A privacy notice somebody can actually read
The Regulation demands a "concise, transparent, intelligible and easily accessible form, using clear and plain language". The usual generated text meets none of those four – and is therefore a breach in its own right.
The duty to inform is not a boilerplate block but a piece of information. It should let a person understand what happens to their data – and then decide whether they are comfortable with it. A text nobody reads to the end has missed that purpose, however complete it may be.
The mandatory content
- Who the controller is – with contact details, and those of the data protection officer where one exists.
- Which purposes are pursued – individually, not as a list of possibilities.
- On which legal basis – named per purpose. For legitimate interests, additionally which interest.
- Who receives the data – recipients or at least categories, and the actual names on request.
- For how long data is kept – or the criteria determining the period.
- Which rights exist – including withdrawal, objection and complaint to the supervisory authority.
- Whether transfers to third countries take place and on what basis.
- Whether providing data is required and what follows from not doing so.
The structure makes the difference
Two structures for the same content
The most common defects
- Services that are not used. A generated text names providers that do not exist on this site – and may omit the ones that do.
- Legal bases in the conditional. "Processing may rest on Article 6(1)(a), (b) or (f)" is not information but a list.
- Missing retention periods. "As long as necessary" merely repeats the statute instead of filling it in.
- An outdated state. The text is written once and never touched again – while the embedded services keep changing.
Against the last point a simple rule helps: the text gets touched whenever a service is added or removed – in the same work step, not a later one. Anyone adopting that needs no annual review, because the notice never falls out of date.