LegalCraftLegalCraft
← All posts

GDPR-Compliant Privacy Policy Template: What You Actually Need

The GDPR applies to any business that handles the personal data of people in the EU or UK — regardless of where the business itself is located. If you have EU visitors, you're in scope. A compliant privacy policy is one of the regulation's most visible requirements, and a vague template won't satisfy it.

When the GDPR applies to you

You must comply if you:

  • Offer goods or services to people in the EU/UK (even for free), or
  • Monitor the behavior of people in the EU/UK (analytics, ad tracking, profiling).

There is no small-business exemption based on size. A two-person shop with EU customers has the same core disclosure obligations as a large company.

Disclosures the GDPR specifically requires

Under Articles 13 and 14, your privacy policy must clearly state:

  • Identity and contact details of the data controller (you), and a Data Protection Officer if you have one.
  • The purposes for processing each category of data.
  • The legal basis for each purpose — consent, contract, legal obligation, or legitimate interests. This is the part generic templates almost always skip.
  • Recipients of the data — the processors and third parties you share it with.
  • International transfers — if data leaves the EU, the safeguards you rely on.
  • Retention periods — how long you keep each type of data, or the criteria used to decide.
  • Data-subject rights — access, rectification, erasure, restriction, portability, and objection.
  • The right to withdraw consent and to lodge a complaint with a supervisory authority.

The lawful-basis point people miss

Every processing activity needs a lawful basis, and you must name it. Marketing emails typically rely on consent; fulfilling an order relies on contract; fraud prevention often relies on legitimate interests. Stating "we process your data to provide our services" is not enough — the regulation expects specificity.

Quick GDPR policy checklist

  • Names your business as the data controller with real contact details
  • Lists each data category and its specific purpose
  • States the lawful basis for every purpose
  • Describes all third parties and processors
  • Explains international transfer safeguards (if applicable)
  • Gives concrete retention periods
  • Spells out all data-subject rights and how to exercise them
  • Mentions the right to complain to a supervisory authority

Generate a GDPR-aware policy

Rather than adapting a static template by hand, LegalCraft generates a policy that reflects your jurisdiction, the tools you use, and whether GDPR (and CCPA) apply to you — with the lawful-basis and data-rights sections built in. Start free and download in minutes.

Note: This is general information, not legal advice. If you process sensitive data or operate in a regulated sector, get your final policy reviewed by a qualified professional.

Need these documents for your own site?

Generate a customized, jurisdiction-aware version in minutes — free to start.

Generate my documents