Do You Need a Privacy Policy Under GDPR? What to Include
GDPR requires transparency about data processing in practice, which almost always means a real privacy policy. Here's what has to be in it and where generic templates fall short.
GDPR doesn’t use the phrase “privacy policy” and technically requires “transparent information” about your processing rather than a specific document by that name, but in practice, a privacy policy is how essentially every site satisfies that requirement. The real question isn’t whether you need one; it’s whether the one you have actually meets the standard.
What GDPR’s transparency requirement actually demands
Articles 13 and 14 of GDPR set out specific information that has to be provided to individuals about how their data is processed. At minimum, that includes:
- Who you are, the identity and contact details of the data controller.
- What data you collect and why, the categories of personal data and the purpose of processing each.
- Your lawful basis for each type of processing (see our piece on legitimate interest vs. consent for the cookie-specific version of this).
- Who you share data with, categories of recipients, including third-party processors.
- How long you retain data.
- International transfers, if data leaves the EU/EEA, and the safeguards in place.
- Individual rights, access, rectification, erasure, and how to exercise them (see our DSAR guide for the mechanics).
- How to complain to a supervisory authority if someone isn’t satisfied with your response.
Where generic template policies fall short
A copy-pasted privacy policy template technically has sections covering most of the above, but the content inside those sections often doesn’t match what the site actually does. This mismatch, disclosed practices that don’t reflect real data flows, is one of the more common issues that surfaces in complaints and audits, because it’s the easiest gap to spot: someone compares the policy’s claims against what the site’s cookies and third-party requests actually reveal.
Usercentrics
A consent platform that scans your actual trackers helps keep your privacy policy honest, Usercentrics' scanning identifies what's really running on your site, which is the same information your policy needs to accurately disclose.
What to actually check in your current policy
- Does it list your real third-party tools by name or category, analytics provider, payment processor, chat vendor, rather than vague boilerplate language?
- Does the lawful basis stated for each processing purpose actually match reality, are you claiming consent where you’re actually relying on legitimate interest, or vice versa?
- Is the retention period stated specifically, rather than a vague “as long as necessary” with no further detail?
- Does it reflect your current tracker stack, not the one you had when the policy was first written? Tools get added over time; policies rarely get updated to match.
The connection to your cookie banner
A privacy policy and a cookie banner should tell the same story. If your banner discloses four tracker categories but your privacy policy only mentions “cookies and similar technologies” generically, that’s a gap worth closing, see our piece on what a compliant cookie banner actually requires for the banner side of this.
This guide is educational and not legal advice. It isn’t a substitute for a properly drafted privacy policy reviewed by counsel. For your specific situation, consult a privacy attorney.