Since the GDPR took effect GDPR May 2018, any company that collects personal data is required to clearly inform its users about how that data is used. Download our free GDPR policy template, drafted by our DPOs and compliant with the recommendations of the CNIL (National Commission for Information Technology and Civil Liberties).
Good to Know: GDPR Charter and Privacy Policy: One and the Same Document
Why Your Website Needs a GDPR Policy
What is a GDPR policy GDPR
A GDPR policy GDPR a legal document that explains how your organization collects, uses, stores, and protects the personal data of your users, clients visitors. Articles 13 and 14 of GDPR that any person whose data you collect be clearly informed before or at the time of collection. The privacy of your users’ data is at the heart of what the GDPR policy GDPR guarantee.
Who is subject to the GDPR
Any organization that collects personal data is affected, regardless of its size: VSB, SMB, nonprofit organizations, local governments, startups, and e-commerce businesses. The GDPR rules GDPR as soon as your organization processes personal data, even in small quantities.
What are the risks of not having a GDPR policy GDPR
The absence of a GDPR policy GDPR your organization to penalties from the CNIL (National Commission for Information Technology and Civil Liberties) undermines your users’ trust. Preventing these risks requires rigorous implementation from the moment your website goes live.
⬇️ Download your free GDPR policy template
To comply with Articles 13 and 14 of GDPR, your GDPR policy GDPR include:
- The identity and contact information of the data controller (your organization)
- The contact information for the DPO (Data Protection Officer), if you have one
- The purposes and legal basis for each processing activity (individual consent, legitimate interest, legal obligation, performance of a contract, etc.)
- Recipients of the data (service providers, processors, partners)
- The Data retention period for each data category
- The rights of the individuals : access, rectification, erasure, objection, portability, restriction
- How to Exercise These Rights: How Your Users Can Contact You
- The right to file a complaint with the CNIL (National Commission for Information Technology and Civil Liberties)
- The existence of transfers outside the EU, if any, and the associated safeguards
Dipeeo Tip: Your GDPR policy GDPR directly GDPR from your data processing inventory. If you don’t have one yet, this is the first document you should create: it lists all of your data processing activities and serves as the backbone of your GDPR compliance.
Data Security and the GDPR What's the Connection?
GDPR Policy GDPR Information Systems Security
The GDPR companies to define and implement security measures appropriate to their data processing activities: access control, encryption, audit trails, and notification of a data breach to the CNIL (National Commission for Information Technology and Civil Liberties) 72 hours. The expected level of security is proportional to the sensitivity of the data being processed. If in doubt, a specialized IT security firm can assist your DPO.
GDPR IT Policy GDPR A Separate Document for Your Employees?
The GDPR Policy GDPR for your users. The IT Policy, on the other hand, outlines the responsibilities of each employee regarding internal data protection. The two documents are complementary, and it is recommended that they be implemented simultaneously.
⬇️ Download your free GDPR policy template
Individual Rights: What Your GDPR Policy GDPR Guarantee
What rights does the GDPR your users?
Right of access, rectification, erasure, objection, data portability, and restriction: Your GDPR policy GDPR list these rights and explain how your users can exercise them.
How should your company respond?
Your company must respond within one month, which may be extended to three months for complex requests. If you receive a large volume of requests, a rights management tool can help you meet these deadlines.
CNIL (National Commission for Information Technology and Civil Liberties) Penalties CNIL (National Commission for Information Technology and Civil Liberties) Noncompliance
What penalties does the CNIL (National Commission for Information Technology and Civil Liberties) impose CNIL (National Commission for Information Technology and Civil Liberties)
The CNIL (National Commission for Information Technology and Civil Liberties) issue a warning, a formal notice, or a financial penalty of up to 20 million euros or 4% of annual global revenue. Violations of the obligation to provide information are among the most frequently cited reasons during its inspections. Check the CNIL (National Commission for Information Technology and Civil Liberties) news CNIL (National Commission for Information Technology and Civil Liberties) stay informed about its priorities for the current year.
We handle your compliance from start to finish
Downloading the template is a good place to start. However, you’ll still need to identify your data processing activities, fill in the fields, publish the policy on your website, and keep it up to date whenever changes occur. If you’d rather focus on your business, we can handle it for you from start to finish.
Here's what Dipeeo actually does for your GDPR policy GDPR
- Assessment of Current Practices: Your GDPR policy GDPR what you actually do—not a generic template.
- Custom-written content: drafted by a legal professional dedicated to your company, tailored to your business and your tools.
- Updates included: new tool, new service provider, new Purpose we've got it covered.
- Data Rights Management: Requests for access, correction, and deletion—handled on your behalf within the timeframes set by CNIL (National Commission for Information Technology and Civil Liberties).
- Access to our compliance platform: all your documents centralized in your Dipeeo account.
Beyond the GDPR guidelines, Dipeeo handles all aspects of your compliance as an external DPO registered with the CNIL (National Commission for Information Technology and Civil Liberties). Drafting and updating your documents, managing your users’ data access requests, securing your data processing operations, and preparing for CNIL (National Commission for Information Technology and Civil Liberties) audits CNIL (National Commission for Information Technology and Civil Liberties) you’ll have a dedicated legal expert who understands your business and keeps track of regulatory changes on your behalf.
[Learn more about outsourced DPO services]
Frequently Asked Questions About the GDPR Policy
GDPR a GDPR privacy policy required for an e-commerce website?
Yes, without exception. An e-commerce site collects order, shipping, payment, and often browsing data.
The GDPR policy GDPR be accessible from every page of the website, in the footer and on every data collection form, before the user submits their information.
GDPR the GDPR policy mandatory for an association or a local government?
Yes. The GDPR to any organization that collects personal data, whether it is a company, an association, a local government, or a healthcare facility.
The GDPR policy GDPR mandatory whenever a form, a member area, or a digital communication tool is used.
GDPR a GDPR policy GDPR to ensure full compliance with GDPR
No. The GDPR the obligation to provide information, but full compliance also requires a record of processing activities, a cookie policy, internal security procedures, and a process for handling requests to exercise data subject rights.
Dipeeo takes care of all of these aspects for you.
Where should you post your GDPR policy GDPR your website?
The GDPR policy GDPR be accessible from every page on your website, ideally via a link in the footer.
It must also be included on every data collection form (contact, registration, order) before the user submits the form.
Do you need to update your GDPR policy GDPR you switch tools or service providers?
Yes. Every new data processing activity—a new CRM tool, a new email marketing service provider, a new payment system—must be reflected in your GDPR policy.
The Dipeeo model is designed to facilitate these updates without requiring a complete rewrite.
Are the GDPR Charter GDPR the Privacy Policy the same thing?
Yes. GDPR Policy, GDPR “Privacy Policy,” “Data Protection Policy,” and “Privacy Statement” all refer to the same document.
The GDPR not GDPR a specific name: only the content is governed by the regulation.
What is the difference between a GDPR policy GDPR an IT policy?
The GDPR policy GDPR for your users and clients it informs them about how their data is processed.
The IT Policy is intended for your employees: it sets out guidelines for the internal use of digital tools and the rules for data processing in a professional context. The two documents are complementary.