This is a worksheet, not ready-to-publish legal text. Complete it with verified facts, then turn those facts into a clear notice and obtain the review appropriate to your service.
1. Identify the controller and scope
Record:
- full legal name, registration details, address, and contact;
- trading names and products covered;
- controller, joint-controller, and processor roles;
- EU representative and DPO details where required;
- countries and customer groups; and
- separate notices needed for applicants, staff, suppliers, or enterprise end users.
Do not list a processor as the controller for customer content merely because it hosts the service.
2. Complete one row per purpose
| Purpose | Data and source | Article 6 basis | Article 9 | Recipients and location | Retention | Rights |
|---|---|---|---|---|---|---|
| Account access | ||||||
| Product delivery | ||||||
| Billing and tax | ||||||
| Support | ||||||
| Security and fraud | ||||||
| Service analytics | ||||||
| Product email | ||||||
| Marketing |
Add rows for uploads, collaboration, integrations, public profiles, location, AI, research, referrals, or advertising where applicable.
3. Inspect SaaS-specific data paths
Authentication
Record email, identity-provider identifiers, session data, logs, and account-recovery events. Explain whether Google or another provider acts independently for parts of the flow.
Payments
Identify the payment provider and distinguish fields your server receives from card data handled only by the provider. Record invoice and tax retention separately from ordinary account data.
Customer content
Explain whether the SaaS acts as processor for tenant-submitted content. A public privacy notice may not replace the Article 28 agreement and tenant instructions for that activity.
Support and telemetry
Tickets and logs often contain unexpected personal data. Define redaction, access, retention, and transfer controls. Avoid putting secrets or personal data in URLs.
AI
Describe inputs, provider, model location, retention, training use, human access, output use, and available controls. Do not say data is not used for training without a contract and configuration that support the statement.
4. Write the required information
Articles 13 and 14 of the GDPR require information including purposes, bases, recipients, transfers, retention, rights, complaints, data source, mandatory fields, and relevant automated decisions. Include legitimate interests where used and explain meaningful consequences rather than copying the article.
Use layered notices at registration, checkout, forms, and integrations. A footer policy alone may be too remote from collection.
5. Verify vendors and transfers
For every recipient, record:
- legal entity and role;
- service and data;
- processing locations;
- subprocessors;
- Article 28 contract;
- Chapter V transfer route;
- supplementary measures where required; and
- exit and deletion process.
Avoid listing only brand names. The contracted entity can differ by customer region.
6. Make retention executable
State a period or usable criterion for each category. Connect it to configured jobs and exceptions. Consider production, logs, support, analytics, deleted accounts, backups, invoices, and disputes.
7. Test rights and publication
Use a test account to exercise access, correction, deletion, portability, consent withdrawal, and objection. Confirm what remains, why, and for how long.
Then:
- compare the notice with a network trace and vendor register;
- search for placeholders and unsupported security claims;
- verify every email and link;
- check mobile and accessibility;
- record the true review date and approver; and
- review after material product or legal changes.
GDPR.Direct can convert completed business answers into an editable draft and hosted Legal Hub. It does not discover all data paths, validate the answers, or certify the final notice.
This worksheet is educational information, not legal advice.