GDPR Privacy Policy Requirements: What Your Policy Must Include
What GDPR requires in a website privacy policy: the Article 13 and 14 disclosure obligations, the mandatory clauses (controller, purposes, legal basis, retention, rights), and how a privacy policy differs from a cookie policy and consent banner.
Disclaimer: This guide is for informational purposes only and does not constitute legal advice (hukuki tavsiye değildir). GDPR compliance depends on your specific data processing activities, the nature of the personal data you handle, and evolving regulatory guidance from European data protection authorities. You should consult qualified legal counsel before relying on any information presented here.
If your website collects personal data — and virtually every modern website does, whether through contact forms, analytics cookies, newsletter sign-ups, or e-commerce checkouts — you need a privacy policy. Under the General Data Protection Regulation (GDPR), a privacy policy (often called a privacy notice or fair processing notice) is not optional window dressing. It is a legal obligation codified in Articles 12, 13, and 14, and it is one of the most visible, externally scrutinised documents your organisation publishes. A well-drafted privacy policy does more than satisfy a compliance checkbox: it builds trust with your visitors, demonstrates accountability to regulators, and serves as the foundation for every other data protection practice — from consent collection to data subject rights fulfilment. Conversely, an incomplete, inaccurate, or missing privacy policy is an open invitation to regulatory complaints, DPA investigations, and fines. This guide explains what a privacy policy is, how it differs from related documents like cookie policies and consent banners, what GDPR Articles 13 and 14 specifically require you to disclose, the minimum clauses every compliant privacy policy must contain, and how Nuvo Consent's role as a data processor fits into your own compliance obligations.
Privacy policy vs. cookie policy vs. consent banner: understanding the differences
One of the most common points of confusion we see at Nuvo Consent is the conflation of three distinct compliance documents: the privacy policy, the cookie policy, and the consent banner. They serve different legal functions, satisfy different regulatory obligations, and failing to distinguish them can create compliance gaps. A privacy policy is your comprehensive legal disclosure that explains how your organisation collects, uses, stores, shares, and protects personal data across all channels — your website, mobile app, email communications, customer support interactions, and any offline data processing. It is the umbrella document that covers your entire data processing ecosystem. A cookie policy is a narrower, more focused document that specifically addresses the cookies, pixels, local storage, and similar tracking technologies deployed on your website or app. It answers questions like: what trackers are present, what categories do they fall into, what data do they collect, how long do they persist, and how can visitors manage their preferences. A consent banner is not a policy document at all — it is a user interface element that collects and records visitor consent choices in real time. It presents the categories of tracking, links to the full cookie policy and privacy policy, and captures the user's granular opt-in or opt-out decisions. All three must work together. The consent banner collects the choice; the cookie policy explains what cookies are in play; and the privacy policy provides the full legal disclosure that GDPR requires. For a deeper dive into the consent side of this triangle, see our GDPR cookie consent requirements guide .
What GDPR Articles 13 and 14 require you to disclose
Articles 13 and 14 of the GDPR are the specific provisions that mandate what information you must provide to data subjects — and they are surprisingly detailed. Article 13 applies when you collect personal data directly from the individual (for example, when someone fills out a contact form, creates an account, or subscribes to a newsletter on your site). Article 14 applies when you obtain personal data indirectly — that is, from a source other than the data subject themselves (for example, when you purchase a marketing list, receive data from a business partner, or collect publicly available information). The disclosure obligations under both articles are largely the same, but Article 14 adds additional requirements around the source of the data and the categories of personal data concerned. At the moment of collection — or within a reasonable period not exceeding one month for indirectly obtained data — you must provide: the identity and contact details of the data controller (your organisation, plus your EU representative if you are based outside the EU); the contact details of your Data Protection Officer if you have appointed one; the purposes of the processing and the legal basis for each purpose; the legitimate interests pursued by the controller or a third party if legitimate interest is the legal basis relied upon; the recipients or categories of recipients of the personal data; whether you intend to transfer personal data to a third country or international organisation, and if so, the existence or absence of an adequacy decision and the safeguards in place; the period for which the personal data will be stored, or the criteria used to determine that period; the data subject's rights — access, rectification, erasure, restriction, data portability, and objection; the right to withdraw consent at any time where consent is the legal basis; the right to lodge a complaint with a supervisory authority; whether the provision of personal data is a statutory or contractual requirement and the consequences of failing to provide it; and the existence of automated decision-making, including profiling, and meaningful information about the logic involved. This is a substantial list, and every element must be addressed in clear, plain language. A privacy policy that omits any of these items — or buries them in impenetrable legalese — is not compliant.
The minimum clauses every privacy policy must include
While the exact structure and wording of your privacy policy will depend on your organisation, jurisdictions, and data processing activities, every GDPR-compliant policy should include at minimum the following sections. Data controller identity: your legal entity name, physical address, email address, and — if you have one — the contact details of your Data Protection Officer and EU representative. This is not a nice-to-have; Article 13(1)(a) and (b) require it. Categories of personal data: the types of data you collect, grouped logically — for example, identity data (name, email), technical data (IP address, browser type), usage data (pages visited, time on site), and marketing data (preferences, newsletter engagement). Purposes and legal bases: for each category of data and each processing activity, state what you use the data for and which of the six GDPR legal bases applies — consent, contract, legal obligation, vital interests, public task, or legitimate interest. If you rely on legitimate interest, you must explain what that interest is and how you balanced it against the data subject's rights. Data retention: how long you keep each category of data, or the criteria you use to determine retention periods. Vague statements like 'we keep your data as long as necessary' are insufficient; specify actual periods or clear criteria. Data sharing and recipients: the categories of third parties with whom you share data — for example, hosting providers, analytics services, email delivery platforms, payment processors — and whether any of them are outside the EU/EEA. International transfers: if data leaves the jurisdiction, explain the transfer mechanism (adequacy decision, Standard Contractual Clauses, Binding Corporate Rules) and how data subjects can obtain a copy. Data subject rights: list all eight GDPR rights — access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making — and explain how to exercise each one. Cookie and tracking disclosure: either a dedicated section or a clear link to your standalone cookie policy that covers the trackers in use. Contact and complaints: how to contact you with privacy questions and the right to lodge a complaint with a supervisory authority. Updates and last revised date: when the policy was last updated and, if practical, a change log of material updates. This structure may look demanding, but each section maps directly to a specific GDPR article or recital — and courts and DPAs will measure your policy against these exact requirements.
How Nuvo Consent handles your data as a processor
Under GDPR, the distinction between a data controller and a data processor is fundamental to understanding your compliance obligations — and ours. As a Nuvo Consent customer, you are the data controller: you determine the purposes and means of processing the personal data collected through your website, including the consent data that our platform manages on your behalf. Nuvo Consent is a data processor: we process personal data only on your documented instructions, for the specific purpose of providing the consent management service you have subscribed to. This means we do not use your visitors' consent data for our own purposes. We do not sell it, we do not aggregate it across customers, and we do not repurpose it for product analytics or model training without your explicit opt-in consent. Our processing activities are governed by a Data Processing Agreement (DPA) that incorporates the Article 28 mandatory terms, including: processing only on your documented instructions; confidentiality commitments from all personnel authorised to process the data; technical and organisational measures appropriate to the risk; obligations to assist you in responding to data subject rights requests; obligations to assist you with data breach notification and data protection impact assessments; restrictions on engaging sub-processors without your authorisation; and deletion or return of all personal data at the conclusion of the service. Our DPA is publicly available and does not require a custom negotiation: you can review and accept it at our DPA page .
Building and maintaining a GDPR-compliant privacy policy
A GDPR-compliant privacy policy is not a one-time document you draft, publish, and forget. It is a living disclosure that must evolve with your data processing activities, your technology stack, and the regulatory landscape. The best approach is to treat your privacy policy as a reflection of your actual data practices — not as a legal artefact that exists in isolation. Start by mapping your data flows: what data enters your organisation, through what channels, for what purposes, and where it goes. Then draft your policy directly from that map, ensuring every Article 13 and 14 disclosure point is addressed in plain language. Link it prominently — from your website footer, your consent banner, your sign-up forms, and your checkout flow — so that it is never more than one click away. Review and update it whenever you add a new third-party service, change your analytics setup, or enter a new market. And make sure your cookie policy and consent banner are consistent with what your privacy policy says — inconsistency across these three documents is one of the most common findings in DPA audits and enforcement actions. Nuvo Consent's own privacy policy follows the structure we recommend in this guide, and you can see it live at our privacy policy page .