“GDPR policy” is not a single document. Organisations searching for a GDPR policy template are usually looking for one of six distinct instruments, and downloading the wrong one produces a document that satisfies nothing.

The six are a privacy notice for individuals, an internal data protection policy for staff, a cookie policy, a data retention policy, a data breach response policy, and a Data Processing Agreement for processors. Each has a different audience, a different legal basis, and different mandatory content.

Free GDPR templates have a specific failure mode. They are structurally sound and substantively empty. A template tells you that you must state your lawful basis. It cannot tell you what your lawful basis is, and that determination is the part a regulator examines.

Two developments in 2026 make templates downloaded before this year unsafe for UK organisations. The Data (Use and Access) Act 2025 came into force on 5 February 2026, changing automated decision-making provisions, introducing recognised legitimate interests, and amending PECR cookie rules.

And the ICO is transitioning to the Information Commission, which means templates referencing the ICO by name will need updating.

This guide sets out what each policy must contain, provides adaptable structures, and explains what a template cannot do for you.

Key Definitions to Know Before Using GDPR Policy Template

TermDefinition
Privacy noticeThe external-facing document informing individuals how their personal data is processed. Required by GDPR Articles 13 and 14
Data protection policyThe internal document setting out how staff must handle personal data. Not expressly required but evidences Article 5(2) accountability
Cookie policyThe document explaining what cookies a website uses. Governed by PECR in the UK and the ePrivacy Directive in the EU
Retention policyThe document setting out how long data categories are kept and why. Evidences Article 5(1)(e) storage limitation
Breach response policyThe internal procedure for handling personal data breaches under Articles 33 and 34
DPAData Processing Agreement. The Article 28 contract between controller and processor
RoPARecords of Processing Activities. Required under Article 30
DPIAData Protection Impact Assessment. Required under Article 35 for high-risk processing
DUAAData (Use and Access) Act 2025. In force 5 February 2026

Which GDPR Policy Template Do You Actually Need

DocumentAudienceLegally requiredPublished
Privacy noticeIndividuals whose data you processYes, Articles 13 and 14Yes, publicly
Internal data protection policyYour staffNot expressly, but evidences accountabilityNo, internal
Cookie policyWebsite visitorsYes where cookies are used, under PECRYes, publicly
Retention policyInternal, with elements publishedNot expressly, but evidences storage limitationPartly
Breach response policyInternalNot expressly, but required to meet 72-hour deadlineNo, internal
Data Processing AgreementYour processorsYes, Article 28No, contractual

Most small businesses need the first three at minimum. Organisations processing special category data, running high-risk processing, or acting as processors for others need all six.

1. Privacy Notice

This is the document most people mean when they search for a GDPR policy template. It is the only one of the six that GDPR expressly requires to be provided to individuals.

Articles 13 and 14 set out mandatory content. Article 13 applies where you collect data directly from the individual. Article 14 applies where you obtain it from another source and adds a requirement to state where the data came from.

Mandatory Content

ElementArticle
Identity and contact details of the controller13(1)(a)
Contact details of the DPO, where appointed13(1)(b)
Purposes of processing13(1)(c)
Lawful basis for each purpose13(1)(c)
Legitimate interests pursued, where that is the basis13(1)(d)
Recipients or categories of recipients13(1)(e)
International transfers and the safeguards applied13(1)(f)
Retention period or criteria for determining it13(2)(a)
Data subject rights: access, rectification, erasure, restriction, portability, objection13(2)(b)
Right to withdraw consent, where consent is the basis13(2)(c)
Right to complain to the supervisory authority13(2)(d)
Whether provision is a statutory or contractual requirement, and consequences of not providing13(2)(e)
Existence of automated decision-making, including profiling, with meaningful information about the logic13(2)(f)
Source of the data, where not collected from the individual14(2)(f)

Structure

Who we are. Legal entity name, registered address, registration number, contact point for data protection queries, and DPO details where one is appointed.

What data we collect. Categories, not an exhaustive field list. Contact details, transaction records, website usage data, and so on. State separately if you process any special category data under Article 9.

Why we process it, and on what basis. This is the section templates cannot complete for you. Each purpose needs a stated lawful basis. Where you rely on legitimate interests, state the interest.

Who we share it with. Categories of recipient: payment processors, cloud hosting providers, professional advisers, regulators. Name specific processors where the individual would reasonably expect it.

International transfers. Where data leaves the UK or EEA, state the destination and the safeguard: adequacy decision, IDTA, UK Addendum, SCCs, or another Article 46 mechanism.

How long we keep it. Either the period or the criteria used to determine it. Vague statements that data is kept “as long as necessary” without criteria do not satisfy Article 13(2)(a).

Your rights. List them and explain how to exercise them. Include the right to complain and name the supervisory authority.

Automated decision-making. Where you use it, explain the logic in meaningful terms and the significance and consequences for the individual. This section has become materially more important following the Dutch DPA’s €825 million fine against Uber in August 2026 for automated driver deactivations.

Changes. How you notify individuals of changes and when the notice was last updated.

2. Internal Data Protection Policy

GDPR does not expressly require an internal data protection policy. Article 5(2) requires you to demonstrate compliance with the data protection principles, and Article 24 requires appropriate technical and organisational measures including data protection policies where proportionate.

In practice, an internal policy is the primary evidence that you have those measures.

What This GDPR Policy Template Should Cover

SectionContent
ScopeWho the policy applies to: employees, contractors, volunteers, temporary staff
The principlesThe six Article 5 principles and what each means operationally in your organisation
Roles and responsibilitiesWho owns data protection, who the DPO is where appointed, what line managers must do
Lawful basisHow staff determine and record the lawful basis before starting new processing
Data minimisation in practiceRules on what staff may collect and what they may not
Data subject rights handlingWho receives requests, the response deadline, the escalation route
Breach reportingThe internal reporting route, who assesses, who notifies the supervisory authority
Third partiesThe requirement to have a DPA before sharing data with a processor
International transfersApproval requirement and the mechanism to be used
TrainingFrequency, who must complete it, how completion is recorded
SecurityAccess control, device rules, remote working, password requirements
ConsequencesWhat happens if the policy is breached

The section most often omitted is the requirement that staff obtain a DPA before engaging a new processor. Shadow IT procurement is a common route to unlawful processing, and a policy that does not address it leaves the gap open.

3. Cookie Policy

A cookie policy is governed by PECR in the UK and the ePrivacy Directive in the EU, not by GDPR directly. GDPR governs the processing of the personal data the cookies collect.

What Changed in February 2026

The DUAA amended PECR to create consent exemptions for certain cookie categories including some analytics and functionality cookies. EU law under the ePrivacy Directive continues to require consent for those categories.

This is the divergence most likely to produce a visible compliance failure. A UK-configured cookie banner served to EU users breaches the ePrivacy Directive.

Cookie categoryUK, post-DUAAEU
Strictly necessaryNo consent requiredNo consent required
AnalyticsExemption available, subject to conditions and a right to objectConsent required
FunctionalityExemption available, subject to conditionsConsent required
Advertising and trackingConsent requiredConsent required

If you serve both markets, either geolocate and serve different configurations, or apply the EU standard to everyone. The second is simpler and defensible in both jurisdictions.

What the Policy Must Contain

ElementDetail
What cookies areA plain-language explanation
Cookies usedTable listing name, provider, purpose, type, and duration
CategoriesStrictly necessary, functional, analytics, advertising
Legal basis for each categoryConsent or exemption, stated per category
Third-party cookiesWho sets them and a link to their policy
How to manage preferencesLink to your consent management tool and browser instructions
How to withdraw consentMust be as easy as giving it
Last updatedDate

The cookie table has to reflect the cookies your site actually sets. This is where template use fails most visibly: a generic table listing cookies you do not use, and omitting ones you do, is both wrong and easy for anyone to verify.

4. Retention Policy

Article 5(1)(e) requires personal data to be kept no longer than necessary for the purposes for which it is processed. A retention policy is how you evidence that you have determined what “necessary” means.

Structure

A retention schedule is a table, not prose. For each data category: what it is, how long you keep it, why that period, and what happens at the end.

Data categoryRetention periodBasisAction at expiry
Customer transaction records6 years from end of relationshipLimitation Act 1980, tax requirementsDelete
Unsuccessful job applications6 months from decisionDiscrimination claim limitation periodDelete
Employee records6 years from end of employmentStatutory and contractual claim periodsDelete
Marketing contacts2 years from last engagementBusiness purposeDelete or re-consent
CCTV footage31 daysSecurity purposeAutomatic overwrite
Website analytics26 monthsBusiness purposeDelete

The periods above are illustrative and common practice rather than legal requirements. Your periods must be defensible against your own purposes and your own regulatory obligations.

The column organisations most often leave blank is the basis. A retention period with no stated reason is a number, not a policy.

5. Breach Response Policy

Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach likely to result in a risk to individuals. Article 34 requires notification to affected individuals where the risk is high.

Seventy-two hours is not long enough to design a process. The policy exists so that the process is already designed when the clock starts.

What It Must Establish

ElementDetail
What counts as a breachConfidentiality, integrity, and availability breaches, with examples
Internal reporting routeWho staff tell, within what timeframe, through what channel
AssessmentWho determines whether the risk threshold is met, against what criteria
Notification decisionWho authorises notification to the supervisory authority
The 72-hour clockWhen it starts, who tracks it
Individual notificationThe high-risk criteria and who decides
Breach registerWhere breaches are recorded, including those not notified
Processor breachesThe route by which processors notify you, and the timeframe in the DPA
Post-incident reviewRoot cause analysis and remediation

Article 33(5) requires you to document all breaches, including those you decide not to notify. The register is the evidence that the decision not to notify was made deliberately rather than by omission.

6. Data Processing Agreement

The DPA is the Article 28 contract between controller and processor. It is required whenever a third party processes personal data on your behalf and under your instructions.

Article 28(3) sets out ten mandatory elements:

  • processing only on documented instructions,
  • confidentiality commitments,
  • Article 32 security measures,
  • sub-processor authorisation and equivalent obligations,
  • assistance with data subject rights,
  • assistance with Articles 32 to 36 obligations,
  • deletion or return at end of service,
  • information provision and audit rights,
  • notification where an instruction appears unlawful,
  • the subject matter, duration, nature, purpose, data types, and categories of data subject.

A DPA that omits any of these is non-compliant regardless of length.

Two clauses deserve particular scrutiny in vendor templates. Sub-processor clauses that provide notification without a genuine objection window do not satisfy Article 28(2).

Audit rights replaced entirely by the vendor’s own certification do not satisfy Article 28(3)(h), which contains two separate obligations: make information available, and allow and contribute to audits.

Should You Use a GDPR Template Policy

Yes, as a starting structure. No, as a finished document.

A template gives you the sections a policy must contain and the order they should appear in. That is genuinely useful and saves real time. What a template cannot give you is the content of the sections that matter.

What a GDPR Policy Template Cannot Determine

Your lawful basis. A template will list the six bases under Article 6 and leave you to pick. The selection is a legal determination specific to each processing purpose, and it is the first thing a regulator examines. Where you select legitimate interests, you need a documented balancing test. A template cannot perform one.

Your retention periods. These follow from your purposes, your sector obligations, and your limitation periods. A template supplying a generic six-year figure has guessed.

Your recipients. Who you share data with is a fact about your organisation. Templates list plausible categories.

Your international transfers. Where your data goes and under what mechanism is specific to your processor arrangements.

Whether the policy matches what you do. This is the failure mode that produces enforcement outcomes. A privacy notice stating that you do not use automated decision-making, published by an organisation that does, is worse than no notice at all: it is a documented misrepresentation to data subjects.

Why Free Templates Fail Audits

FailureWhy it happens
Wrong jurisdictionUK templates not updated for the DUAA, or EU templates applied to UK operations
Out of dateTemplates written before February 2026 do not reflect DUAA changes
Generic cookie tablesListing cookies the site does not set and omitting ones it does
Unfilled placeholders“[Company Name]” and “[X years]” surviving into published documents
No lawful basis mappingListing all six bases rather than stating which applies to which purpose
Contradicts actual practiceThe policy describes an organisation that does not exist
No supporting recordsA policy with no RoPA, no DPIA, and no evidence the policy is applied

The last is the most consequential. A policy is one component of accountability under Article 5(2). Without records of processing under Article 30, a DPIA where required under Article 35, DPAs with your processors, and evidence of staff training, the policy is an assertion with nothing behind it.

What to Do After You Have the GDPR Policy Template

StepAction
1Map your processing: what data, what purposes, who it comes from, who it goes to
2Determine and document the lawful basis for each purpose
3Complete a Legitimate Interests Assessment wherever you rely on that basis
4Build your Article 30 records of processing
5Set retention periods per data category, with a stated reason for each
6Audit your actual cookies and build the table from what the site sets
7Identify every processor and confirm a compliant DPA is in place
8Map international transfers and confirm the mechanism for each
9Complete a DPIA where processing is high-risk under Article 35
10Adapt the template to match what you do, not what the template assumed
11Publish the privacy notice and cookie policy; circulate the internal policy
12Train staff and record completion
13Diarise annual review, and review on any change to processing

Steps 1 to 3 are the work. Steps 10 to 13 are the document. Organisations that start at step 10 produce a policy describing an organisation that does not exist.

UK-Specific: What Changed in 2026

ChangeEffect on your policies
DUAA in force 5 February 2026Review all policies drafted before this date
Recognised legitimate interestsNew lawful basis for a closed list of purposes. Privacy notices may need updating where relied on
Automated decision-making restructuredPrivacy notice ADM section needs review. UK position now differs from EU Article 22
PECR cookie exemptionsCookie policy and banner configuration need review, and must not be applied to EU users
SAR reasonable and proportionate searchInternal policy and rights-handling procedure should reflect the new standard
ICO transitioning to Information CommissionPolicies naming the ICO will need updating once the transition completes

The ICO transition is a small point with wide reach. Every privacy notice referencing the right to complain names the supervisory authority. Those references will need changing.

FAQ

What is a GDPR policy template?

A pre-written document structure for one of the policies GDPR compliance requires, most commonly a privacy notice. It provides the sections and order but not the organisation-specific content: your lawful bases, retention periods, recipients, and transfer mechanisms.

Is a GDPR policy legally required?

A privacy notice is required under Articles 13 and 14. A cookie policy is required under PECR where cookies are used. An internal data protection policy is not expressly required, but Article 5(2) requires you to demonstrate compliance and Article 24 requires data protection policies where proportionate. In practice the internal policy is your primary evidence.

Should I use a free GDPR policy template?

As a starting structure, yes. As a finished document, no. The sections a template cannot complete, lawful basis, retention periods, recipients, and transfers, are the sections a regulator examines. A template also cannot tell you whether the policy matches what your organisation actually does, which is the most common cause of enforcement problems.

Why shouldn’t you use a GDPR compliance policy template unchanged?

Because the policy will describe an organisation other than yours. A published privacy notice is a statement to individuals about how you handle their data. Where it does not match reality, you have made a documented misrepresentation, which is a worse position than having no notice. Templates also date quickly: anything written before February 2026 does not reflect the DUAA changes to UK law.

What GDPR policies does a small business need?

At minimum, a privacy notice, a cookie policy where the website uses cookies, and an internal data protection policy. Add a retention policy and breach response policy as you grow. You need DPAs with every processor from day one, regardless of size. There is no small business exemption from Article 28.

Is the internal data protection policy the same as the privacy notice?

No. The privacy notice is external, addressed to individuals, and tells them how you process their data. The internal policy is addressed to your staff and tells them how they must handle data. Different audiences, different content, different purposes. Publishing an internal policy as a privacy notice is a common error.

Does a GDPR policy template cover UK GDPR and EU GDPR?

Not necessarily. Since the DUAA came into force on 5 February 2026, the two regimes diverge on automated decision-making, recognised legitimate interests, subject access requests, cookies, and international transfers. A template drafted for one may not be accurate for the other. Where you process data of both UK and EU residents, the EU standard is stricter in the areas that diverge and is the safer baseline.

How often should GDPR policies be reviewed?

Annually as a minimum, and whenever your processing changes: new systems, new processors, new data categories, new purposes, or changes in international transfers. Legislative change also triggers review, as the DUAA did in February 2026.

Do we need a DPO to have a GDPR policy?

No. A DPO is required under Article 37 only for public authorities, organisations carrying out large-scale systematic monitoring, and organisations processing special categories at scale. Policies are required regardless of whether a DPO is appointed. Where you do not have one, name an internal contact point for data protection queries.

What is the difference between a privacy policy and a privacy notice?

The terms are used interchangeably in practice. GDPR uses “information to be provided” rather than either term. “Privacy notice” is the more accurate label because the document notifies individuals rather than governing internal behaviour. “Privacy policy” is more common on websites and search engines treat them as equivalent.

Do we need a cookie policy if we only use essential cookies?

You still need to inform users, but no consent is required for strictly necessary cookies. A short notice explaining what essential cookies you set and why satisfies the requirement. Where you use any non-essential cookie, the consent position applies and the policy needs to be fuller.

Can we use the same cookie banner for UK and EU visitors?

Only if configured to the EU standard. The DUAA created UK exemptions for certain analytics and functionality cookies that EU law does not permit. A UK-configured banner served to EU visitors breaches the ePrivacy Directive. Either geolocate, or apply the EU standard to all visitors.

Disclaimer

This guide reflects the EU GDPR, the UK GDPR as amended by the Data (Use and Access) Act 2025, and PECR as amended, as at September 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Organisations should obtain advice specific to their processing activities before publishing data protection documentation.

Fact Checked & Editorial Guidelines
Reviewed by: Subject Matter Experts