Almost every website collects personal data, even when that isn’t obvious. A contact form, a newsletter sign-up or the server’s plain log files are enough to give rise to a precise obligation: informing users about how their data is processed. This is what the privacy policy is for. It is worth clarifying what it is, why it is in practice mandatory, what it must contain under the GDPR, where to place it and which mistakes to avoid.
What the privacy policy is (and why it’s almost always required)
“Privacy policy” is the common name for the notice on the processing of personal data. Its legal basis lies in Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR): Article 13 applies when data are collected directly from the data subject, Article 14 when they come from other sources. The underlying principle is transparency: anyone who processes data must make known, in clear form, their identity, the purposes pursued and the rights belonging to the data subject.
From this stems the most common misunderstanding, according to which the notice would be required only of those who sell online or handle large amounts of data. That is not the case. Even apparently “static” sites are subject to it: a “Contact us” form collects a name and an email address; a newsletter sign-up form acquires a contact detail and a consent; even the server’s technical logs record IP addresses, which are personal data. In all these cases the notice is due. In practice, only purely showcase sites that collect no data — and use no tools that do so on their behalf — can do without it.
Article 12 of the Regulation also lays down a formal requirement: the notice must be concise, transparent, intelligible and easily accessible, written in clear and plain language. A text that is correct in content but incomprehensible does not satisfy the obligation.
Privacy policy and cookie policy are not the same
This is a point that is often confused. The privacy policy concerns all the processing of personal data carried out through the site (forms, sign-ups, logs and so on). The cookie policy, by contrast, deals specifically with the use of cookies and tracking tools, and links to the management of consent via the relevant banner. They are separate documents, with partly different legal bases, to be kept apart: folding cookies into the privacy policy, or vice versa, is a frequent mistake. On how the banner works and when consent is required, see the dedicated article on the cookie banner.
What the privacy policy must contain
Article 13 sets out precisely the information the notice must give the data subject. In summary:
- The identity and contact details of the data controller and, where appointed, of the data protection officer (DPO): you must state who processes the data and how to contact them.
- The purposes of the processing and the relevant legal bases. For each purpose (replying to a request, sending the newsletter, managing an order) the legal basis under Article 6 must be indicated: consent, performance of a contract, a legal obligation or the controller’s legitimate interest.
- The recipients or categories of recipients of the data: those to whom the data may be disclosed, including external suppliers appointed as data processors (for example the hosting service, the email-marketing platform, the form provider).
- Any transfers to third countries or international organisations, indicating the safeguards provided under Chapter V of the Regulation — a point that is often relevant when relying on non-EU services.
- The data retention period, or the criteria used to determine it where no fixed term is possible.
- The data subject’s rights. The rights under Articles 15 to 22 must be recalled: access, rectification, erasure, restriction, portability and objection. Where the processing is based on consent, the right to withdraw it at any time (Article 7(3)) must also be mentioned, without affecting the lawfulness of processing prior to the withdrawal.
- The right to lodge a complaint with the competent supervisory authority — in Italy, the Garante — in the Member State of your habitual residence, place of work or of the alleged infringement (Article 77).
- Whether providing the data is mandatory or optional and the consequences of not providing it: in a contact form, for instance, it is advisable to specify which fields are necessary for a reply and which are not.
Where the conditions apply, further information must be added, such as the existence of automated decision-making. The practical rule is clear-cut: the notice must allow the user to understand the fate of their data before the processing begins.
When Article 14 also applies
Article 13 governs the ordinary case: data come directly from the person who fills in a form or signs up. Article 14 comes into play when data are not collected from the data subject, but obtained elsewhere: a purchased list, a business partner, a public source. In such cases the notice must also indicate the source and the categories of data processed, and be provided within the time limits set by law. For many sites Article 14 is not relevant, but it is central for anyone managing databases or receiving contacts from third parties.
Where to place it
It is not enough to have a good privacy policy: it must be easy to find. Correct practice calls for two measures. First, a link accessible from every page, usually in the footer, so the user can consult it at any time. Second, a reference to the notice at the very point where the data are collected, that is next to each form, before submission: anyone filling in a contact form must be able to read the notice before sending it, not find it afterwards.
The most common mistakes
A few mistakes recur regularly in practice:
- Adopting a generic template. A notice downloaded and transposed, not tailored to the processing actually carried out, is almost always incomplete or inaccurate.
- Failing to update it. The privacy policy must be revised as the processing changes: a new tool, a new purpose, a new supplier. A notice frozen in time does not reflect reality.
- Failing to indicate suppliers and data processors. Hosting, the newsletter platform, the form provider and other external services must be listed among the recipients. It is among the failings the Authority has actually censured (see below). Correctly identifying these parties is, moreover, made easier by keeping an up-to-date record of processing activities.
- Confusing it with the cookie policy. As noted, they are separate documents.
- Neglecting the legal bases. Stating the purposes without the correct legal basis makes the notice formally deficient.
What the case law says
The Authority’s measures show that the completeness and transparency of the notice are not formal details.
By measure of 11 January 2023 (web doc. no. 9861941), against a company running a classified-ads site, the Authority found that the notice omitted two partners to whom data were disclosed for promotional purposes, in breach of Article 13(1)(e) of the Regulation: the omission — the Authority observed — prevents the data subject from knowing the actual recipients and, with that, from knowingly exercising their rights. The Authority issued a reprimand (Article 58(2)(b)) and an order to rectify the notice, without a financial penalty. The lesson is unambiguous: the list of recipients must be kept complete and up to date.
In another case — the measure of 22 June 2023 (web doc. no. 9909702), concerning a cashback service — the Authority found the notice inadequately drafted: it did not state the correct identity of the actual controller (wrongly described as a processor) nor the purposes pursued, in breach of the principles of fairness and transparency (Article 5(1)(a)), of Article 13 and of the obligations concerning processors (Article 28). In that case the Authority imposed a penalty of one million euros. The point is substantive: the user must be able to know exactly who processes their data and for what purposes.
These precedents confirm a practical rule: the notice must faithfully reflect the actual processing, precisely identify the controller and the recipients, and be written in comprehensible form. Drawing it up in this way — or checking that an existing one complies — is a key part of bringing a site into GDPR compliance.
Frequently asked questions
Does the user have to sign the privacy policy? No: it is a notice — it must be provided, that is, made available — not signed. It responds to a transparency obligation, not a contractual one.
Can I copy another website’s privacy policy? No: the notice must be tailored to the processing actually carried out — purposes, legal bases, data collected, third-party tools. A copied template is almost always inaccurate and, for that reason, non-compliant.
Where should it go on the site? In a place reachable from every page, usually a link in the footer, and it should be referenced where data is collected: contact form, newsletter sign-up, checkout.
This article is for information purposes and does not replace an assessment of the specific case.
This article is for general information only and is not legal advice on any specific case. Content reviewed by Giuseppe Foti, legal consultant — last checked on July 15, 2026.