handles it

Selecting EU or EEA GDPR in the questionnaire adds two regional clauses to an otherwise shared document: an EU legal-bases clause placed after the general uses section, and an EEA rights clause placed with the other regional disclosures. The international-transfers clause also becomes active whenever an EU or UK GDPR module is selected, even when no other international processing is reported. Wording comes from versioned Markdown clauses kept in the repository, values you enter are substituted as escaped text, and no language model writes wording at generation time. The list below is read from the clause library each time this page is rendered, so the identifiers, versions, review dates, and sources match what the generator currently uses.

## Questionnaire answers that switch it on

The EU clauses activate only when the jurisdiction answer includes EU or EEA GDPR; the generator never infers the GDPR from a country or a domain name. Once the module is selected, validation requires at least one legal basis other than the UK-only recognised legitimate interest option, a purpose-to-basis mapping whenever more than one basis is chosen, an answer on whether EU information is transferred internationally, and confirmations about sensitive information and significant solely automated decisions. Reporting a transfer requires a description of the locations and the safeguard, and the generator will not guess an adequacy decision or standard contractual clauses from a provider's name. Optional answers add a data protection officer contact, an EU representative contact, and a description of legitimate interests. When sensitive information or significant automated decisions are confirmed, the rights clause adds sentences on special-category conditions and on human intervention. Privacy request methods such as a privacy email, account settings, a web form, or a preference tool must be selected before they can appear in the policy.

## Common mistakes

Listing every Article 6 basis without tying bases to purposes tells readers nothing and invites challenge. Naming legitimate interests without saying what the interest is fails Article 13(1)(d). Claiming standard contractual clauses or an adequacy decision that was never checked creates a false statement in a public document. Copying a rights catalogue that promises unconditional erasure or portability overstates rights that depend on the legal basis and statutory exceptions. Omitting the supervisory-authority complaint right or the consent-withdrawal right leaves out mandatory items. Forgetting information received from partners, marketplaces, or enrichment services misses the Article 14 source disclosure. Writing that data is kept for as long as necessary, without criteria, does not describe retention. Finally, a notice that differs from the cookie banner, processor contracts, or records of processing is inaccurate even if each document looks complete on its own. A privacy policy is one part of compliance; lawful processing, security, records, contracts, and working request handling have to exist in practice.

## Common questions

### Does a business outside the EU need a GDPR privacy policy?

It does when Article 3(2) applies, meaning it offers goods or services to people in the Union or monitors their behaviour there. Being reachable from Europe is not decisive on its own; targeting and monitoring facts are.

### Do I have to name every recipient of personal data?

Article 13 allows recipients or categories of recipients. European transparency guidance treats naming the actual recipients as the default, and category descriptions should be specific enough to be meaningful.

### Is a GDPR privacy policy the same as cookie consent?

No. Consent for non-essential cookies and similar technologies comes from national ePrivacy rules, while the privacy policy explains the processing. Both need to describe the same technologies and providers.

### Can one policy cover EU, UK, and US users?

Yes. The generator combines each selected regional module into one document with separate regional sections, so EU wording is not presented as a global standard.

### Does a generated GDPR policy guarantee compliance?

No. The generated wording reflects the facts you supply and is not legal advice. Compliance also depends on lawful processing, security, contracts, records, and how requests are handled.

Generated wording reflects supplied facts. It is not legal advice or a guarantee of compliance or enforceability.
