If your website is accessible to visitors in the European Union — or if you're based in an EU member state — you almost certainly need a Privacy Policy. This isn't optional. The EU General Data Protection Regulation (GDPR) makes it a legal requirement, and the consequences of getting it wrong can be severe.
Does EU GDPR apply to my website?
The EU GDPR (Regulation 2016/679) has an unusually broad territorial scope, set out in Article 3. It applies to you if:
- Your organisation is established in the EU — regardless of where your data processing takes place
- You are based outside the EU but offer goods or services to people in the EU (even for free)
- You are based outside the EU but monitor the behaviour of people in the EU (for example, through analytics or advertising cookies)
Personal data includes email addresses, IP addresses, names, cookie identifiers, and any other information that can be linked to an identifiable individual. If you use Google Analytics, Mailchimp, or a contact form, you are collecting personal data.
What does EU GDPR require in a Privacy Policy?
Under Articles 13 and 14 of the EU GDPR, you must provide specific information to data subjects at the time their data is collected. This information is typically contained in a Privacy Policy. The required disclosures include:
Identity and contact details of the data controller
Your business name, registered address, and contact details. If you have a Data Protection Officer (DPO), their contact details must also be provided.
EU representative (if applicable)
If your business is established outside the EU but processes EU residents' data, Article 27 requires you to appoint an EU representative and name them in your Privacy Policy. This is a commonly overlooked requirement for non-EU businesses.
Purposes and legal basis for processing
You must state why you process personal data and what legal basis you rely on under Article 6. The six lawful bases are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Vague statements like "to improve your experience" are not sufficient.
Categories of data collected and recipients
You must list the types of personal data you collect and name the third-party processors you share it with — including Google, Stripe, Mailchimp, and any advertising platforms.
International data transfers
If you transfer personal data outside the EEA (for example, to US-based cloud services), you must disclose this and state the safeguard used — typically Standard Contractual Clauses (SCCs) or an adequacy decision.
Retention periods
Article 5(1)(e) requires that data is not kept longer than necessary. Your Privacy Policy must state how long you retain each category of data, or the criteria used to determine retention periods.
Data subject rights
You must inform users of all eight rights under EU GDPR: access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), objection (Article 21), rights related to automated decision-making (Article 22), and the right to withdraw consent (Article 7(3)).
Right to complain to a supervisory authority
You must tell users they have the right to lodge a complaint with the relevant national supervisory authority — for example, the CNIL in France, the BfDI in Germany, the Garante in Italy, or the DPC in Ireland.
What about the ePrivacy Directive and cookies?
In addition to EU GDPR, the ePrivacy Directive (2002/58/EC) applies to the use of cookies and similar tracking technologies. It requires prior informed consent before placing non-essential cookies — analytics and advertising cookies require an opt-in, not just a notice.
If your website uses Google Analytics, Facebook Pixel, or any advertising cookies, you need both a Privacy Policy and a Cookie Policy, plus a compliant cookie consent mechanism (consent banner).
⚠ A cookie banner that pre-ticks consent boxes or uses dark patterns (making "reject" harder to find than "accept") does not constitute valid consent under EU GDPR. Several EU supervisory authorities have issued significant fines for non-compliant consent mechanisms.
Which supervisory authority oversees my compliance?
If you are established in an EU member state, your lead supervisory authority is the data protection regulator in the country where your EU establishment is based — for example:
- Germany — Federal Commissioner for Data Protection (BfDI)
- France — CNIL
- Ireland — Data Protection Commission (DPC)
- Netherlands — Autoriteit Persoonsgegevens (AP)
- Italy — Garante per la Protezione dei Dati Personali
- Spain — Agencia Española de Protección de Datos (AEPD)
- Poland — UODO
If you are not established in the EU, the supervisory authority of the member state where your EU representative is based, or where your EU customers are located, will typically have jurisdiction.
What are the penalties for not having a Privacy Policy?
The EU GDPR imposes two tiers of administrative fines:
- Up to €10 million or 2% of global annual turnover (whichever is higher) for less severe infringements — including failures to provide required information to data subjects
- Up to €20 million or 4% of global annual turnover (whichever is higher) for the most serious infringements — including unlawful processing and violations of data subject rights
Failing to have a compliant Privacy Policy — or having one that doesn't include the required Article 13/14 disclosures — falls into the first tier. Regulators have issued fines to businesses of all sizes, including small businesses and sole traders.
How to get a GDPR-compliant Privacy Policy for your EU website
- Know what data you collect — email addresses, IP addresses, payment data, cookies
- Know your legal basis — consent, contract, or legitimate interests for each purpose
- List your third-party processors — Google Analytics, payment providers, email marketing tools
- Determine your retention periods — how long you keep customer data, contact data, transaction data
- Identify your supervisory authority — based on your EU member state of establishment
- Generate your Privacy Policy — personalised to your business, not a generic template
DataShark generates a personalised EU GDPR Privacy Policy in under 3 minutes. It automatically includes your supervisory authority, EU representative clause (if applicable), lawful basis statements, processor disclosures, and all mandatory Article 13 information — from €10.
Ready to generate your GDPR policy?
Answer a few questions about your business and get a personalised, legally-structured document in minutes.
Start free — from £29 →