← Back to blog
EU Privacy Law

Does My EU Website Need a Privacy Policy? GDPR Requirements Explained

By DataShark · 23 June 2026 · 8 min read
?>

If your website is accessible to visitors in the European Union — or if you're based in an EU member state — you almost certainly need a Privacy Policy. This isn't optional. The EU General Data Protection Regulation (GDPR) makes it a legal requirement, and the consequences of getting it wrong can be severe.

Does EU GDPR apply to my website?

The EU GDPR (Regulation 2016/679) has an unusually broad territorial scope, set out in Article 3. It applies to you if:

In practice, this means that almost any website with EU visitors — including US-based, UK-based, and non-EU international businesses — falls within the scope of EU GDPR if it collects personal data from EU residents.

Personal data includes email addresses, IP addresses, names, cookie identifiers, and any other information that can be linked to an identifiable individual. If you use Google Analytics, Mailchimp, or a contact form, you are collecting personal data.

What does EU GDPR require in a Privacy Policy?

Under Articles 13 and 14 of the EU GDPR, you must provide specific information to data subjects at the time their data is collected. This information is typically contained in a Privacy Policy. The required disclosures include:

Identity and contact details of the data controller

Your business name, registered address, and contact details. If you have a Data Protection Officer (DPO), their contact details must also be provided.

EU representative (if applicable)

If your business is established outside the EU but processes EU residents' data, Article 27 requires you to appoint an EU representative and name them in your Privacy Policy. This is a commonly overlooked requirement for non-EU businesses.

Purposes and legal basis for processing

You must state why you process personal data and what legal basis you rely on under Article 6. The six lawful bases are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Vague statements like "to improve your experience" are not sufficient.

Categories of data collected and recipients

You must list the types of personal data you collect and name the third-party processors you share it with — including Google, Stripe, Mailchimp, and any advertising platforms.

International data transfers

If you transfer personal data outside the EEA (for example, to US-based cloud services), you must disclose this and state the safeguard used — typically Standard Contractual Clauses (SCCs) or an adequacy decision.

Retention periods

Article 5(1)(e) requires that data is not kept longer than necessary. Your Privacy Policy must state how long you retain each category of data, or the criteria used to determine retention periods.

Data subject rights

You must inform users of all eight rights under EU GDPR: access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), objection (Article 21), rights related to automated decision-making (Article 22), and the right to withdraw consent (Article 7(3)).

Right to complain to a supervisory authority

You must tell users they have the right to lodge a complaint with the relevant national supervisory authority — for example, the CNIL in France, the BfDI in Germany, the Garante in Italy, or the DPC in Ireland.

What about the ePrivacy Directive and cookies?

In addition to EU GDPR, the ePrivacy Directive (2002/58/EC) applies to the use of cookies and similar tracking technologies. It requires prior informed consent before placing non-essential cookies — analytics and advertising cookies require an opt-in, not just a notice.

If your website uses Google Analytics, Facebook Pixel, or any advertising cookies, you need both a Privacy Policy and a Cookie Policy, plus a compliant cookie consent mechanism (consent banner).

⚠ A cookie banner that pre-ticks consent boxes or uses dark patterns (making "reject" harder to find than "accept") does not constitute valid consent under EU GDPR. Several EU supervisory authorities have issued significant fines for non-compliant consent mechanisms.

Which supervisory authority oversees my compliance?

If you are established in an EU member state, your lead supervisory authority is the data protection regulator in the country where your EU establishment is based — for example:

If you are not established in the EU, the supervisory authority of the member state where your EU representative is based, or where your EU customers are located, will typically have jurisdiction.

What are the penalties for not having a Privacy Policy?

The EU GDPR imposes two tiers of administrative fines:

Failing to have a compliant Privacy Policy — or having one that doesn't include the required Article 13/14 disclosures — falls into the first tier. Regulators have issued fines to businesses of all sizes, including small businesses and sole traders.

How to get a GDPR-compliant Privacy Policy for your EU website

  1. Know what data you collect — email addresses, IP addresses, payment data, cookies
  2. Know your legal basis — consent, contract, or legitimate interests for each purpose
  3. List your third-party processors — Google Analytics, payment providers, email marketing tools
  4. Determine your retention periods — how long you keep customer data, contact data, transaction data
  5. Identify your supervisory authority — based on your EU member state of establishment
  6. Generate your Privacy Policy — personalised to your business, not a generic template

DataShark generates a personalised EU GDPR Privacy Policy in under 3 minutes. It automatically includes your supervisory authority, EU representative clause (if applicable), lawful basis statements, processor disclosures, and all mandatory Article 13 information — from €10.

Ready to generate your GDPR policy?

Answer a few questions about your business and get a personalised, legally-structured document in minutes.

Start free — from £29 →