A twelve-person joinery workshop in Lyon gets an email from a customer: "What do you do with my address and phone number?" The owner opens the "Politique de confidentialité" page on her website. It was copied three years ago from a competitor's site. The other company's name still appears in the third paragraph. The page describes a newsletter the workshop has never sent, says nothing about how long quotes are kept, and names no legal basis. It cannot answer the customer's question. This article explains what Articles 13 and 14 GDPR require, item by item, and how to write the page in half a day from a document you may already have: the record of processing activities.
Disclaimer: this article is provided for information only and does not constitute legal advice. The texts cited are those in force at the time of writing; for a specific situation, consult a qualified legal professional.
Before rewriting anything, look for these five items in your current page. They are the ones most often absent.
If these five are present, your page already has a backbone. If not, the sections below give you the full list and a method to fill it.
The GDPR separates two cases according to where the data comes from.
| Situation | Article | When to inform |
|---|---|---|
| The data is collected from the person directly: contact form, quote request, order, newsletter sign-up. | Article 13 | "At the time when personal data are obtained", in other words at the form itself. |
| The data was not obtained from the person: a purchased or rented list, a business directory, a social network, data passed on by a partner. | Article 14 | Within a reasonable period and at the latest within one month; at the latest at the first communication if the data is used to contact the person; at the latest at the first disclosure if it is passed to another recipient (Article 14(3)). |
The list of items is almost identical in both articles. Article 14 adds two: the categories of personal data concerned (paragraph 1(d)) and the source of the data, including whether it came from publicly accessible sources (paragraph 2(f)). A small business that only uses its own forms falls under Article 13. As soon as it prospects from a bought list or a directory, Article 14 applies as well, and the one-month clock starts when the list is obtained.
What you can do now: for each category of people (customers, prospects, applicants, site visitors), write down where their data comes from. That sorting decides which article applies.
Article 12(1) GDPR sets the form. The information is provided "in a concise, transparent, intelligible and easily accessible form, using clear and plain language". It is given in writing, including by electronic means. Paragraph 5 of the same article adds that it is provided free of charge.
For a web page, that means:
The CNIL accepts layered information: the essentials under the form (who collects, why, a link to the full page), the detail on the privacy policy page itself. What you can do now: read your page aloud; every sentence a customer would not understand is one to rewrite.
These are the items Articles 13 and 14 GDPR require, and where to find the information in your business. The "Record" column points to the matching field of the record of processing activities under Article 30.
| Item | Art. 13 | Art. 14 | Record (Art. 30) |
|---|---|---|---|
| Identity and contact details of the controller (and of its representative, where applicable) | (1)(a) | (1)(a) | (1)(a): name and contact details |
| Contact details of the data protection officer, if you have one | (1)(b) | (1)(b) | (1)(a) |
| Purposes of the processing and the legal basis for each purpose | (1)(c) | (1)(c) | (1)(b): purposes (the legal basis is not a record field; add a column) |
| Legitimate interests pursued, where that is the basis relied on | (1)(d) | (2)(b) | Same added column |
| Categories of personal data concerned | Not required | (1)(d) | (1)(c) |
| Recipients or categories of recipients | (1)(e) | (1)(e) | (1)(d) |
| Transfer outside the EU, existence or absence of an adequacy decision, appropriate safeguards and how to obtain a copy | (1)(f) | (1)(f) | (1)(e) |
| Retention period or the criteria used to determine it | (2)(a) | (2)(a) | (1)(f): time limits for erasure |
| Rights of access, rectification, erasure, restriction, objection and data portability | (2)(b) | (2)(c) | Common text for all operations |
| Right to withdraw consent at any time (consent-based operations) | (2)(c) | (2)(d) | Legal-basis column = consent |
| Right to lodge a complaint with a supervisory authority | (2)(d) | (2)(e) | Common text |
| Whether providing the data is a statutory or contractual requirement, and the consequences of not providing it | (2)(e) | Not required | Derived from the purpose (a quote cannot be prepared without an address) |
| Source of the data, and whether it came from publicly accessible sources | Not required | (2)(f) | Add to the record if absent |
| Existence of automated decision-making, including profiling, and the logic involved | (2)(f) | (2)(g) | Rare for a small business; saying there is none is good practice |
The possible legal bases are listed in Article 6(1): consent, contract or pre-contractual steps, a legal requirement, vital interests, a public-interest task, legitimate interests. For a small business, three come up almost every time: contract (quotes, orders, invoices), legal requirement (keeping accounting records) and consent (newsletter, non-essential trackers). What you can do now: add a "legal basis" column to your record and fill it line by line.
The record of processing activities under Article 30 GDPR already holds, for each operation, the purposes, the categories of people and data, the recipients, transfers outside the EU and the time limits for erasure. Two columns aside, those are the Article 13 and 14 items. If you do not have a record yet, or believe you are exempt, read our article on the record and the under-250-employees exemption first: a six-line record is enough for a small company and takes a morning to build.
The method has four steps:
The advantage of this method is consistency: the policy cannot announce a processing operation that is missing from the record, or the reverse. When a new tool arrives (quoting software, a chat widget on the site), one line goes into the record and one block onto the page, the same day.
This is the skeleton we recommend for each processing operation, to be completed with your own data. The page opens with a common block (controller, DPO if any, rights, complaint), then repeats this block once per line of the record. For a French audience, the page itself should be in French; the field labels below are given in English for readability.
Controller
[Company name] – [address] – [contact email]
Data protection officer (if any): [contact details]
Processing: [Quotes and orders]
Purpose : prepare a quote, fulfil the order, invoice
Legal basis : contract or pre-contractual steps
; legal requirement for keeping
accounting records
Data : identity, contact details, content of the
request, billing data
Provision : needed to prepare the quote; without it the
request cannot be handled
Recipients : [hosting provider], [quoting software],
[accountant], [payment provider]
Transfer outside the EU : [none] / [country, safeguard,
where to obtain a copy]
Retention : [length of the business relationship + N years];
accounting records: [statutory period]
Source (Art. 14 only) : [list, directory, partner]
Your rights
Access, rectification, erasure, restriction, objection,
portability; withdrawal of consent at any time for
consent-based operations.
To exercise them: [email / postal address]
Complaint: you may contact the CNIL (www.cnil.fr)
Last updated: [date]
The free Sitetals check reviews your home page and reports, among other things, whether a legal notice page or a privacy policy page is missing or unreachable, and which third-party services your site loads. It is a starting point for the review described above, not a replacement for it.
Also worth reading:
Sources: Regulation (EU) 2016/679, Articles 6, 7, 12, 13, 14 and 30 · CNIL, "Conformité RGPD : comment informer les personnes et assurer la transparence ?" · Law no. 78-17 of 6 January 1978, article 82 · Sitetals methodology.
Sitetals editorial team