Privacy Policy

Knowledge Base | Privacy Policy | What is a GDPR privacy policy?

What is a GDPR privacy policy?

A GDPR privacy policy explains how an organization processes personal data and meets the regulation’s transparency requirements. Often called a privacy notice, it covers:

  • Who controls the data and how to contact them.

  • What information is processed, why, and on which legal bases.

  • Who receives it, relevant international transfers, and retention periods.

  • Individuals’ rights, how to exercise them, and how to complain.

  • Additional details where applicable, such as data sources and significant automated decisions.

Articles 13 and 14 distinguish information collected directly from people from information obtained elsewhere. The notice must be clear, accessible, and provided at the required time. The EDPB’s transparency guidance explains these obligations.

Publishing a policy supports GDPR compliance, but does not replace lawful processing, appropriate security, or effective rights procedures.