July 2026 · Compliance Guide

GDPR Privacy Policy: Full Compliance Guide

If you process personal data of anyone in the European Economic Area (EEA) or the United Kingdom, you need a privacy policy that complies with the General Data Protection Regulation (GDPR) — regardless of where your business is based. The GDPR's territorial scope (Article 3) extends to any organisation offering goods or services to data subjects in the EU/UK or monitoring their behaviour.

This guide walks through every GDPR requirement your privacy policy must meet, with direct references to the Articles that apply. Use our free AI policy generator to create a fully compliant policy in minutes.

Article 13: Information to Be Provided When Personal Data Are Collected

Article 13 is the core transparency provision. When you collect personal data directly from an individual, you must provide all of the following at the time of collection:

1. Controller Identity and Contact Details (Art. 13(1)(a))

Your privacy policy must state the full legal name of the data controller (your business or organisation) and its physical address. If you are established outside the EU/UK, you must also name your representative in the EU/UK under Article 27 and provide their contact information. Simply writing "we respect your privacy" is not sufficient — the identity must be specific enough for a data subject to know exactly who is processing their data.

2. Data Protection Officer Contact (Art. 13(1)(b))

If you are required to appoint a Data Protection Officer (DPO) — which applies when you are a public authority, engage in large-scale systematic monitoring, or process special categories of data on a large scale (Articles 35-37) — you must provide the DPO's full contact details. Even where appointment is not mandatory, including DPO contact information demonstrates strong compliance posture.

3. Purposes and Legal Basis for Processing (Art. 13(1)(c))

Every processing activity must be tied to one of six lawful bases under Article 6(1):

Your privacy policy must map each category of personal data to its specific purpose and legal basis. A single policy section saying "we process data based on legitimate interests" without specifying which interest is not compliant.

4. Legitimate Interests Explained (Art. 13(1)(d))

If you rely on legitimate interests as your legal basis for any processing, you must name the specific legitimate interest pursued. Common examples include direct email marketing (subject to soft opt-in under ePrivacy), fraud detection, IT network security, internal administration, or anonymised analytics. The ICO (UK), CNIL (France), and other supervisory authorities expect this to be specific — not a generic recital.

5. Recipients or Categories of Recipients (Art. 13(1)(e))

You must list any third parties who receive personal data — either by name or by category. Categories might include: payment processors (Stripe, PayPal), analytics providers (Google Analytics 4, Plausible), email marketing platforms (Mailchimp, ConvertKit), cloud hosting providers (AWS, DigitalOcean), and sub-processors. Under Article 28, each processor must be bound by a data processing agreement (DPA) that reflects GDPR requirements.

6. International Transfers and Safeguards (Art. 13(1)(f))

If you transfer personal data outside the EEA or UK, you must disclose this and explain which safeguard mechanism you rely on under Articles 44-49. The three most common transfer mechanisms are:

For US transfers post-Schrems II (CJEU Case C-311/18), you must also conduct a Transfer Impact Assessment (TIA) to verify that the SCCs provide essentially equivalent protection in practice, factoring in US surveillance law.

7. Retention Periods (Art. 13(2)(a))

You must specify how long each category of personal data will be retained, or the criteria used to determine that period. Generic "we keep data as long as necessary" is insufficient. Specific periods (e.g., "email addresses are retained for the duration of the account plus 12 months following account closure, after which they are deleted") are best practice. The data minimisation and storage limitation principles (Articles 5(1)(c) and (e)) require that you keep data no longer than needed.

8. The Eight Data Subject Rights (Art. 13(2)(b))

Your privacy policy must inform data subjects of all eight GDPR rights:

  1. Right of access (Article 15) — data subjects can request confirmation of whether you process their data and obtain a copy, along with information about purposes, categories, recipients, retention, and safeguards on transfers.
  2. Right to rectification (Article 16) — inaccurate personal data must be corrected without undue delay.
  3. Right to erasure / "right to be forgotten" (Article 17) — data subjects can request deletion where data is no longer necessary, consent is withdrawn, processing is unlawful, or a legal obligation requires erasure. This right is not absolute — it does not apply where processing is necessary for exercising freedom of expression, legal compliance, or legal claims.
  4. Right to restriction of processing (Article 18) — data subjects can "pause" processing while accuracy is contested, processing is unlawful but erasure is not desired, or you no longer need the data but the data subject needs it for legal claims.
  5. Right to data portability (Article 20) — where processing is based on consent or contract and is carried out by automated means, data subjects can receive their data in a structured, commonly used, machine-readable format (CSV, JSON, XML) and have it transmitted directly to another controller where technically feasible.
  6. Right to object (Article 21) — data subjects can object at any time to processing based on legitimate interests, including profiling. You must stop processing unless you demonstrate compelling legitimate grounds that override the data subject's interests. Where processing is for direct marketing, the right to object is absolute — you must stop immediately.
  7. Rights relating to automated decision-making (Article 22) — data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significant effects. If you conduct such processing, you must provide meaningful information about the logic involved, the significance, and the envisaged consequences.
  8. Right to lodge a complaint with a supervisory authority (Article 77) — you must inform data subjects of their right to lodge a complaint with their local data protection authority. For each relevant jurisdiction, name the authority: the ICO (UK, ico.org.uk), CNIL (France, cnil.fr), the DPC (Ireland, dataprotection.ie), the BfDI (Germany), the APD/GBA (Belgium), the AEPD (Spain), the Garante (Italy), and the Autoriteit Persoonsgegevens (Netherlands).

9. Consequences of Not Providing Data (Art. 13(2)(e))

Where the collection of personal data is a statutory or contractual requirement, and the data subject is obliged to provide it, you must explain the possible consequences of failing to do so. For example: "If you do not provide your payment information, we cannot process your order." This is often overlooked but is specifically required by Article 13(2)(e).

10. Existence of Automated Decision-Making (Art. 13(2)(f))

If you use any form of automated decision-making under Article 22, you must provide meaningful information about the logic involved, the significance, and the envisaged consequences. This includes credit scoring, AI-based hiring filters, insurance underwriting algorithms, and any other purely automated decision that affects individuals' legal rights.

Article 14: When Data Is Not Obtained from the Data Subject

If you obtain personal data from a third-party source (e.g., data brokers, public registers, referrals), Article 14 imposes additional transparency obligations: you must inform the data subject within one month, including the categories of data and the source, in addition to the Article 13 requirements.

Additional GDPR Requirements Your Privacy Policy Must Cover

Data Protection by Design and Default (Article 25)

While not strictly a privacy policy disclosure requirement, your policy should reference the technical and organisational measures you implement to protect data: encryption at rest and in transit, pseudonymisation where feasible, access controls, and regular security testing. Mentioning these measures builds trust and demonstrates accountability under Article 5(2).

Data Breach Notification (Articles 33-34)

Your privacy policy should outline your procedure in the event of a personal data breach — specifically that you will notify the supervisory authority within 72 hours (Article 33) and communicate the breach to affected data subjects where it poses a high risk (Article 34). Including a breach response timeline reassures data subjects that you take security seriously.

Special Category Data (Article 9)

If you process special categories of data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data for identification, health data, or sex life/orientation), you need an explicit legal basis under Article 9(2) — usually explicit consent or employment law necessity — and your privacy policy must state this separately.

Jurisdictional Variations: UK GDPR vs. EU GDPR

The UK GDPR (as retained post-Brexit) is substantially identical to the EU GDPR, with minor differences: the UK has its own adequacy decisions, its own SCCs published by the ICO, and the ICO as the lead supervisory authority. If your business operates in both the UK and EU, your privacy policy should note that both regimes apply. The UK GDPR age of digital consent is 13 (vs. 16 in most EU member states). The ICO also publishes updated guidance on legitimate interests, AI, and direct marketing that diverges slightly from the EDPB guidance.

How Our Generator Creates GDPR Compliant Policies

Our free AI privacy policy generator produces policies that address every Article 13 requirement: it asks about your controller identity, processing purposes, legal bases, data categories, recipients, international transfers, and retention periods, then structures the output to meet GDPR transparency standards. You can generate a complete GDPR-ready privacy policy in under five minutes.

Generate Your GDPR Privacy Policy Now