How it works What We Check Pricing Articles About Free Scan →
← All Articles GDPR · Privacy policy 9 min read Updated 6 September 2026

Privacy policy: what Articles 13 and 14 GDPR require, starting from your record of processing

A twelve-person joinery workshop in Lyon gets an email from a customer: "What do you do with my address and phone number?" The owner opens the "Politique de confidentialité" page on her website. It was copied three years ago from a competitor's site. The other company's name still appears in the third paragraph. The page describes a newsletter the workshop has never sent, says nothing about how long quotes are kept, and names no legal basis. It cannot answer the customer's question. This article explains what Articles 13 and 14 GDPR require, item by item, and how to write the page in half a day from a document you may already have: the record of processing activities.

Disclaimer: this article is provided for information only and does not constitute legal advice. The texts cited are those in force at the time of writing; for a specific situation, consult a qualified legal professional.


Start here: the five items most often missing

Before rewriting anything, look for these five items in your current page. They are the ones most often absent.

  1. A legal basis for each purpose. Article 13(1)(c) asks for "the purposes of the processing […] as well as the legal basis for the processing". A list of purposes on its own is not enough.
  2. A retention period, or the criteria used to set it (Article 13(2)(a)).
  3. The right to lodge a complaint with a supervisory authority, which for a French site is the CNIL (Article 13(2)(d)).
  4. The right to withdraw consent at any time, for every processing operation based on consent (Article 13(2)(c)).
  5. Recipients or categories of recipients: hosting provider, email tool, payment provider, accountant (Article 13(1)(e)).

If these five are present, your page already has a backbone. If not, the sections below give you the full list and a method to fill it.


Two articles, two situations: 13 and 14

The GDPR separates two cases according to where the data comes from.

Situation Article When to inform
The data is collected from the person directly: contact form, quote request, order, newsletter sign-up. Article 13 "At the time when personal data are obtained", in other words at the form itself.
The data was not obtained from the person: a purchased or rented list, a business directory, a social network, data passed on by a partner. Article 14 Within a reasonable period and at the latest within one month; at the latest at the first communication if the data is used to contact the person; at the latest at the first disclosure if it is passed to another recipient (Article 14(3)).

The list of items is almost identical in both articles. Article 14 adds two: the categories of personal data concerned (paragraph 1(d)) and the source of the data, including whether it came from publicly accessible sources (paragraph 2(f)). A small business that only uses its own forms falls under Article 13. As soon as it prospects from a bought list or a directory, Article 14 applies as well, and the one-month clock starts when the list is obtained.

What you can do now: for each category of people (customers, prospects, applicants, site visitors), write down where their data comes from. That sorting decides which article applies.


The form: what Article 12 requires

Article 12(1) GDPR sets the form. The information is provided "in a concise, transparent, intelligible and easily accessible form, using clear and plain language". It is given in writing, including by electronic means. Paragraph 5 of the same article adds that it is provided free of charge.

For a web page, that means:

The CNIL accepts layered information: the essentials under the form (who collects, why, a link to the full page), the detail on the privacy policy page itself. What you can do now: read your page aloud; every sentence a customer would not understand is one to rewrite.


Item by item: the full list

These are the items Articles 13 and 14 GDPR require, and where to find the information in your business. The "Record" column points to the matching field of the record of processing activities under Article 30.

Item Art. 13 Art. 14 Record (Art. 30)
Identity and contact details of the controller (and of its representative, where applicable) (1)(a) (1)(a) (1)(a): name and contact details
Contact details of the data protection officer, if you have one (1)(b) (1)(b) (1)(a)
Purposes of the processing and the legal basis for each purpose (1)(c) (1)(c) (1)(b): purposes (the legal basis is not a record field; add a column)
Legitimate interests pursued, where that is the basis relied on (1)(d) (2)(b) Same added column
Categories of personal data concerned Not required (1)(d) (1)(c)
Recipients or categories of recipients (1)(e) (1)(e) (1)(d)
Transfer outside the EU, existence or absence of an adequacy decision, appropriate safeguards and how to obtain a copy (1)(f) (1)(f) (1)(e)
Retention period or the criteria used to determine it (2)(a) (2)(a) (1)(f): time limits for erasure
Rights of access, rectification, erasure, restriction, objection and data portability (2)(b) (2)(c) Common text for all operations
Right to withdraw consent at any time (consent-based operations) (2)(c) (2)(d) Legal-basis column = consent
Right to lodge a complaint with a supervisory authority (2)(d) (2)(e) Common text
Whether providing the data is a statutory or contractual requirement, and the consequences of not providing it (2)(e) Not required Derived from the purpose (a quote cannot be prepared without an address)
Source of the data, and whether it came from publicly accessible sources Not required (2)(f) Add to the record if absent
Existence of automated decision-making, including profiling, and the logic involved (2)(f) (2)(g) Rare for a small business; saying there is none is good practice

The possible legal bases are listed in Article 6(1): consent, contract or pre-contractual steps, a legal requirement, vital interests, a public-interest task, legitimate interests. For a small business, three come up almost every time: contract (quotes, orders, invoices), legal requirement (keeping accounting records) and consent (newsletter, non-essential trackers). What you can do now: add a "legal basis" column to your record and fill it line by line.


The "record first" method: one processing operation, one block

The record of processing activities under Article 30 GDPR already holds, for each operation, the purposes, the categories of people and data, the recipients, transfers outside the EU and the time limits for erasure. Two columns aside, those are the Article 13 and 14 items. If you do not have a record yet, or believe you are exempt, read our article on the record and the under-250-employees exemption first: a six-line record is enough for a small company and takes a morning to build.

The method has four steps:

  1. Complete the record with two columns it does not contain by default: the legal basis and, for data obtained elsewhere, the source. (One hour.)
  2. Write a common block at the top of the page: controller identity and contact details, DPO if there is one, the list of rights, the right to complain to the CNIL, the address for exercising rights. (Thirty minutes.)
  3. Turn each line of the record into a block: "Quotes and orders", "Replies to contact requests", "Newsletter", "Job applications", "Audience measurement". Each block gives, in the same order, purpose, legal basis, data, recipients, retention, any transfer. (Twenty minutes per operation.)
  4. Re-read with a customer in mind, delete anything that does not apply to you, date the page. (Thirty minutes.)

The advantage of this method is consistency: the policy cannot announce a processing operation that is missing from the record, or the reverse. When a new tool arrives (quoting software, a chat widget on the site), one line goes into the record and one block onto the page, the same day.


Where to put the page and how to link it


The most frequent mistakes

  1. A policy copied from another company. It describes someone else's processing, sometimes under their name. Every block on your page describes an operation you actually carry out.
  2. Purposes without a legal basis. "We use your data to improve our services" says neither why this is permitted nor what the person can do about it.
  3. A "cookies" paragraph with no list. "This site uses cookies" informs nobody of anything. The list of trackers, who sets them, their purpose and their lifetime are what is expected.
  4. No retention period. "As long as necessary" is neither a period nor a criterion. "Until the end of the business relationship, then for the statutory retention period for accounting records" is.
  5. No right to complain. The right to take a complaint to the CNIL is missing from many pages, even though it fits in one sentence.
  6. No withdrawal of consent for the newsletter or the trackers, although Article 7(3) GDPR provides that withdrawing consent shall be as easy as giving it.
  7. Purchased data left unmentioned. A prospecting list falls under Article 14: the source and the data categories belong on the page, and the information is sent within the month or at first contact.

Template block for one processing operation

This is the skeleton we recommend for each processing operation, to be completed with your own data. The page opens with a common block (controller, DPO if any, rights, complaint), then repeats this block once per line of the record. For a French audience, the page itself should be in French; the field labels below are given in English for readability.

Controller
  [Company name] – [address] – [contact email]
  Data protection officer (if any): [contact details]

Processing: [Quotes and orders]
  Purpose        : prepare a quote, fulfil the order, invoice
  Legal basis    : contract or pre-contractual steps
                   ; legal requirement for keeping
                   accounting records
  Data           : identity, contact details, content of the
                   request, billing data
  Provision      : needed to prepare the quote; without it the
                   request cannot be handled
  Recipients     : [hosting provider], [quoting software],
                   [accountant], [payment provider]
  Transfer outside the EU : [none] / [country, safeguard,
                   where to obtain a copy]
  Retention      : [length of the business relationship + N years];
                   accounting records: [statutory period]
  Source (Art. 14 only) : [list, directory, partner]

Your rights
  Access, rectification, erasure, restriction, objection,
  portability; withdrawal of consent at any time for
  consent-based operations.
  To exercise them: [email / postal address]
  Complaint: you may contact the CNIL (www.cnil.fr)

Last updated: [date]

Checklist


Check that your legal pages are present

The free Sitetals check reviews your home page and reports, among other things, whether a legal notice page or a privacy policy page is missing or unreachable, and which third-party services your site loads. It is a starting point for the review described above, not a replacement for it.

Run the free check

Also worth reading:


Sources: Regulation (EU) 2016/679, Articles 6, 7, 12, 13, 14 and 30 · CNIL, "Conformité RGPD : comment informer les personnes et assurer la transparence ?" · Law no. 78-17 of 6 January 1978, article 82 · Sitetals methodology.

Sitetals editorial team