Free GDPR Privacy Policy Template
A GDPR privacy policy tells people what personal data you collect, why, how long you keep it, and how they can have it deleted. This free template satisfies Articles 12–14 of the EU GDPR and the UK GDPR.
What must a GDPR privacy policy include?
Controller identity and contact details, DPO details where applicable, purposes and lawful basis for each processing activity, legitimate interests relied on, recipients, international transfers and safeguards, retention periods, data subject rights, the right to complain to a supervisory authority, and any automated decision-making or profiling.
Do US businesses need a GDPR privacy policy?
Yes, if you offer goods or services to people in the EU or UK or monitor their behaviour. Article 3 makes the GDPR extraterritorial, and non-EU controllers may also need an Article 27 EU representative.
Consent, cookies, and ePrivacy
A privacy policy alone does not make tracking lawful. Non-essential cookies need prior, informed, freely given consent collected in a banner where rejecting is as easy as accepting; the policy describes the cookie categories.
Keeping the policy accurate
Update it whenever you add a processor, change retention, transfer data to a new country, or launch profiling features, and keep a dated version history.
Frequently asked questions
Is a free GDPR privacy policy template enough for compliance?
It gets the required disclosures in place, but you must edit it to match the data you actually collect, the processors you use, and your real retention periods. Article 5(1)(a) requires transparency, so an inaccurate policy is itself a breach.
What is the fine for not having a GDPR privacy policy?
Transparency breaches sit in the higher tier of Article 83: up to €20 million or 4% of worldwide annual turnover, whichever is greater.
Do I need a data protection officer?
Only if you are a public authority, carry out large-scale regular and systematic monitoring, or process special category data at scale. Most small SaaS companies name a privacy contact instead.
Can one policy cover GDPR, UK GDPR, and CCPA?
Yes — typically a single policy with a UK addendum naming the ICO and a California addendum covering data sold or shared plus the do-not-sell/share link.
Where should the privacy policy link appear?
In the site footer on every page, at every point of collection, in the cookie banner, and in your app store listing.