Why your privacy policy is strategic
Beyond a legal requirement, a clear privacy policy builds trust and conversion. The GDPR requires transparent processing information (Articles 12 to 14 of Regulation (EU) 2016/679) and fundamental principles (lawfulness, minimisation, security: art. 5 and 32). Breaches may attract penalties up to €20m or 4% of worldwide turnover (art. 83 GDPR via EUR-Lex — EU law portal). CNIL reiterates that information must be easily accessible and understandable, particularly for very small businesses, SMEs and startups (CNIL — integrating GDPR into your startup; CNIL — very small businesses/SMEs).
Practical tip: make the policy available from every key page (footer, onboarding, mobile app) and align it with your terms of use/sale and SaaS contract to avoid discrepancies.
The 10 essential sections to include
1) Controller and contacts
- Controller identity and contact details (and DPO where applicable: art. 13.1.a GDPR).
- Dedicated contact channel for GDPR rights.
2) Data collected (categories)
- Account data (identity, contact), product use (logs, events), billing, support, marketing.
- Special categories where relevant (health, biometric) and appropriate basis.
3) Purposes and legal bases
- Performance of a contract (account creation, service provision).
- Legitimate interest (product improvement, security, measured B2B prospecting).
- Consent (B2C newsletter, non-essential cookies, SMS marketing, profiling).
- Legal obligation (accounting, responses to authorities).
Reference: art. 6 GDPR and EDPB guidelines on lawfulness and consent (EDPB — European Data Protection Board).
4) Recipients and processors
- Cloud, email, analytics, helpdesk and payment providers.
- Contractual clauses (art. 28 GDPR) and documented instructions.
5) Transfers outside the EU/EEA
- Mechanisms: adequacy decision, standard contractual clauses (SCCs), and transfer impact assessment (EDPB post-Schrems II recommendations; EDPB — European Data Protection Board).
6) Retention periods
- Limitation principle: define periods by purpose, then anonymise or delete (art. 5.1.e GDPR).
- Publish a readable table (“active account”, “prospects”, “logs”, etc.).
7) Individuals' rights and arrangements
- Access, rectification, erasure, restriction, objection, portability, post-mortem instructions where applicable.
- Response period: 1 month (extendable by 2 months); information about CNIL for complaints (art. 12 and 15 to 22 GDPR; CNIL — French data protection authority).
8) Security
- Technical and organisational measures: encryption, access management, logging, testing (art. 32 GDPR).
- Notify breaches to CNIL within 72 hours where there is a risk (art. 33; CNIL — French data protection authority).
9) Cookies/trackers and analytics
- Consent banner for non-essential trackers, proof of consent, ability to withdraw consent at any time (CNIL, ePrivacy).
- Separate cookie policy or dedicated section, linked from the privacy policy.
10) Updates and versioning
- Procedure for notifying material changes, timestamped versions, accessible archive.
Useful official resources: Service-public Pro — personal data obligations, France Num — managing data properly, Legifrance — French legislation portal, EUR-Lex — GDPR, CNIL — Startups, CNIL — very small businesses/SMEs.
A 7-step method for sound drafting
- Map processing: what data, why, where, who accesses it, for how long. Use a record (art. 30) even with < 250 employees: CNIL recommends it (startup guide).
- Select the legal basis for each purpose and check whether consent is needed (see EDPB guidelines; EDPB — European Data Protection Board).
- Define justified, operational retention periods (scheduled deletion/anonymisation).
- Regulate processors (art. 28 DPA, audits, access logs, security plan).
- Assess transfers outside the EU (SCCs + supplementary assessment) and document them (EDPB — European Data Protection Board).
- Prepare rights-request procedures (identity validation, 1-month SLA, traceability).
- Publish the policy, review for plain language, link from terms of use/sale, provide a compliant cookie banner and preference centre. Train teams.
Legal bases: common startup use cases
- User account and service provision: contract performance (art. 6.1.b GDPR).
- Product improvement, limited audience measurement (without non-essential trackers) and security: legitimate interest (6.1.f), with a balancing test and opt-out where appropriate.
- B2C newsletter, personalised advertising, non-essential cookies, SMS prospecting: consent (6.1.a), withdrawable at any time.
- Billing/accounting: legal obligation (6.1.c).
- AI/ML using personal data: document lawfulness (contract/legitimate interest/consent depending on the case) and privacy by design (art. 25). See our dedicated guide GDPR and AI: legal obligations.
Retention periods: how to set them
The GDPR requires retention “no longer than necessary” (art. 5.1.e). Recommended practice:
- Define a period for each purpose (e.g. account data = contract duration + minimum necessary archiving period).
- Distinguish inactive prospects from customers, technical logs from business data.
- Automate deletion/anonymisation and record deletions.
Processors and international transfers
- Art. 28 GDPR contracts: subject matter, duration, security, subprocessors, breach assistance, exit arrangements.
- Transfers outside the EU/EEA: check for an adequacy decision; otherwise SCCs + supplementary measures + local-law assessment (EDPB guides).
Cookies, analytics and prospecting
- Banner before placing non-essential trackers; refusal as simple as acceptance; proof of consent (CNIL).
- B2C electronic prospecting subject to prior consent; B2B possible under conditions with clear information and an easy right to object (CNIL reference frameworks).
- Create a separate cookie policy linked from the GDPR policy.
DPIAs, security and breach management
- DPIA (impact assessment, art. 35) if high risk: large-scale monitoring, sensitive data, systematic tracking, minors. CNIL and EDPB publish lists and guides (CNIL — French data protection authority; EDPB — European Data Protection Board).
- Security (art. 32): encryption, testing, secrets management, least privilege, logging. For more on code and secrets, see our source code protection good practice.
- Breach: notify CNIL within 72 hours if there is a risk to individuals, and notify individuals if the risk is high (art. 33-34; CNIL — French data protection authority).
Customisable privacy policy template (copy/paste)
Adapt this outline to your product, complete the brackets and check legal bases and retention periods against your processing record.
<h2>Who are we?</h2>
[Company name], [legal form], [RCS], [address]. GDPR contact: [email].
DPO: [contact details] (if applicable).
<h2>What data do we collect?</h2>
Categories: [identity, contact, product use, billing, support, marketing, ...].
Sources: [you/partners/third parties].
<h2>Why, and on what legal basis?</h2>
Purposes/bases:
- Service provision (contract art. 6.1.b): [details].
- Improvement & security (legitimate interest art. 6.1.f): [details, balancing test available on request].
- Marketing & non-essential cookies (consent art. 6.1.a): [details, withdrawal at any time].
- Legal obligations (art. 6.1.c): [details].
<h2>Who do we share your data with?</h2>
Processors: [list/categories], governed by art. 28 GDPR. Statutory recipients: [if required].
<h2>Transfers outside the EU/EEA</h2>
Mechanisms: [adequacy/SCCs], supplementary measures, assessment of local laws.
<h2>How long do we retain your data?</h2>
By purpose: [summary table]. At the end, deletion or anonymisation.
<h2>Your rights</h2>
Access, rectification, erasure, restriction, objection, portability. Exercise your rights: [email/form].
Period: 1 month. Complaints: CNIL (www.cnil.fr).
<h2>Security</h2>
Technical/organisational measures: [encryption, access control, testing].
<h2>Cookies</h2>
See our cookie policy: [link]. Settings via the Preference Centre.
<h2>Minors</h2>
[Specific age/consent conditions if applicable].
<h2>Updates</h2>
Version: [date]. We will notify you of any material change.
Common mistakes to avoid
- Generic copy-paste that does not reflect actual processing.
- Forgetting your tools' transfers outside the EU (support, logs, analytics).
- Confusing legitimate interest with no need for consent for marketing trackers.
- Publishing without internal procedures (rights, deletion, breaches) or a record (art. 30).
Integrate privacy into documents and operations
Harmonise the policy with terms of use/sale and B2B contracts (processing, security, exit clauses). Our guides to differences between terms of use and terms of sale and key SaaS clauses detail the connections. Organisationally, a legal ops approach helps document the record, automate deletion and manage risks. Finally, if using AI, define datasets and legal bases using our GDPR and AI article.
Further reading
Related resources
- GDPR and artificial intelligence: legal obligations for businesses
- SaaS terms of sale: essential clauses for online software
- Differences between terms of use and terms of sale, and related obligations
- Protecting a startup's source code: copyright and practice
- Legal ops for startups: organising the legal function
Frequently asked questions
FAQ
What must a GDPR privacy policy contain?
Controller/DPO identity, data categories, purposes and legal bases, recipients and transfers, retention periods, rights and how to exercise them, security, cookies/trackers, updates.
How should you choose the appropriate legal basis?
Match each purpose to a basis: contract for service provision, legal obligation for accounting, legitimate interest for security/improvement (after a balancing test), consent for marketing/non-essential cookies.
Does a small startup need a record of processing activities?
Yes, CNIL strongly recommends it. The < 250 employee exemption is limited and does not cover non-occasional, sensitive or risky processing.
What is the response period for an access or deletion request?
1 month from receipt (extendable by 2 months for complexity), with information to the individual concerned.
How should transfers outside the EU/EEA be managed?
Check for an adequacy decision; otherwise use SCCs, add supplementary measures and document a local-law assessment in accordance with EDPB recommendations.
References
Sources used
- Personal data protection obligations | Entreprendre.Service-public.fr
- How to manage personal data properly | France Num
- EDPB — European Data Protection Board
- How to integrate GDPR into your startup | CNIL
- Applying GDPR in a very small business or SME: CNIL questions and answers
- Startup: turning GDPR compliance into an advantage — CNIL
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.