TermsBox
PricingBlog
LoginGet Started
PricingBlogLogin
Get Started
  1. Home
  2. Blog
  3. GDPR Privacy Policy Template: What It Must Include in 2026
Privacy Policy

GDPR Privacy Policy Template: What It Must Include in 2026

A GDPR privacy policy template must cover 13 disclosures under Articles 13 and 14. Learn what to include, what to avoid, and how to adapt one to your site.

TermsBox Team|July 24, 202613 min read

If you are searching for a GDPR privacy policy template, you are probably looking for a document that satisfies Articles 13 and 14 of the General Data Protection Regulation (GDPR) without needing to read 99 articles of legislation first. That is a reasonable goal, but a template only gets you the structure. The disclosures that actually determine compliance depend on facts only you know: which trackers run on your site, which processors touch your data, and why you are allowed to process it at all. This guide covers the key requirements you should know, though you should consult a qualified attorney for advice tailored to your specific business.

What a GDPR Privacy Policy Template Actually Is

A GDPR privacy policy template is a structured document that maps each mandatory transparency disclosure in Articles 13 and 14 of the GDPR to a section you fill in with your organization's real processing details. It is a checklist in prose form, not a finished legal document.

The GDPR never uses the phrase "privacy policy." The obligation lives in Chapter III, Section 1, under the heading "Transparency and modalities." Article 12(1) requires the information to be provided "in a concise, transparent, intelligible and easily accessible form, using clear and plain language." Article 13 covers data you collect directly from the person. Article 14 covers data you obtained from somewhere else, such as a data broker, a public register, or a partner referral.

This is why regulators, including the UK Information Commissioner's Office (ICO), prefer the term privacy notice. If you are comparing a GDPR privacy notice template against a privacy policy template GDPR result, you are almost always looking at the same category of document. The naming difference does not change what has to be inside.

Two practical consequences follow from this framing:

  • A template that reads like a contract fails Article 12(1). Plain language is a legal requirement, not a style preference.
  • A template with placeholder text left in ("[Company Name] may share data with [third parties]") is worse than no policy, because it demonstrates to a regulator that no assessment took place.

The 13 Disclosures Every GDPR Privacy Policy Template Must Cover

Article 13(1) and 13(2) list the information you must provide when you collect data directly from a person. Any credible GDPR privacy policy template contains all of the following:

  1. Identity and contact details of the controller, and of the controller's representative in the EU where Article 27 applies.
  2. Contact details of the Data Protection Officer (DPO), where you have appointed one under Article 37.
  3. The purposes of the processing, stated specifically rather than as a catch-all.
  4. The legal basis for each purpose, drawn from Article 6(1).
  5. The legitimate interests pursued, where you rely on Article 6(1)(f).
  6. The recipients or categories of recipients of the personal data.
  7. Details of transfers to third countries, including the safeguard used under Chapter V.
  8. The retention period, or the criteria used to determine it.
  9. The data subject rights under Articles 15 to 21.
  10. The right to withdraw consent at any time, where processing relies on Article 6(1)(a) or 9(2)(a).
  11. The right to lodge a complaint with a supervisory authority.
  12. Whether providing the data is a statutory or contractual requirement, and the consequences of not providing it.
  13. The existence of automated decision-making, including profiling, with meaningful information about the logic involved.

If your data came from a third party rather than the person directly, Article 14 adds two further requirements: the categories of personal data you obtained, and the source of the data, including whether it came from publicly accessible sources. Article 14(3) also sets a deadline: you must provide this information within a reasonable period, and at the latest within one month.

Why a Free GDPR Privacy Policy Template Fails Without Editing

Searching for a GDPR privacy policy template free will return hundreds of downloadable Word documents. Most are structurally sound and substantively empty. The gap is always in the same four places.

Legal Basis Is Site-Specific

Article 6(1) offers six legal bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. A template cannot choose for you, and choosing wrong is a substantive breach, not a drafting error.

The European Data Protection Board has been clear that you cannot rely on legitimate interests as a fallback when consent is the appropriate basis, particularly for direct marketing cookies and behavioural advertising. You must state a basis per purpose, not one basis for the whole document.

Recipients Depend on Your Actual Stack

Article 13(1)(e) requires the recipients or categories of recipients. If your site loads Google Analytics, Meta Pixel, Hotjar, Intercom, and Stripe, those are real data flows to real processors. A template lists "analytics providers" as a placeholder; your policy needs to reflect what is genuinely running.

This is the single most common inaccuracy in published privacy policies. Marketing teams add a tag through a tag manager, and the legal document silently falls out of date. Building your privacy policy from an actual inventory of the third-party requests your pages make is the practical way to keep the recipient list honest.

Retention Periods Cannot Be Guessed

Article 13(2)(a) requires the storage period or the criteria used to determine it. "As long as necessary" on its own has been criticised repeatedly by supervisory authorities as meaningless. Acceptable phrasing ties retention to a trigger:

  • Account data: retained for the life of the account, then deleted within 90 days of closure.
  • Transaction records: retained for six years to satisfy tax and accounting obligations.
  • Marketing consent records: retained for three years from the last engagement.

International Transfers Changed After Schrems II

If you use US-based processors, Chapter V applies. Since the Court of Justice of the European Union invalidated Privacy Shield in Schrems II (Case C-311/18), transfers rely on either the EU-US Data Privacy Framework, adopted in July 2023, or Standard Contractual Clauses with a transfer impact assessment. A template written before 2023 will cite a mechanism that no longer exists.

Legal Bases Mapped to Common Website Activities

Activity Typical Article 6(1) Basis Notes
Fulfilling an order (b) Contract Covers shipping, payment, and support tied to the purchase
Marketing emails (a) Consent ePrivacy Directive Article 13 also applies; soft opt-in may cover existing customers
Analytics cookies (a) Consent ePrivacy Directive Article 5(3) requires consent before storage
Strictly necessary cookies Article 5(3) exemption No consent needed, but still disclose them
Fraud prevention (f) Legitimate interests Requires a documented balancing test
Tax and accounting records (c) Legal obligation Cite the retention period the law imposes
Employee payroll (b) Contract and (c) Legal obligation Often relies on more than one basis

Note the split in the cookie rows. Cookie consent is governed by Article 5(3) of the ePrivacy Directive, not by the GDPR alone. The GDPR supplies the definition of valid consent under Article 4(11) and Article 7, but the trigger for needing consent before storing information on a device comes from ePrivacy. Your cookie policy and your privacy policy address related but legally distinct obligations.

How to Adapt a GDPR Privacy Policy Template to Your Business

Work through these steps in order. Each one produces an input the next step needs.

  1. Build a processing inventory. List every purpose for which you handle personal data. Article 30 requires most organizations to maintain records of processing activities anyway, so this work is not optional overhead.
  2. Scan your site for trackers. Identify every third-party script, pixel, and cookie actually loading in production, including ones added through a tag manager.
  3. Assign a legal basis to each purpose. Document your reasoning, especially for anything relying on legitimate interests under Article 6(1)(f).
  4. Map recipients and locations. For each processor, record what data it receives, where it stores it, and which Chapter V safeguard covers any transfer outside the EEA.
  5. Set retention periods with a stated trigger. Tie each to an event and a duration.
  6. Write the rights section with a working mechanism. Naming Article 15 to 21 rights is not enough; you need a real channel that responds within the one-month deadline in Article 12(3).
  7. Publish it where it is genuinely accessible. Footer link on every page, plus a link at each point of collection, including signup forms and checkout.
  8. Version and date it. Keep prior versions. If a regulator asks what your policy said in March, you need to be able to answer.

Data Subject Rights Your GDPR Privacy Policy Template Must Explain

Chapter III grants eight rights. Your policy must reference all that apply to your processing, and vague summaries will not satisfy Article 12(1).

  • Right of access (Article 15): a copy of the personal data plus the processing details.
  • Right to rectification (Article 16): correction of inaccurate or incomplete data.
  • Right to erasure (Article 17): deletion where one of the six listed grounds applies. It is not absolute.
  • Right to restriction (Article 18): processing paused while a dispute is resolved.
  • Right to data portability (Article 20): a structured, commonly used, machine-readable copy. Applies only to consent-based or contract-based processing carried out by automated means.
  • Right to object (Article 21): including an absolute right to object to direct marketing under Article 21(3).
  • Rights around automated decision-making (Article 22): including the right to human intervention.
  • Right to withdraw consent (Article 7(3)): and it must be as easy to withdraw as it was to give.

Two details are frequently missed. First, Article 12(5) says you must respond free of charge; you may only charge or refuse where a request is manifestly unfounded or excessive, and the burden of proving that sits with you. Second, Article 12(3) sets a one-month response deadline, extendable by two further months for complex requests, but only if you tell the person within the first month.

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.

Generate Now

Common Mistakes in GDPR Privacy Policy Templates

Reviewing published policies surfaces the same defects repeatedly:

  • Bundled consent. A single checkbox covering terms, marketing, and cookies violates Article 7(2), which requires consent requests to be clearly distinguishable from other matters.
  • Pre-ticked boxes. The CJEU settled this in Planet49 (Case C-673/17): pre-checked consent is not valid consent.
  • Copying a competitor's policy. Their processors are not yours, and their legal bases are not yours. It also risks a copyright claim.
  • Listing rights that do not apply. Offering data portability for processing based on legitimate interests is inaccurate and signals the policy was never assessed.
  • No named controller. Article 13(1)(a) requires an identity and contact details. A generic contact form is not a substitute for identifying the legal entity.
  • Stale third-party lists. The most frequent failure. The policy was accurate the day it was published and drifted the first time someone added a tracking tag.
  • Undated policies. Without a version date you cannot demonstrate the Article 5(2) accountability principle.

Keeping a GDPR Privacy Policy Accurate Over Time

Compliance is a state your policy is in, not a document you produced once. Article 5(2) makes the controller responsible for demonstrating compliance, which means being able to show the policy matched reality at any given point.

Three habits keep the gap closed. Re-scan after every marketing or product change, because new tags arrive without legal review. Review the full policy at least annually against your Article 30 records. Notify data subjects of material changes rather than editing quietly, since Article 13(3) requires informing people before processing their data for a new purpose.

Tooling can carry part of this. TermsBox generates a privacy policy from a scan of your live site, so the recipient list starts accurate, and its scanner re-checks the site on a schedule. On the Starter tier at $12 per month, or $9 per month billed annually, documents update as the scanner detects new cookies and trackers, with monthly scans; Pro at $25 per month moves that to weekly scans across all policy types. The free tier gives you the base templates and manual scans if you would rather maintain the document yourself.

Whichever route you take, the test a regulator applies is the same: does the published document describe what your website actually does with personal data? A privacy policy generator that builds from real scan data answers that question better than any static template you fill in by hand.

Frequently Asked Questions

Is a free GDPR privacy policy template good enough for compliance?

A free GDPR privacy policy template gives you the correct structure, but it cannot know your actual data practices. Compliance depends on whether the document accurately describes the personal data you collect, your legal bases under Article 6, and every third party you share data with, so any template must be edited against a real inventory of your processing.

What is the difference between a privacy policy and a GDPR privacy notice?

The GDPR itself never uses the phrase privacy policy. Articles 13 and 14 require you to provide information to data subjects, which regulators such as the ICO call a privacy notice. In practice the two terms describe the same public-facing document, so a GDPR privacy notice template and a privacy policy template GDPR search return the same thing.

Do I need a GDPR privacy policy if my business is not in the EU?

Yes, if you offer goods or services to people in the EU or monitor their behaviour, including through analytics or advertising cookies. Article 3(2) applies the GDPR extraterritorially based on whose data you process, not where your company is registered, so a US or UK company with EU visitors is in scope.

What legal basis should I list in my privacy policy?

You must state a specific Article 6(1) legal basis for each processing purpose, not one basis for the whole document. Common combinations are contract for order fulfilment, consent for marketing emails and non-essential cookies, legal obligation for tax records, and legitimate interests for fraud prevention, which also requires a documented balancing test.

How often does a GDPR privacy policy need to be updated?

Update it whenever your processing changes: a new analytics tool, a new payment processor, a new retention period, or a new international transfer. Article 13(3) requires you to inform data subjects before you use their data for a new purpose, so silent edits to a live policy are not sufficient for material changes.

What are the penalties for an inadequate GDPR privacy policy?

Transparency failures fall in the higher tier of Article 83(5), with fines up to 20 million EUR or 4 percent of global annual turnover, whichever is higher. Regulators have applied this in practice, including the Irish DPC's 225 million EUR fine against WhatsApp in 2021, which was based primarily on Articles 12 to 14 transparency breaches.

Related Tools

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app

Related Articles

Privacy Policy

GDPR Policy Template: What to Include and How to Use It

A complete GDPR policy template guide covering every required disclosure under Articles 13 and 14, plus how to adapt a free template to your business.

July 24, 202614 min read
Privacy Policy

Sample GDPR Privacy Policy: Full Template and Section Guide

A sample GDPR privacy policy with every required section explained, plus the Article 13 and 14 disclosures regulators check for and common mistakes.

July 24, 202617 min read
Privacy Policy

Terms of Service Privacy Policy Generator: Complete Guide

How a terms of service privacy policy generator works, what each document must cover, and how to pick a tool that keeps both pages legally accurate.

July 24, 202615 min read

Ready to Create Your Legal Documents?

Generate professional privacy policies, terms of service, and more in minutes. Free to start, no credit card required.

View All Generators

On This Page

  • What a GDPR Privacy Policy Template Actually Is
  • The 13 Disclosures Every GDPR Privacy Policy Template Must Cover
  • Why a Free GDPR Privacy Policy Template Fails Without Editing
  • Legal Basis Is Site-Specific
  • Recipients Depend on Your Actual Stack
  • Retention Periods Cannot Be Guessed
  • International Transfers Changed After Schrems II
  • Legal Bases Mapped to Common Website Activities
  • How to Adapt a GDPR Privacy Policy Template to Your Business
  • Data Subject Rights Your GDPR Privacy Policy Template Must Explain
  • Common Mistakes in GDPR Privacy Policy Templates
  • Keeping a GDPR Privacy Policy Accurate Over Time
  • Frequently Asked Questions
TermsBox

Scan your website, auto-generate legal documents, add a consent banner, and stay compliant. One platform for everything.

Product
  • Cookie Scanner
  • Consent Banner
  • Cookie Policy Generator
  • Pricing
Generators
  • Privacy Policy Generator
  • Terms and Conditions Generator
  • EULA Generator
  • Disclaimer Generator
  • Return and Refund Policy Generator
Company
  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
GDPR
ePrivacy
CCPA
LGPD
Google Consent Mode v2
IAB TCF 2.2
© 2026 TermsBox. All rights reserved.