You know you need a privacy policy, and you think you also need to be compliant with GDPR. So what are the requirements of a GDPR privacy policy?
The exact content of your website’s privacy policy will be determined by the type of business you’re running. However, all privacy policies need the following in order to be GDPR compliant: an outline of what personal data your company collects, why you collect that data, who the data may be shared with, where it is stored, and how it is kept protected. It must also ensure users are made aware of all their rights in relation to their personal data.

What is a privacy policy?
A privacy policy is a legal document: an agreement between you and your user that outlines what data you collect from them, and how and why you collect their personal data. It also explains where and how the data is stored, and what security measures you have in place to protect it.
There are international privacy laws your privacy policy should comply with; for more, see our article on international privacy laws.
What to include in a GDPR-compliant privacy policy
To understand what’s required in a GDPR-compliant privacy policy, you need to know what GDPR is. GDPR stands for the General Data Protection Regulation, which the EU put in place to protect the rights of its residents and citizens over their personal data.
Here is a list of the sections and clauses your GDPR privacy policy needs to include:
- Table of Contents
- Data Collection
- Personally Identifying Information
- Non-Personally Identifying Information
- Cookie Policy
- Data Protection Rights (under GDPR)
- Data Protection Fee
- Policy Changes
- Contact Information
- How to Contact the Data Controller
- How to Contact the Data Protection Officer
Table of Contents
A clear, easy-to-navigate table of contents at the top of your privacy policy helps users quickly find the section relevant to them, rather than reading the whole document.
As you can see with Netflix’s Privacy Policy Table of Contents everything is easy to understand and access
Data Collection
A clear explanation of what kind of data will be collected from the user is a must in order to be GDPR compliant. You should also include how the data is collected, where it’s stored and processed, and how long it’s retained, along with the security measures you have in place to protect it.
Personally Identifying Information
Your privacy policy needs to explain what Personally Identifying Information (PII) is, and let users know what types of PII your company or website collects (for example: full name, street address, birthdate). You should also explain:
- How the information collected is used
- Whether the information may be disclosed to third parties, and if so, who
- How the user can opt in or out of personal information collection
- How they can update, restrict, or delete their personal information
- How they can request erasure of their personal information
Non-Personally Identifying Information
Your company or website may also collect non-personally identifying information, such as education status, geolocation, or IP address. Your privacy policy needs to explain what type of non-personally identifying information you collect and how you may use it.
Cookies
Your privacy policy should explain what a cookie is and how it enables certain functions on your website. What types of cookies does your website use, and what are they used for? How can your users opt out of them if they wish?
Your Data Protection Rights
In alignment with the GDPR (see our article on GDPR compliance for more detail), you must outline the data protection rights of your users and customers. These rights are:
- To be informed: users have the right to know how you collect and use their personal data. This is a major requirement under the GDPR to promote transparency; users must be given this information at the time their personal data is collected.
- Of access: users can request access to their data at any time, either verbally or in writing. You have one calendar month to respond.
- Rectification: users can have inaccuracies in their personal data corrected, again with a one-month response window.
- To be forgotten (erasure): users can request that their personal data be erased, with the same one-month response window.
- Restrict processing: users can request that you stop processing their personal data in certain circumstances, again within one calendar month.
- Object to processing: users can object to their personal data being used for direct marketing, or request that you stop processing it in certain circumstances, such as where the processing is for a task carried out in the public interest, an exercise of official authority, or your legitimate interests (or those of a third party).
- Data portability: users can obtain their personal data and move it safely and securely from one IT environment to another.
- Object to automated processing: users can object to their personal data being processed without human involvement, by automated means.
Data Processing Fee
You must let your users and customers know if a processing fee may apply to any of their data requests. In most cases a fee won’t apply, but you must disclose the possibility.
Contact Details
You must include your company’s contact details in your privacy policy so users can reach you easily.
How to Contact the Data Controller
If you have a data controller, their contact details must be made available in your privacy policy under the GDPR.
How to Contact the Data Protection Officer
If you have a data protection officer, their contact details must also be made available in your privacy policy under the GDPR.
Conclusion
To ensure your privacy policy complies with the GDPR, your users need to be informed about their rights in relation to the personal data you’re collecting from them. Your privacy policy must include information on what personal data you collect, how you use it, how you collect it, why you collect it, where it is stored, and how it’s kept secure.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.