Privacy Policy Template for the European Union (GDPR)
Generate a GDPR-compliant privacy policy for your website, app, or service. Covers all requirements under the General Data Protection Regulation including lawful basis, data subject rights, DPO requirements, and international data transfers.
AI-generated draft for review. Not legal advice. Starting at $29.
Legal Requirements in European Union (GDPR)
Must specify the lawful basis for each type of data processing (Article 6 GDPR)
Must clearly describe all data subject rights (Articles 15-22 GDPR)
Must identify the data controller and provide contact information
Must address international data transfers and the legal mechanisms used (e.g., SCCs, adequacy decisions)
Must describe data retention periods for each category of data
Must appoint a Data Protection Officer (DPO) if required by Article 37
Key Statutes & Regulations
- General Data Protection Regulation (GDPR) 2016/679
- ePrivacy Directive 2002/58/EC (cookies and electronic communications)
- Applicable member state data protection implementing legislation
Common Pitfalls
- •Relying solely on consent when legitimate interest or contractual necessity would be more appropriate
- •Not specifying data retention periods for each category of personal data
- •Failing to address international data transfers (especially post-Schrems II)
- •Using pre-ticked consent boxes (not valid under GDPR)
Local Terminology
- Data Controller
- Entity that determines the purposes and means of processing personal data
- Data Processor
- Entity that processes personal data on behalf of the controller
- Lawful Basis
- Legal justification required under Article 6 GDPR for each processing activity
- DPIA
- Data Protection Impact Assessment — required for high-risk processing activities
- SCCs
- Standard Contractual Clauses — mechanism for international data transfers
How European Union (GDPR) Differs
GDPR requires specific lawful basis for each processing activity — consent, legitimate interest, contract, legal obligation, vital interest, or public task
Data subject rights are extensive: access, rectification, erasure, restriction, portability, and objection
Maximum fines of up to 4% of global annual revenue or EUR 20 million (whichever is higher)
Covers any organization processing EU residents data, regardless of where the organization is located
Frequently Asked Questions
What lawful basis should I use for processing under GDPR?
▾
It depends on the purpose. Common bases include: consent (for marketing emails), contractual necessity (to provide your service), legitimate interest (for analytics and fraud prevention), and legal obligation (for tax records). Each processing activity needs its own lawful basis, documented before processing begins.
Do I need a DPO under GDPR?
▾
You need a DPO if you are a public authority, if your core activities involve regular and systematic monitoring of individuals on a large scale, or if you process special categories of data on a large scale. Even if not required, appointing a DPO is recommended as a best practice.
What are the GDPR fines?
▾
GDPR has two tiers of fines: up to EUR 10 million or 2% of global revenue for lesser violations (e.g., record-keeping failures), and up to EUR 20 million or 4% of global revenue for more serious violations (e.g., violating data subject rights or transferring data without legal basis).
How do I handle international data transfers under GDPR?
▾
You need a legal mechanism: adequacy decision (the destination country has adequate protection), Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or specific derogations. After the Schrems II ruling, you must also conduct a Transfer Impact Assessment to evaluate destination country surveillance laws.
Available in Other Jurisdictions
Related Contract Types
More Templates for European Union (GDPR)
Ready to Create Your Privacy Policy?
Describe your deal in plain English. Three AI agents draft, review, and refine your privacy policy for European Union (GDPR).
Get StartedAI-generated draft for review. Not legal advice.