TermsBox
PricingBlog
LoginGet Started
PricingBlogLogin
Get Started
  1. Home
  2. Blog
  3. Sample GDPR Privacy Policy: Full Template and Section Guide
Privacy Policy

Sample GDPR Privacy Policy: Full Template and Section Guide

A sample GDPR privacy policy with every required section explained, plus the Article 13 and 14 disclosures regulators check for and common mistakes.

TermsBox Team|July 24, 202617 min read

If you are looking for a sample GDPR privacy policy, you probably want two things: a document you can model your own on, and a clear explanation of why each section exists. This guide gives you both, with a complete sample GDPR privacy policy broken into annotated sections tied to the specific GDPR articles that require them. The content here is educational rather than legal advice, so treat it as a working reference and consult a qualified attorney for anything specific to your business.

What a GDPR Privacy Policy Actually Is

A GDPR privacy policy is a public-facing document that tells people whose personal data you process what you collect, why you collect it, what legal basis permits it, who else receives it, how long you keep it, and what rights they have over it. The General Data Protection Regulation (GDPR) does not use the phrase "privacy policy" anywhere in its text. The obligation comes from Article 13 (data collected directly from the person) and Article 14 (data obtained from other sources), which is why the UK Information Commissioner's Office (ICO) prefers the term "privacy notice."

The distinction matters more than it sounds. A privacy policy in the older, pre-GDPR sense was often a general statement of intent. Article 13 instead requires a fixed list of specific disclosures, delivered at the time data is collected, in a form that Article 12(1) describes as "concise, transparent, intelligible and easily accessible," using "clear and plain language."

Two practical consequences follow. First, a generic gdpr privacy policy example that you paste in unchanged will almost certainly be inaccurate, because it will describe processing you do not do and omit processing you do. Second, length is not a virtue. A twelve-page policy that buries the retention period in paragraph 40 fails the Article 12 accessibility test even if every required item is technically present.

The Mandatory Sections in Any Sample GDPR Privacy Policy

Before the sample itself, here is the checklist Article 13 imposes. Every item on this list must appear in a compliant policy where the situation applies to you:

  • Identity and contact details of the controller, and of the controller's representative where Article 27 applies.
  • Contact details of the Data Protection Officer (DPO), where one has been designated under Article 37.
  • The purposes of the processing and the legal basis for each purpose under Article 6(1).
  • The legitimate interests pursued, where you rely on Article 6(1)(f), stated specifically rather than as a generic reference.
  • The recipients or categories of recipients of the personal data.
  • Any transfer to a third country, the safeguard used, and how to obtain a copy of that safeguard.
  • The retention period, or the criteria used to determine it, under Article 13(2)(a).
  • The data subject rights in Articles 15 to 22, including the right to withdraw consent under Article 7(3) where consent is the basis.
  • The right to lodge a complaint with a supervisory authority.
  • Whether providing the data is a statutory or contractual requirement, and the consequences of not providing it.
  • The existence of automated decision-making, including profiling, with meaningful information about the logic involved, under Article 22.

Article 14 adds one more item when you did not get the data from the person directly: the source of the data, and whether it came from a publicly accessible source.

A Complete Sample GDPR Privacy Policy

The following gdpr privacy statement example uses a fictional company, Northline Analytics Ltd, a UK-based SaaS company selling to EU customers. Replace every bracketed value and, more importantly, delete every section that does not describe what you actually do.

1. Who We Are

Northline Analytics Ltd ("Northline," "we," "us") is the data controller for the personal data described in this notice. We are registered in England and Wales under company number 12345678, at 14 Fenwick Street, Manchester, M1 4AB, United Kingdom.

Our EU representative under Article 27 of the GDPR is [Representative Name], [EU address], reachable at [email].

Our Data Protection Officer can be reached at [email protected] or at the postal address above.

The controller identity is the first Article 13(1)(a) requirement and the one most often handled badly. "Northline Analytics" alone is not enough. A registered name, company number, and postal address let a data subject or regulator identify the legal entity responsible.

2. What Personal Data We Collect

Account data: name, business email address, company name, hashed password, and account role. Collected directly from you at signup.

Billing data: billing address, VAT number, and the last four digits and expiry of your payment card. Full card numbers are collected and stored by our payment processor, not by us.

Usage data: pages viewed within the application, feature interactions, timestamps, browser type, operating system, and IP address.

Support data: the contents of messages you send us, including any personal data you choose to include.

Marketing data: email engagement events (opens, clicks) where you have subscribed to our newsletter.

Group data by category rather than listing every field, but keep the categories granular enough to be informative. "Personal information" as a single category is not a disclosure. Note the explicit statement about card data: telling people what you do not collect prevents a common misunderstanding.

3. Why We Process It and Our Legal Basis

The GDPR requires a legal basis under Article 6(1) for every purpose. A table is the clearest way to present this, and it forces you to notice purposes that have no valid basis.

Purpose Data used Legal basis
Creating and administering your account Account data Article 6(1)(b), performance of a contract
Processing payments and issuing invoices Billing data Article 6(1)(b), performance of a contract
Complying with tax and accounting law Billing data Article 6(1)(c), legal obligation
Detecting fraud and abuse Usage data, account data Article 6(1)(f), legitimate interests
Product analytics to improve features Usage data Article 6(1)(a), consent via cookie banner
Sending our newsletter Marketing data Article 6(1)(a), consent
Responding to support requests Support data Article 6(1)(b), performance of a contract

Where we rely on legitimate interests, our interest is in keeping the service secure and preventing unauthorized access to customer accounts. We have assessed that this does not override your rights, because the data used is limited to security-relevant events and is retained for 90 days.

That last paragraph matters. Article 13(1)(d) requires you to state the legitimate interests pursued, and simply writing "our legitimate business interests" has been criticized by supervisory authorities as meaningless. Naming the interest, and summarizing the balancing test, is what the provision asks for.

4. Who We Share It With

We share personal data with the following categories of recipient:

  • Cloud hosting: Amazon Web Services EMEA SARL (data stored in the eu-west-1 region, Ireland).
  • Payment processing: Paddle.com Market Ltd, acting as merchant of record.
  • Email delivery: Resend, Inc. (United States).
  • Product analytics: [Analytics provider], only where you have consented.
  • Professional advisers: our accountants and legal counsel, where required.

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.

Article 13(1)(e) permits "recipients or categories of recipients," but naming actual companies is the safer and more useful approach. It is also increasingly the regulator expectation: the European Data Protection Board's transparency guidelines state that the default should be to name recipients unless there is a good reason not to.

5. International Transfers

Some of our processors are located outside the European Economic Area. Where personal data is transferred to the United States, we rely on the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, supplemented by our own transfer impact assessment. Where a recipient is certified under the EU-US Data Privacy Framework, we rely on the adequacy decision of 10 July 2023.

You can request a copy of the safeguards we use by emailing [email protected].

Article 13(1)(f) requires you to identify the safeguard and explain how to obtain a copy. Since the Schrems II judgment (Case C-311/18, July 2020), a bare reference to "appropriate safeguards" without naming the mechanism is not adequate.

6. How Long We Keep It

  • Account data: for the life of your account, then 30 days after deletion.
  • Billing records: six years from the end of the accounting period, to meet UK and EU tax record-keeping requirements.
  • Usage and security logs: 90 days.
  • Support correspondence: three years from the date of last contact.
  • Marketing data: until you unsubscribe, then 12 months to honor your suppression preference.

Article 13(2)(a) allows either a period or the criteria used to determine it. Specific periods are stronger, and each one should have a reason you could defend. "As long as necessary" is the most common failing phrase in real policies, and it communicates nothing.

7. Your Rights

Under the GDPR you have the right to:

  • Access your personal data and receive a copy (Article 15).
  • Rectify inaccurate or incomplete data (Article 16).
  • Erase your data in the circumstances set out in Article 17.
  • Restrict processing in the circumstances set out in Article 18.
  • Data portability, receiving your data in a structured, commonly used, machine-readable format (Article 20).
  • Object to processing based on legitimate interests, and to direct marketing at any time (Article 21).
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 22).
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal (Article 7(3)).

To exercise any right, email [email protected]. We respond within one month, as required by Article 12(3), and will tell you if we need to extend that period by up to two further months.

You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EU, you may complain to the authority in your country of residence or workplace.

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.

Generate Now

8. Cookies and Tracking

We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These do not require consent under Article 5(3) of the ePrivacy Directive.

All other cookies, including product analytics, are set only after you consent through our cookie banner. You can change your choices at any time through the "Cookie settings" link in our footer. A full inventory of the cookies we use, with purpose and duration, is available in our Cookie Policy.

Cookie consent is governed by Article 5(3) of the ePrivacy Directive (2002/58/EC as amended), not by the GDPR alone, though the GDPR supplies the consent standard. This is why a compliant setup pairs the privacy policy with a separate cookie policy and a real consent mechanism rather than a notice-only banner.

9. Automated Decision-Making

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.

If that statement is true, say it plainly. If it is not, Article 13(2)(f) requires meaningful information about the logic involved and the significance and envisaged consequences for the individual.

10. Changes to This Notice

This notice was last updated on 24 July 2026. If we make material changes to how we process your personal data, we will notify registered users by email at least 14 days before the change takes effect. Previous versions are available on request.

How to Adapt This GDPR Privacy Policy Example to Your Business

A sample GDPR privacy policy is a starting structure, not a finished document. The adaptation work is where compliance actually happens, and it follows a fixed order:

  1. Inventory your actual data flows. List every form, integration, script, and vendor that touches personal data. Most teams discover processors nobody documented, typically an analytics tag or a support widget added by marketing.
  2. Assign a legal basis to each purpose. If you cannot name a basis, you cannot lawfully do the processing. This step frequently eliminates processing rather than documenting it.
  3. Write specific retention periods. Ask the owner of each dataset why the period is what it is. Storage limitation is an Article 5(1)(e) principle, not an optional extra.
  4. Confirm every named recipient. Delete vendors you no longer use. A policy naming a processor you dropped 18 months ago is evidence you are not maintaining it.
  5. Check the transfer mechanism for each non-EEA processor. Standard Contractual Clauses, an adequacy decision, or a derogation under Article 49. There is no fourth option.
  6. Test the reading level. Article 12(1) requires plain language. If a non-lawyer on your team cannot summarize a section after one read, rewrite it.

Running an automated scan of your own site shortens step one considerably, because it surfaces the third-party scripts and cookies actually loading in a visitor's browser rather than the ones your team remembers adding. TermsBox does this and maps detected vendors into the corresponding privacy policy and cookie policy sections.

Article 14: When You Did Not Collect the Data Directly

Article 14 applies when personal data reaches you from somewhere other than the data subject: a data broker, a partner referral, a public register, or an enrichment provider. The disclosure list is the same as Article 13, plus two additions.

  • The categories of personal data concerned. Article 13 assumes the person knows what they gave you. Article 14 does not, so you must spell out the categories.
  • The source of the data, including whether it came from a publicly accessible source.

The timing rules also differ. Under Article 14(3), you must provide the information within a reasonable period and at the latest within one month of obtaining the data, or at the time of first communication if that comes sooner. A B2B company enriching leads from a third-party database and emailing them without ever sending this notice is in breach, and this specific pattern has drawn enforcement across several member states.

Common Mistakes in Real GDPR Privacy Policies

The failures below appear repeatedly in regulator decisions and in audits of live sites.

  • Vague legal bases. Listing all six Article 6 bases and letting the reader guess which applies to what. Regulators treat this as no disclosure at all.
  • Consent as a catch-all. Claiming consent for processing you actually need for the contract. This is worse than useless, because it gives the person a right to withdraw and stop service delivery you were entitled to perform anyway.
  • "We may share your data with third parties." No categories, no names. This fails Article 13(1)(e) outright.
  • Retention stated as "as long as necessary." No period, no criteria, no compliance with Article 13(2)(a).
  • Rights listed without a route to exercise them. Article 12(2) requires you to facilitate the exercise of rights, which means a working contact point and a process behind it.
  • A cookie banner that contradicts the policy. The policy says analytics run on consent, but the tag fires on page load before any choice is made. Regulators check the site, not just the text.
  • No version history. When the policy changes silently, you cannot show which version applied at the time of a given processing activity.

The last two are the ones that turn a documentation problem into an enforcement problem, because they are observable from outside your organization.

GDPR Privacy Policy Versus Other Privacy Documents

Confusion between these documents leads to teams publishing the wrong thing or believing they are covered when they are not.

Document Audience Required by
Privacy policy / privacy notice Data subjects (public) GDPR Articles 13 and 14
Record of Processing Activities (ROPA) Supervisory authority on request GDPR Article 30
Data Processing Agreement (DPA) Processors you engage GDPR Article 28(3)
Data Protection Impact Assessment (DPIA) Internal, plus the authority for prior consultation GDPR Article 35
Cookie policy Website visitors ePrivacy Directive Article 5(3) plus GDPR

Only the privacy policy and cookie policy are published. The ROPA and DPIA are internal records you produce on request, and Article 30(5) exempts organizations under 250 employees from the ROPA only where processing is occasional, poses no risk to rights, and excludes special category data, which in practice exempts very few businesses.

Building Your Own Instead of Copying a Sample

Once you understand what each section must contain, the mechanical work of writing a policy is not the hard part. Keeping it accurate is. A policy is a snapshot of your processing on the day it was written, and processing changes every time someone adds a script, switches an email provider, or ships a feature that logs something new.

A privacy policy generator that asks structured questions about your data flows produces a more accurate result than editing a gdpr privacy policy example by hand, because it forces the legal basis and retention decisions instead of letting you skip them. On paid TermsBox plans starting at $12 per month, scans run on a schedule and flag when a newly detected vendor means your published policy no longer matches reality, so you find out before a data subject or a regulator does.

Whichever route you take, treat the published document as something you own and maintain, not something you install once. Diary a review at least annually, and immediately after any change to your stack that touches personal data.

Frequently Asked Questions

Can I copy a sample GDPR privacy policy for my own website?

You can use a sample GDPR privacy policy as a structural reference, but copying it verbatim creates legal risk because Article 13 requires disclosures specific to your actual processing activities. A policy that lists processors you do not use, or omits ones you do, is inaccurate and unenforceable as a compliance defense.

What is the difference between a privacy policy and a privacy notice under GDPR?

The GDPR itself never uses the term privacy policy. Articles 13 and 14 refer to information provided to data subjects, which regulators such as the ICO call a privacy notice. In practice the two terms are used interchangeably for the public-facing document on your website.

Does a GDPR privacy policy need to list every cookie and tracker?

The GDPR requires you to identify the categories of personal data and the recipients of that data, so you must at minimum disclose each third party receiving data. Regulators including CNIL expect a full cookie inventory with purpose and duration, which is why most sites publish a separate cookie policy linked from the privacy policy.

What are the penalties for an inadequate GDPR privacy policy?

Breaches of the Article 13 and 14 transparency obligations fall in the higher penalty tier under Article 83(5), up to 20 million EUR or 4 percent of global annual turnover, whichever is higher. The CNIL fine against Google in January 2019 of 50 million EUR was based substantially on information that was not easily accessible or sufficiently clear.

How often should a GDPR privacy policy be updated?

Update it whenever your processing changes: a new analytics tool, a new payment processor, a new purpose, or a new international transfer mechanism. Article 12 requires that changes affecting data subjects be communicated to them, so a silent edit to the page is not sufficient for material changes.

Do I need a GDPR privacy policy if my business is outside the EU?

Yes, if Article 3(2) applies to you. The GDPR reaches any organization that offers goods or services to people in the EU or monitors their behavior, regardless of where the organization is established, and non-EU controllers may also need an EU representative under Article 27.

Related Tools

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app

Related Articles

Privacy Policy

GDPR Policy Template: What to Include and How to Use It

A complete GDPR policy template guide covering every required disclosure under Articles 13 and 14, plus how to adapt a free template to your business.

July 24, 202614 min read
Privacy Policy

GDPR Privacy Policy Template: What It Must Include in 2026

A GDPR privacy policy template must cover 13 disclosures under Articles 13 and 14. Learn what to include, what to avoid, and how to adapt one to your site.

July 24, 202613 min read
Privacy Policy

Terms of Service Privacy Policy Generator: Complete Guide

How a terms of service privacy policy generator works, what each document must cover, and how to pick a tool that keeps both pages legally accurate.

July 24, 202615 min read

Ready to Create Your Legal Documents?

Generate professional privacy policies, terms of service, and more in minutes. Free to start, no credit card required.

View All Generators

On This Page

  • What a GDPR Privacy Policy Actually Is
  • The Mandatory Sections in Any Sample GDPR Privacy Policy
  • A Complete Sample GDPR Privacy Policy
  • 1. Who We Are
  • 2. What Personal Data We Collect
  • 3. Why We Process It and Our Legal Basis
  • 4. Who We Share It With
  • 5. International Transfers
  • 6. How Long We Keep It
  • 7. Your Rights
  • 8. Cookies and Tracking
  • 9. Automated Decision-Making
  • 10. Changes to This Notice
  • How to Adapt This GDPR Privacy Policy Example to Your Business
  • Article 14: When You Did Not Collect the Data Directly
  • Common Mistakes in Real GDPR Privacy Policies
  • GDPR Privacy Policy Versus Other Privacy Documents
  • Building Your Own Instead of Copying a Sample
  • Frequently Asked Questions
TermsBox

Scan your website, auto-generate legal documents, add a consent banner, and stay compliant. One platform for everything.

Product
  • Cookie Scanner
  • Consent Banner
  • Cookie Policy Generator
  • Pricing
Generators
  • Privacy Policy Generator
  • Terms and Conditions Generator
  • EULA Generator
  • Disclaimer Generator
  • Return and Refund Policy Generator
Company
  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
GDPR
ePrivacy
CCPA
LGPD
Google Consent Mode v2
IAB TCF 2.2
© 2026 TermsBox. All rights reserved.