The Legal Hub gives an organisation one public URL for its generated document drafts. It solves hosting and linking. It does not verify the facts or turn the documents into evidence that the underlying controls operate.
What can appear
The standard public set contains:
- Legal Notice
- Privacy Policy
- Cookie Policy
- Recruitment Privacy
- Processing Activities
- Exercise Your Rights
Tenants that declare special-category processing can also see a clinical document set. Those drafts need an additional professional review because the correct Article 9 condition, clinical duties, and national law depend on the service.
Owners can hide documents from the public hub. A hidden item remains in the dashboard but is also removed from embeds. Use that control when a draft is incomplete or a document does not apply.
1. Complete the business facts
Before sharing the hub, verify:
- legal entity, trading name, registration, and contact details;
- every purpose and lawful basis;
- Article 9 conditions, where relevant;
- real fields and data-subject categories;
- processors, recipients, subprocessors, and locations;
- international transfers and safeguards;
- retention periods or criteria;
- rights contact and internal response process; and
- cookies and similar technologies found in a technical scan.
Do not guess to make the wizard complete. Record unknowns and resolve them with the owner of the system.
2. Review each draft
Read the whole document in both selected languages. Search for:
- placeholders;
- providers no longer used;
- broad consent wording;
- generic retention;
- unsupported claims about encryption or regional hosting;
- an Article 28 contract confused with transfer SCCs;
- health-data consent used where another Article 9 condition may apply; and
- a date that suggests review when none occurred.
Compare the text with the live product, contracts, and configuration. Use a qualified data-protection reviewer for uncertain classifications and a native reviewer for translated public text.
3. Choose a publication method
Link to the hosted hub
Copy the public hub URL from the dashboard. Add it to the website footer, checkout, registration, and relevant collection points. This keeps the full set in one place.
Link to a specific hosted document
Where a form needs a direct notice link, use the relevant public document URL rather than asking the visitor to navigate a long hub.
Embed a document
The dashboard can generate an iframe snippet for a visible document. Paste the exact snippet into the page and give the frame enough height. Do not construct tenant or document identifiers manually.
Embeds are convenient, but also test:
- loading when third-party content is restricted;
- keyboard navigation and readable focus;
- mobile width and height;
- a meaningful title on the iframe;
- language selection;
- failure or timeout behaviour; and
- whether security headers on the host allow the frame.
Provide a normal link as a fallback.
4. Verify the public release
Use a signed-out browser:
- open the hub URL;
- confirm only intended documents appear;
- open every document and search for placeholders;
- verify the controller and contact details;
- test rights links and email addresses;
- inspect mobile and keyboard use;
- check that hidden documents and their embed routes are unavailable;
- test both languages where published; and
- compare the cookie text with a current storage scan.
Capture the version reviewed, reviewer, date, source evidence, defects, and approval. A public page returning 200 is not the same as substantive approval.
5. Maintain the hub
Review after a new vendor, purpose, field, country, transfer, retention rule, pricing flow, cookie, or legal requirement. GDPR.Direct does not currently inspect those systems or automatically prove that a legal change affects a tenant’s facts. Treat update prompts and document generation as the start of review, not its completion.
This guide is educational information, not legal advice.