A privacy notice is the document your customers, leads and applicants actually read to understand what you do with their personal data - and the one a regulator checks first because it's public. Getting it right is less about legal polish than about completeness: every category of personal data you process, every purpose and every legal basis have to be in there. This guide covers exactly what GDPR requires, how to write a privacy notice step by step, and where to get a template that you adapt rather than copy.
- Articles 13 and 14 GDPR define the mandatory content - in plain language, not legal boilerplate.
- A privacy notice must name every processing purpose and its legal basis, including the tools used to carry it out (CRM, email, AI), not generic categories.
- A privacy notice template is a starting point, never a finished product.
What Must a Privacy Notice Include Under GDPR?
Which information is mandatory?
Articles 13 and 14 GDPR set the minimum content. A compliant privacy notice covers all of the following:
- Name and contact details of the controller (your company).
- Contact details of the Data Protection Officer, if you have appointed one.
- The purposes of processing and the legal basis for each (Art. 6).
- The recipients or categories of recipients - including your sub-processors.
- Any transfers of data outside the EU/EEA, and the safeguards for them.
- Retention periods, or the criteria used to set them.
- Data subject rights: access, rectification, erasure, restriction, objection, portability.
- The right to withdraw consent, where processing is based on consent.
- The right to lodge a complaint with a supervisory authority.
- Whether providing the data is a statutory or contractual requirement.
If your processing involves automated decision-making or profiling, you must say so and explain the logic and consequences. Anything missing here is a gap a regulator will flag - so this list doubles as your privacy notice checklist.
How to Write a Privacy Notice, Step by Step
Where do I start - the template or the content?
Start with the content, not the template. A template structures the document, but it can't know which tools you run. Work in this order:
1. List every processing purpose. Pull the purposes straight from your Record of Processing Activities (ROPA) - if it's in the ROPA, it belongs in the notice. One purpose can involve several tools, and one tool can serve several purposes.
2. Assign the legal basis, the tools and recipients, and the retention period to each purpose. "Sending our newsletter - consent (Art. 6(1)(a))" is specific; "we process data for business purposes" is not.
3. Name your recipients and sub-processors. HubSpot, Intercom, an AI tool, your hosting provider - name them.
4. State retention and transfers. How long you keep each category, and whether any data leaves the EU.
5. Write the rights section in plain language, with a working contact route to exercise them.
6. Publish it where people actually encounter the data collection - website footer, signup forms, app onboarding.
How do I keep it current as tools change?
Build a lightweight rule: when a new tool is introduced, one named person checks whether it processes personal data, and if so, the privacy notice is updated within two weeks. No committee, no approval chain - one person, one process, one deadline. A notice that's accurate today and stale in three months is a common and avoidable failure.
GDPR Privacy Notice Template (DOCX)
Common Privacy Notice Mistakes
Where do SMEs usually go wrong?
- Generic text from a generator, published unchanged. It doesn't know your processing purposes and tools, so it doesn't describe your processing.
- Only the website is covered. The CRM, newsletter platform and support chat process data too and belong in the notice.
- Wrong legal basis. "Legitimate interest" is not a catch-all - where consent is required, it must be named and obtained.
- Never updated. Every new vendor or processing activity needs a corresponding update.
- No working route to exercise rights. A rights section with no reachable contact is incomplete.
Privacy Notice Generator vs. Doing It Properly
Can I just use a privacy notice generator?
As a starting point, yes - as a finished product, no. A generator produces standard text that doesn't know your specific tools, vendors or legal bases. Treat its output as a skeleton: add every purpose and tool, verify every legal basis, and remove clauses that don't apply to you. A generated notice published without that work does not meet GDPR requirements, and the gap is easy for a regulator to spot.
The same applies to the template below - it gives you structure and prompts, but the value is in adapting it to your real processing. If you'd rather not maintain this by hand, ETHYX generates the notice from your ROPA and flags it for review whenever a new tool is added.