Research guide
GDPR privacy-policy requirements
GDPR transparency requires concise, intelligible, accessible information that reflects processing rather than a copied rights catalogue.
Article 13 and 14 context matters
Required detail differs depending on whether information comes from the person or another source, and includes identity, purposes, bases, recipients, retention, and rights.
Legitimate interests need substance
When relied on, name the interests and assess necessity and balancing rather than using the phrase as a universal basis.
Changes require operational follow-through
A published notice must match records, contracts, security, consent, transfer mechanisms, and request handling.
Official sources checked for this guide
These primary materials were checked on August 5, 2026. Platform rules and legislation can change; verify the current text before publishing or making a high-risk decision.