A privacy notice is an explanation of real processing. It is not a licence to collect whatever the document happens to mention.
Start with the system, not a template. Inspect forms, authentication, payments, analytics, support, email, logs, embedded media, advertising, and any AI feature. A notice copied from another website will usually omit a recipient or claim a purpose that does not match the product.
Build a fact table
Create one row for each purpose:
| Field | What to record |
|---|---|
| Purpose | The specific outcome, not “business purposes” |
| Data | The fields and inferred data used |
| Source | The person, a customer, a public source, or another party |
| Article 6 basis | The basis that applies to this purpose |
| Article 9 condition | Required where special-category data is processed |
| Recipients | Processors, controllers, authorities, and categories |
| Transfers | Destination and Chapter V safeguard |
| Retention | A period or the criteria used to decide it |
| Rights | Which rights apply and how to exercise them |
Verify this table with the people who built and operate the service. A network trace, vendor list, database schema, and deletion jobs are better evidence than an old policy.
Map the table to Articles 13 and 14
When data comes from the person, Article 13 of the GDPR generally requires:
- the controller and contact details;
- the data protection officer’s details, where applicable;
- purposes and lawful bases;
- legitimate interests, where that is the basis;
- recipients;
- international transfers and safeguards;
- retention period or criteria;
- the applicable rights and complaint route;
- whether providing data is required and the consequences of not doing so; and
- meaningful information about relevant automated decision-making.
Article 14 adds information about the categories and source when the data was not obtained from the person, subject to its conditions and exceptions.
Use plain language and put essential information at the point of collection. The AEPD’s layered information guide shows how a short first layer can link to fuller detail.
Avoid five common failures
- One basis for everything. Bases apply to purposes, not to a company as a whole.
- Unnamed “trusted partners.” Describe the actual recipients or meaningful categories.
- No usable retention rule. “As long as necessary” merely repeats the legal test.
- A blanket consent statement. Contract, legal obligation, legitimate interests, or another basis may be more accurate for a particular purpose.
- A policy that outruns the product. Do not claim encryption, regional hosting, deletion, or a response time unless the implementation supports it.
Publish, connect, and maintain it
Link the notice from every relevant collection point. Keep the link public and readable without an account. Make it accessible from mobile forms and OAuth consent-screen domains.
Give the document a true revision date. Review it when a vendor, purpose, field, transfer, retention job, or user journey changes. Keep a change log or approval record for material versions.
Publishing the notice only addresses transparency. It does not by itself make the processing lawful, secure, minimal, or responsive to rights.
GDPR.Direct can generate an editable first draft and host it in a legal hub. The output is based on the facts you provide. Verify every statement against the live service, and seek qualified review for unusual bases, special-category data, profiling, children, or complex transfers.
This article is educational information, not legal advice.