Who are we?
Provide the name and contact details of the data controller.
This will usually be your business or you if you are a sole trader. Where applicable,
you should provide the identity and contact details of the representative of the controller or data protection officer.
What data do we collect?
Specify the types of personal data you collect, e.g. Names, addresses, usernames, etc.
You should provide certain details about: how you collect data
(eg when a user registers, purchases or uses your services, fills out a contact form, logs in to the network, etc.)
what specific data you collect through each of the data collection methods if you collect data from third parties,
you must specify the categories of data and the source if you process sensitive personal data or financial
data and how you do it
You may wish to provide the user with relevant definitions regarding personal data and sensitive personal data.
How do we use personal data?
Describe in detail all the service and business purposes for which you will process the data.
For example, this may include things like: personalizing content,
business information or user experience account setup and administration delivering marketing communications
and events conducting surveys and polls internal research and development purposes providing goods and services
legal obligations (e.g. fraud prevention) meeting internal audit requirements
Please note that this list is not exhaustive. You will need to record all the purposes for which you process personal data.
What legal basis do we have for processing your personal data?
Describe the relevant processing terms contained in the GDPR.
There are six possible legal bases: consent contract legitimate interests vital interests public task legal obligation
Provide detailed information on all grounds relating to your processing and why.
If you rely on consent, explain how individuals can withdraw and manage their consent.
If you rely on legitimate interests, clearly explain what they are.
If you are processing special category personal data, you will need to meet at least one of the six
processing conditions as well as additional processing requirements under the GDPR.
Provide information on any additional grounds that apply.
When do we share personal information?
Explain that you will treat confidential information confidentially and describe the circumstances
under which you might disclose or share it. For example When necessary for the provision of your services
or the conduct of your business operations, as set out in your processing purposes.
You should provide information on: how you will share data, what safeguards you will have in place,
who you can share data with, and why
Where do we store and process personal data?
If applicable, explain whether you intend to process the data and information outside the home country of the data subject.
Describe the steps you will take to ensure that data is processed in accordance with your privacy policy and the applicable
law of the country where the data is located. If you transfer data outside the European Economic Area,
please specify the measures you will take to ensure an appropriate level of data privacy protection.
For example Contract clauses, data transfer agreements, etc.
How do we secure personal data?
Describe your approach to data security and the technologies and procedures you use to protect personal data.
For example, these may be measures: to protect data from accidental loss to prevent unauthorized access, use,
destruction or disclosure to ensure business continuity and disaster recovery to limit access to personal data
to conduct privacy impact assessments in accordance with the law and your business policies to train staff and
contractors on data security to manage third-party risks, using contracts and security reviews
Please note that this list is not exhaustive. You should note any mechanisms you rely on to protect personal data.
You should also indicate whether your organization adheres to certain accepted standards or regulatory requirements.
How long do we keep your personal data?
Provide specific information about the time interval in which you will store them in relation to each processing purpose.
The GDPR requires you to keep data for as long as is reasonably necessary.
Include details of data or records retention schedules or link to additional resources where published.
If you cannot specify a specific period, you should determine the criteria you will apply to determine how long
the data should be kept (e.g. local laws, contractual obligations, etc.)
You should also state how you dispose of the data securely after you no longer need it.
Your rights in relation to personal data
Under the GDPR, you must respect data subjects' right to access and control their personal data.
In the privacy notice you must set out their rights in relation to: access to personal data rectification
and erasure withdrawal of consent (if data is processed subject to consent) data portability restriction of processing
and objection lodging a complaint with the Information Commissioner's Office You should explain how individuals can
exercise their rights and how you plan to respond to the relevant data requests. State whether any relevant exemptions
may apply and outline the identity verification procedures you can rely on. Include details of the circumstances in
which the data subject's rights may be restricted, e.g. If complying with a data subject's request may expose
personal data about another person or if you are required to delete data that you are required to retain by law.
Use of automated decision making and profiling
Where you use profiling or other automated decision-making, you must disclose this in your privacy policy.
In such cases, you must provide details of the existence of any automated decision-making,
together with information about the logic involved and the likely significance and consequences of the processing
of the individual.
How to contact us?
Explain how the data subject can get in touch if they have questions or concerns about your privacy practices,
their personal data, or if they want to file a complaint.
Describe all the ways I can contact you - eg. Via the Internet, by e-mail or by post.
If applicable, you can also include information about:
Use of cookies and other technologies
You may include a link to additional information or describe within the policy if you intend to set and use cookies,
tracking and similar technologies to store and manage user preferences on your website, advertise, enable content,
or otherwise analyze user and usage data. Provide information about the types of cookies and technologies you use,
why you use them, and how an individual can control and manage them.
Linking to Other Websites / Third Party Content If you link to external websites and resources from your website,
please be clear as to whether this constitutes an endorsement and if you assume any responsibility for the content
(or information contained therein) of any linked website.
You may want to consider adding other optional clauses to your privacy policy,
depending on the circumstances of your business.