“GDPR policy” is not a single document. Organisations searching for a GDPR policy template are usually looking for one of six distinct instruments, and downloading the wrong one produces a document that satisfies nothing.
The six are a privacy notice for individuals, an internal data protection policy for staff, a cookie policy, a data retention policy, a data breach response policy, and a Data Processing Agreement for processors. Each has a different audience, a different legal basis, and different mandatory content.
Free GDPR templates have a specific failure mode. They are structurally sound and substantively empty. A template tells you that you must state your lawful basis. It cannot tell you what your lawful basis is, and that determination is the part a regulator examines.
Two developments in 2026 make templates downloaded before this year unsafe for UK organisations. The Data (Use and Access) Act 2025 came into force on 5 February 2026, changing automated decision-making provisions, introducing recognised legitimate interests, and amending PECR cookie rules.
And the ICO is transitioning to the Information Commission, which means templates referencing the ICO by name will need updating.
This guide sets out what each policy must contain, provides adaptable structures, and explains what a template cannot do for you.
Key Definitions to Know Before Using GDPR Policy Template
| Term | Definition |
|---|---|
| Privacy notice | The external-facing document informing individuals how their personal data is processed. Required by GDPR Articles 13 and 14 |
| Data protection policy | The internal document setting out how staff must handle personal data. Not expressly required but evidences Article 5(2) accountability |
| Cookie policy | The document explaining what cookies a website uses. Governed by PECR in the UK and the ePrivacy Directive in the EU |
| Retention policy | The document setting out how long data categories are kept and why. Evidences Article 5(1)(e) storage limitation |
| Breach response policy | The internal procedure for handling personal data breaches under Articles 33 and 34 |
| DPA | Data Processing Agreement. The Article 28 contract between controller and processor |
| RoPA | Records of Processing Activities. Required under Article 30 |
| DPIA | Data Protection Impact Assessment. Required under Article 35 for high-risk processing |
| DUAA | Data (Use and Access) Act 2025. In force 5 February 2026 |
Which GDPR Policy Template Do You Actually Need
| Document | Audience | Legally required | Published |
|---|---|---|---|
| Privacy notice | Individuals whose data you process | Yes, Articles 13 and 14 | Yes, publicly |
| Internal data protection policy | Your staff | Not expressly, but evidences accountability | No, internal |
| Cookie policy | Website visitors | Yes where cookies are used, under PECR | Yes, publicly |
| Retention policy | Internal, with elements published | Not expressly, but evidences storage limitation | Partly |
| Breach response policy | Internal | Not expressly, but required to meet 72-hour deadline | No, internal |
| Data Processing Agreement | Your processors | Yes, Article 28 | No, contractual |
Most small businesses need the first three at minimum. Organisations processing special category data, running high-risk processing, or acting as processors for others need all six.
1. Privacy Notice
This is the document most people mean when they search for a GDPR policy template. It is the only one of the six that GDPR expressly requires to be provided to individuals.
Articles 13 and 14 set out mandatory content. Article 13 applies where you collect data directly from the individual. Article 14 applies where you obtain it from another source and adds a requirement to state where the data came from.
Mandatory Content
| Element | Article |
|---|---|
| Identity and contact details of the controller | 13(1)(a) |
| Contact details of the DPO, where appointed | 13(1)(b) |
| Purposes of processing | 13(1)(c) |
| Lawful basis for each purpose | 13(1)(c) |
| Legitimate interests pursued, where that is the basis | 13(1)(d) |
| Recipients or categories of recipients | 13(1)(e) |
| International transfers and the safeguards applied | 13(1)(f) |
| Retention period or criteria for determining it | 13(2)(a) |
| Data subject rights: access, rectification, erasure, restriction, portability, objection | 13(2)(b) |
| Right to withdraw consent, where consent is the basis | 13(2)(c) |
| Right to complain to the supervisory authority | 13(2)(d) |
| Whether provision is a statutory or contractual requirement, and consequences of not providing | 13(2)(e) |
| Existence of automated decision-making, including profiling, with meaningful information about the logic | 13(2)(f) |
| Source of the data, where not collected from the individual | 14(2)(f) |
Structure
Who we are. Legal entity name, registered address, registration number, contact point for data protection queries, and DPO details where one is appointed.
What data we collect. Categories, not an exhaustive field list. Contact details, transaction records, website usage data, and so on. State separately if you process any special category data under Article 9.
Why we process it, and on what basis. This is the section templates cannot complete for you. Each purpose needs a stated lawful basis. Where you rely on legitimate interests, state the interest.
Who we share it with. Categories of recipient: payment processors, cloud hosting providers, professional advisers, regulators. Name specific processors where the individual would reasonably expect it.
International transfers. Where data leaves the UK or EEA, state the destination and the safeguard: adequacy decision, IDTA, UK Addendum, SCCs, or another Article 46 mechanism.
How long we keep it. Either the period or the criteria used to determine it. Vague statements that data is kept “as long as necessary” without criteria do not satisfy Article 13(2)(a).
Your rights. List them and explain how to exercise them. Include the right to complain and name the supervisory authority.
Automated decision-making. Where you use it, explain the logic in meaningful terms and the significance and consequences for the individual. This section has become materially more important following the Dutch DPA’s €825 million fine against Uber in August 2026 for automated driver deactivations.
Changes. How you notify individuals of changes and when the notice was last updated.
2. Internal Data Protection Policy
GDPR does not expressly require an internal data protection policy. Article 5(2) requires you to demonstrate compliance with the data protection principles, and Article 24 requires appropriate technical and organisational measures including data protection policies where proportionate.
In practice, an internal policy is the primary evidence that you have those measures.
What This GDPR Policy Template Should Cover
| Section | Content |
|---|---|
| Scope | Who the policy applies to: employees, contractors, volunteers, temporary staff |
| The principles | The six Article 5 principles and what each means operationally in your organisation |
| Roles and responsibilities | Who owns data protection, who the DPO is where appointed, what line managers must do |
| Lawful basis | How staff determine and record the lawful basis before starting new processing |
| Data minimisation in practice | Rules on what staff may collect and what they may not |
| Data subject rights handling | Who receives requests, the response deadline, the escalation route |
| Breach reporting | The internal reporting route, who assesses, who notifies the supervisory authority |
| Third parties | The requirement to have a DPA before sharing data with a processor |
| International transfers | Approval requirement and the mechanism to be used |
| Training | Frequency, who must complete it, how completion is recorded |
| Security | Access control, device rules, remote working, password requirements |
| Consequences | What happens if the policy is breached |
The section most often omitted is the requirement that staff obtain a DPA before engaging a new processor. Shadow IT procurement is a common route to unlawful processing, and a policy that does not address it leaves the gap open.
3. Cookie Policy
A cookie policy is governed by PECR in the UK and the ePrivacy Directive in the EU, not by GDPR directly. GDPR governs the processing of the personal data the cookies collect.
What Changed in February 2026
The DUAA amended PECR to create consent exemptions for certain cookie categories including some analytics and functionality cookies. EU law under the ePrivacy Directive continues to require consent for those categories.
This is the divergence most likely to produce a visible compliance failure. A UK-configured cookie banner served to EU users breaches the ePrivacy Directive.
| Cookie category | UK, post-DUAA | EU |
|---|---|---|
| Strictly necessary | No consent required | No consent required |
| Analytics | Exemption available, subject to conditions and a right to object | Consent required |
| Functionality | Exemption available, subject to conditions | Consent required |
| Advertising and tracking | Consent required | Consent required |
If you serve both markets, either geolocate and serve different configurations, or apply the EU standard to everyone. The second is simpler and defensible in both jurisdictions.
What the Policy Must Contain
| Element | Detail |
|---|---|
| What cookies are | A plain-language explanation |
| Cookies used | Table listing name, provider, purpose, type, and duration |
| Categories | Strictly necessary, functional, analytics, advertising |
| Legal basis for each category | Consent or exemption, stated per category |
| Third-party cookies | Who sets them and a link to their policy |
| How to manage preferences | Link to your consent management tool and browser instructions |
| How to withdraw consent | Must be as easy as giving it |
| Last updated | Date |
The cookie table has to reflect the cookies your site actually sets. This is where template use fails most visibly: a generic table listing cookies you do not use, and omitting ones you do, is both wrong and easy for anyone to verify.
4. Retention Policy
Article 5(1)(e) requires personal data to be kept no longer than necessary for the purposes for which it is processed. A retention policy is how you evidence that you have determined what “necessary” means.
Structure
A retention schedule is a table, not prose. For each data category: what it is, how long you keep it, why that period, and what happens at the end.
| Data category | Retention period | Basis | Action at expiry |
|---|---|---|---|
| Customer transaction records | 6 years from end of relationship | Limitation Act 1980, tax requirements | Delete |
| Unsuccessful job applications | 6 months from decision | Discrimination claim limitation period | Delete |
| Employee records | 6 years from end of employment | Statutory and contractual claim periods | Delete |
| Marketing contacts | 2 years from last engagement | Business purpose | Delete or re-consent |
| CCTV footage | 31 days | Security purpose | Automatic overwrite |
| Website analytics | 26 months | Business purpose | Delete |
The periods above are illustrative and common practice rather than legal requirements. Your periods must be defensible against your own purposes and your own regulatory obligations.
The column organisations most often leave blank is the basis. A retention period with no stated reason is a number, not a policy.
5. Breach Response Policy
Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in a risk to individuals. Article 34 requires notification to affected individuals where the risk is high.
Seventy-two hours is not long enough to design a process. The policy exists so that the process is already designed when the clock starts.
What It Must Establish
| Element | Detail |
|---|---|
| What counts as a breach | Confidentiality, integrity, and availability breaches, with examples |
| Internal reporting route | Who staff tell, within what timeframe, through what channel |
| Assessment | Who determines whether the risk threshold is met, against what criteria |
| Notification decision | Who authorises notification to the supervisory authority |
| The 72-hour clock | When it starts, who tracks it |
| Individual notification | The high-risk criteria and who decides |
| Breach register | Where breaches are recorded, including those not notified |
| Processor breaches | The route by which processors notify you, and the timeframe in the DPA |
| Post-incident review | Root cause analysis and remediation |
Article 33(5) requires you to document all breaches, including those you decide not to notify. The register is the evidence that the decision not to notify was made deliberately rather than by omission.
6. Data Processing Agreement
The DPA is the Article 28 contract between controller and processor. It is required whenever a third party processes personal data on your behalf and under your instructions.
Article 28(3) sets out ten mandatory elements:
- processing only on documented instructions,
- confidentiality commitments,
- Article 32 security measures,
- sub-processor authorisation and equivalent obligations,
- assistance with data subject rights,
- assistance with Articles 32 to 36 obligations,
- deletion or return at end of service,
- information provision and audit rights,
- notification where an instruction appears unlawful,
- the subject matter, duration, nature, purpose, data types, and categories of data subject.
A DPA that omits any of these is non-compliant regardless of length.
Two clauses deserve particular scrutiny in vendor templates. Sub-processor clauses that provide notification without a genuine objection window do not satisfy Article 28(2).
Audit rights replaced entirely by the vendor’s own certification do not satisfy Article 28(3)(h), which contains two separate obligations: make information available, and allow and contribute to audits.
Should You Use a GDPR Template Policy
Yes, as a starting structure. No, as a finished document.
A template gives you the sections a policy must contain and the order they should appear in. That is genuinely useful and saves real time. What a template cannot give you is the content of the sections that matter.
What a GDPR Policy Template Cannot Determine
Your lawful basis. A template will list the six bases under Article 6 and leave you to pick. The selection is a legal determination specific to each processing purpose, and it is the first thing a regulator examines. Where you select legitimate interests, you need a documented balancing test. A template cannot perform one.
Your retention periods. These follow from your purposes, your sector obligations, and your limitation periods. A template supplying a generic six-year figure has guessed.
Your recipients. Who you share data with is a fact about your organisation. Templates list plausible categories.
Your international transfers. Where your data goes and under what mechanism is specific to your processor arrangements.
Whether the policy matches what you do. This is the failure mode that produces enforcement outcomes. A privacy notice stating that you do not use automated decision-making, published by an organisation that does, is worse than no notice at all: it is a documented misrepresentation to data subjects.
Why Free Templates Fail Audits
| Failure | Why it happens |
|---|---|
| Wrong jurisdiction | UK templates not updated for the DUAA, or EU templates applied to UK operations |
| Out of date | Templates written before February 2026 do not reflect DUAA changes |
| Generic cookie tables | Listing cookies the site does not set and omitting ones it does |
| Unfilled placeholders | “[Company Name]” and “[X years]” surviving into published documents |
| No lawful basis mapping | Listing all six bases rather than stating which applies to which purpose |
| Contradicts actual practice | The policy describes an organisation that does not exist |
| No supporting records | A policy with no RoPA, no DPIA, and no evidence the policy is applied |
The last is the most consequential. A policy is one component of accountability under Article 5(2). Without records of processing under Article 30, a DPIA where required under Article 35, DPAs with your processors, and evidence of staff training, the policy is an assertion with nothing behind it.
What to Do After You Have the GDPR Policy Template
| Step | Action |
|---|---|
| 1 | Map your processing: what data, what purposes, who it comes from, who it goes to |
| 2 | Determine and document the lawful basis for each purpose |
| 3 | Complete a Legitimate Interests Assessment wherever you rely on that basis |
| 4 | Build your Article 30 records of processing |
| 5 | Set retention periods per data category, with a stated reason for each |
| 6 | Audit your actual cookies and build the table from what the site sets |
| 7 | Identify every processor and confirm a compliant DPA is in place |
| 8 | Map international transfers and confirm the mechanism for each |
| 9 | Complete a DPIA where processing is high-risk under Article 35 |
| 10 | Adapt the template to match what you do, not what the template assumed |
| 11 | Publish the privacy notice and cookie policy; circulate the internal policy |
| 12 | Train staff and record completion |
| 13 | Diarise annual review, and review on any change to processing |
Steps 1 to 3 are the work. Steps 10 to 13 are the document. Organisations that start at step 10 produce a policy describing an organisation that does not exist.
UK-Specific: What Changed in 2026
| Change | Effect on your policies |
|---|---|
| DUAA in force 5 February 2026 | Review all policies drafted before this date |
| Recognised legitimate interests | New lawful basis for a closed list of purposes. Privacy notices may need updating where relied on |
| Automated decision-making restructured | Privacy notice ADM section needs review. UK position now differs from EU Article 22 |
| PECR cookie exemptions | Cookie policy and banner configuration need review, and must not be applied to EU users |
| SAR reasonable and proportionate search | Internal policy and rights-handling procedure should reflect the new standard |
| ICO transitioning to Information Commission | Policies naming the ICO will need updating once the transition completes |
The ICO transition is a small point with wide reach. Every privacy notice referencing the right to complain names the supervisory authority. Those references will need changing.
FAQ
What is a GDPR policy template?
A pre-written document structure for one of the policies GDPR compliance requires, most commonly a privacy notice. It provides the sections and order but not the organisation-specific content: your lawful bases, retention periods, recipients, and transfer mechanisms.
Is a GDPR policy legally required?
A privacy notice is required under Articles 13 and 14. A cookie policy is required under PECR where cookies are used. An internal data protection policy is not expressly required, but Article 5(2) requires you to demonstrate compliance and Article 24 requires data protection policies where proportionate. In practice the internal policy is your primary evidence.
Should I use a free GDPR policy template?
As a starting structure, yes. As a finished document, no. The sections a template cannot complete, lawful basis, retention periods, recipients, and transfers, are the sections a regulator examines. A template also cannot tell you whether the policy matches what your organisation actually does, which is the most common cause of enforcement problems.
Why shouldn’t you use a GDPR compliance policy template unchanged?
Because the policy will describe an organisation other than yours. A published privacy notice is a statement to individuals about how you handle their data. Where it does not match reality, you have made a documented misrepresentation, which is a worse position than having no notice. Templates also date quickly: anything written before February 2026 does not reflect the DUAA changes to UK law.
What GDPR policies does a small business need?
At minimum, a privacy notice, a cookie policy where the website uses cookies, and an internal data protection policy. Add a retention policy and breach response policy as you grow. You need DPAs with every processor from day one, regardless of size. There is no small business exemption from Article 28.
Is the internal data protection policy the same as the privacy notice?
No. The privacy notice is external, addressed to individuals, and tells them how you process their data. The internal policy is addressed to your staff and tells them how they must handle data. Different audiences, different content, different purposes. Publishing an internal policy as a privacy notice is a common error.
Does a GDPR policy template cover UK GDPR and EU GDPR?
Not necessarily. Since the DUAA came into force on 5 February 2026, the two regimes diverge on automated decision-making, recognised legitimate interests, subject access requests, cookies, and international transfers. A template drafted for one may not be accurate for the other. Where you process data of both UK and EU residents, the EU standard is stricter in the areas that diverge and is the safer baseline.
How often should GDPR policies be reviewed?
Annually as a minimum, and whenever your processing changes: new systems, new processors, new data categories, new purposes, or changes in international transfers. Legislative change also triggers review, as the DUAA did in February 2026.
Do we need a DPO to have a GDPR policy?
No. A DPO is required under Article 37 only for public authorities, organisations carrying out large-scale systematic monitoring, and organisations processing special categories at scale. Policies are required regardless of whether a DPO is appointed. Where you do not have one, name an internal contact point for data protection queries.
What is the difference between a privacy policy and a privacy notice?
The terms are used interchangeably in practice. GDPR uses “information to be provided” rather than either term. “Privacy notice” is the more accurate label because the document notifies individuals rather than governing internal behaviour. “Privacy policy” is more common on websites and search engines treat them as equivalent.
Do we need a cookie policy if we only use essential cookies?
Can we use the same cookie banner for UK and EU visitors?
Only if configured to the EU standard. The DUAA created UK exemptions for certain analytics and functionality cookies that EU law does not permit. A UK-configured banner served to EU visitors breaches the ePrivacy Directive. Either geolocate, or apply the EU standard to all visitors.
Disclaimer
This guide reflects the EU GDPR, the UK GDPR as amended by the Data (Use and Access) Act 2025, and PECR as amended, as at September 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Organisations should obtain advice specific to their processing activities before publishing data protection documentation.
