The French data protection authority (CNIL) issued 42 fines in 2023, totalling €89 million. The Irish DPC fined Meta €1.2 billion for unlawful data transfers. But you don't need to be Meta-sized to get fined: a German online retailer received a €20,000 penalty for an incomplete privacy policy. A small Austrian hotel chain was fined €18,000. A Portuguese hospital: €400,000. Regulators across the EU are actively enforcing Article 13 obligations against businesses of all sizes. Here's exactly what your policy needs — and template language to get it right the first time.

Who Needs a GDPR Privacy Policy?

The GDPR applies based on where your visitors are located, not where your business is registered. A US-based SaaS company with EU users is subject to GDPR. If your website:

  • Receives visitors from EU countries (even incidentally)
  • Uses Google Analytics, Facebook Pixel, Hotjar, or any tracking tool
  • Has a contact form, newsletter signup, or user registration
  • Processes payment card data or shipping addresses
  • Stores cookies beyond strictly functional ones

...then you need a GDPR-compliant privacy policy. Not a generic template, not a copied policy — a document that accurately reflects your specific data processing activities.

What Must a GDPR Privacy Policy Include — Article 13 Requirements

Article 13 of the GDPR specifies nine categories of information that must be disclosed when personal data is collected directly from the individual. Here is each requirement with template language you can adapt:

1. Identity and Contact Details of the Data Controller

What's required: Your full legal name (or business name), registered address, and contact email. If you have a Data Protection Officer, their name and contact details must also be included.

Template language:

"This website is operated by [Business Legal Name], registered at [Address]. For data protection enquiries, contact us at [email address]."

For every type of personal data you collect, you must state why you collect it and the legal basis under Article 6 GDPR. The six legal bases are: consent (Art. 6(1)(a)), contract performance (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)), vital interests (Art. 6(1)(d)), public task (Art. 6(1)(e)), and legitimate interests (Art. 6(1)(f)).

Most websites rely on two:

Consent — for non-essential cookies, marketing emails, and analytics with identifiable tracking:

"We process your data based on your freely given consent (Article 6(1)(a) GDPR), which you provide by [subscribing to our newsletter / accepting cookies]. You may withdraw your consent at any time by [unsubscribing / adjusting cookie settings]."

Legitimate interests — for server logs, security monitoring, and fraud prevention:

"We process IP addresses and access logs for the legitimate interest of maintaining website security and preventing abuse (Article 6(1)(f) GDPR). We have assessed that our interests are not overridden by your rights and freedoms."

3. Legitimate Interests Disclosure

If you rely on legitimate interests, you must state what those interests are specifically. "Legitimate business interests" is not sufficient. Be concrete:

"Our legitimate interests include: ensuring the security and integrity of our systems; preventing fraudulent account activity; improving the performance and user experience of our website based on aggregated analytics data."

4. Third-Party Recipients and International Transfers

Disclose every third party that receives personal data: hosting provider, analytics platform, email provider, payment processor, CRM, live chat tool. If any transfers occur outside the EU/EEA (e.g., data processed by US-based services), you must state the safeguard in place — typically Standard Contractual Clauses (SCCs).

Template language:

"We share personal data with the following processors: [Hosting Provider] (hosting, EU/EEA servers); Google LLC (analytics via Google Analytics 4, US — Standard Contractual Clauses in place); [Email Provider] (email marketing, EU servers)."

5. Data Retention Periods

You must state how long you keep each category of data. Vague statements like "as long as necessary" are insufficient under GDPR enforcement guidance. Use a retention schedule:

Data TypeRetention PeriodBasis
Contact form submissions2 yearsLegitimate interests
Order / invoice records7–10 yearsLegal obligation (tax law)
Website analytics data14 monthsConsent (then auto-deleted)
Newsletter subscriber recordsUntil unsubscribe + 1 yearConsent record requirement
Job application data6 months after decisionLegitimate interests
User account dataDuration of account + 30 daysContract performance

6. Data Subject Rights

You must inform users of all their rights and explain how to exercise them:

  • Right of access (Art. 15): request a copy of their data
  • Right to rectification (Art. 16): correct inaccurate data
  • Right to erasure (Art. 17): "right to be forgotten"
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20): receive their data in machine-readable format
  • Right to object (Art. 21): especially to direct marketing and profiling
  • Right to withdraw consent at any time without detriment

Template language:

"To exercise any of these rights, email us at [contact email]. We will respond within 30 days. You may also lodge a complaint with your national data protection authority."

7. Right to Lodge a Complaint

Users must be told they can complain to their national Data Protection Authority:

  • Germany: Der Bundesbeauftragte für den Datenschutz (BfDI) or relevant Landesbeauftragter
  • France: Commission Nationale de l'Informatique et des Libertés (CNIL)
  • Ireland: Data Protection Commission (DPC)
  • Netherlands: Autoriteit Persoonsgegevens (AP)
  • Spain: Agencia Española de Protección de Datos (AEPD)

8. Whether Data Provision is Obligatory

For any form where you request personal data, you must state whether providing it is mandatory and what happens if the person refuses. For contact forms: "Providing your name and email is optional, but we cannot respond to your enquiry without them."

9. Automated Decision-Making and Profiling

If your website uses automated decision-making that produces legal or similarly significant effects (uncommon for most small businesses), this must be disclosed with the logic and consequences explained.

Your privacy policy must reference your use of cookies and ideally link to a separate, detailed cookie policy. The EU ePrivacy Directive requires prior opt-in consent for all non-essential cookies — analytics, advertising, social media embeds, and marketing pixels all require consent before being set.

If you are using Google Analytics, Google Consent Mode v2 (required since March 2024 for EU users) must be configured to respect consent signals. See our Cookie Consent Generator to build a compliant banner that integrates with Google Tag Manager.

Data Processing Agreements — The Hidden Compliance Gap

Most website owners have a reasonably complete privacy policy but are missing Data Processing Agreements with their processors. Under Article 28 GDPR, every service that processes personal data on your behalf must be covered by a DPA. This includes:

  • Web hosting provider (Cloudflare, Vercel, AWS, SiteGround)
  • Email marketing platform (Mailchimp, Brevo, ConvertKit)
  • Analytics service (Google Analytics, Plausible, Fathom)
  • Payment processor (Stripe, PayPal, Mollie)
  • CRM or helpdesk (HubSpot, Intercom, Zendesk)

Most major services provide DPAs in their terms of service or allow you to sign one online in your account settings. Check each service and ensure you have accepted their DPA. Not having a DPA is an independent GDPR violation — separate from your privacy policy's completeness.

GDPR Compliance Checklist for Website Owners

Run through these 10 points to audit your current position:

  1. Privacy policy is published and linked from every page (typically in the footer)
  2. Policy accurately reflects your current data processing activities (not outdated or copied)
  3. All 9 Article 13 elements are covered with specific, accurate language
  4. Legal basis for each processing activity is stated (consent, legitimate interests, contract, etc.)
  5. Third-party processors are listed with their country of operation
  6. Retention periods are specified for each data category
  7. Users can exercise all 8 GDPR rights with a clear contact method
  8. Cookie consent banner obtains prior opt-in for non-essential cookies
  9. Data Processing Agreements are in place with all processors
  10. Policy has been reviewed in the last 12 months and "last updated" date is current

What Happens If Your Privacy Policy is Non-Compliant?

Under Article 83(5) GDPR, violations of transparency obligations (Articles 13–14) carry maximum fines of €20 million or 4% of global annual turnover, whichever is higher. In practice, regulators typically issue warnings and correction orders for first offences from small businesses. But repeat violations, or violations combined with a data breach, attract significantly heavier penalties.

Beyond regulatory risk, a clear privacy policy builds user trust and reduces the risk of complaints — which is how most enforcement actions begin.

Generate Your GDPR Privacy Policy

Use our free GDPR Privacy Policy Generator to create a customised policy covering all Article 13 requirements. Answer questions about your specific tools and data flows, and receive a ready-to-publish document tailored to your website — not a generic template that could apply to anyone.