Privacy policy for a website | Obligations GDPR

Share

When you are preparing to create a website to offer your products or services, the first instinct is often to think about the logo, the design, the artistic direction of the site, or the customer experience. However, in practice, a website is not limited to being a simple showcase. Above all, you must take into account several rules, particularly those relating to data protection. The purpose of this article is to help you understand what a privacy policy is, what it must contain, and the precautions that should be taken.

“Data is a treasure. Knowing how to use and protect it is the key.” S. LENDI, “Collect data while respecting your customers”, in Marketing in the Age of AI and the Web, Vuilbert, 2024, p. 50.

General Data Protection Regulation (GDPR)

Throughout the European Union, the collection and processing of data are governed by the General Data Protection Regulation, hereinafter referred to as the GDPR. This regulation aims to protect the privacy of natural persons when their personal data is collected, while also guaranteeing the free movement of data between Member States. Indeed, as soon as a website collects data about its visitors, it falls within the scope of the GDPR. A contact form, a newsletter subscription, or even certain cookies will generally involve the processing of personal data.

In practice, many websites use and publish standard privacy policies that are not adapted to how the website actually operates and do not reflect the reality of their business activity. However, a poorly drafted or incomplete privacy policy may expose the website operator to legal difficulties. This is why it is necessary to be assisted by a specialist in order to put in place a tailor-made privacy policy adapted to your activity.

Definitions and concepts

Before drafting a privacy policy, it is useful to understand certain basic GDPR concepts. These concepts make it easier to understand the obligations that must be respected when creating a website, what your privacy policy must contain, and the role of each of the actors involved.

  • Personal data: This refers to any information that makes it possible to identify a person, directly or indirectly. This may include, for example, a name, a telephone number, location data, or an online identifier.
  • Data processing: This refers to all operations carried out on personal data. It may include collecting data, recording it, organising it, using it, transmitting it, sharing it, storing it, etc. In practice, a simple contact form already constitutes data processing.
  • Data controller: This is the natural or legal person, company, or organisation that determines the purposes, meaning the way in which and the reasons why the data will be collected and used. In other words, if you decide to create a website for your activity and you decide what data will be collected and for what purpose, then you are the data controller.
  • Purpose of processing: The purpose refers to the reason why the data is collected. This is a key concept, because you must always be able to justify why you are asking your visitors for a particular piece of information.
  • Purpose of processing: The purpose refers to the reason why the data is collected. This is a key concept, because you must always be able to justify why you are asking your visitors for a particular piece of information.
  • Data subject: This is the person whose personal data is collected or processed for a purpose determined by the data controller. In other words, it is any person who is identified or identifiable, directly or indirectly, on the basis of the information being processed.

These concepts are fundamental and form the basis of any privacy policy: they make it possible to understand its logic and to structure it properly.

What is the purpose of a privacy policy?

Far from being an accessory or decorative document, a privacy policy is an important legal tool. Contrary to what one might think, a privacy policy is not simply a text inserted at the bottom of a website in order to comply with the rules. From both a legal and practical point of view, it is a document that informs users and explains how the website uses their personal data. It answers a series of questions that every user has the right to ask. For example: how will my data be collected? Why and how will it be used by the website? With whom may it be shared? How long will it be stored? And above all, what are my rights and how can I exercise them?

For this reason, the GDPR imposes an obligation to provide information that is clear, transparent and accessible. In practice, this obligation is generally fulfilled through a privacy policy adapted to the way the website operates. Beyond the legal obligation, the privacy policy also helps establish a relationship of trust between the user and the website.

💡 In practice, as the website owner, the benefit is twofold: 1) you comply with a legal obligation to provide information and 2) you give your website greater credibility.

The privacy policy and the cookie policy are often confused, but they do not have the same purpose. On the one hand, the privacy policy concerns the processing of personal data as a whole. On the other hand, the cookie policy concerns cookies and other tracking technologies used on the website.

The privacy policy, informing users about the use of personal data

The privacy policy explains how a website collects, uses, stores and protects users’ personal data. It concerns data collected through a contact form, a quotation request, a newsletter subscription, an online order or the creation of a customer account. It must specify what data is collected, why it is used, on what legal basis, how long it is stored, with whom it may be shared, and what rights users may exercise. In short, the privacy policy allows users to understand what the website does with their personal data.

The cookie policy concerns cookies and similar technologies used on the website. It explains which cookies are placed, for what purposes, for how long, by whom, and how the user can accept them, refuse them or change their preferences. These may include cookies that are necessary for the functioning of the website, analytical cookies, advertising cookies, cookies linked to social networks, or other tracking tools. In short, the cookie policy allows users to understand which trackers are used when they browse the website.

Not all cookies are subject to the same rules

Some cookies are strictly necessary for the functioning of the website. For example, they may be used to secure browsing, keep items in a shopping cart, remember the user’s language choice, or record the user’s cookie preferences. These cookies can generally be used without prior consent, because they are essential for the functioning of the website or for the provision of a service requested by the user. By contrast, analytical, advertising or marketing cookies are not essential cookies for the functioning of the website. When they make it possible to measure audience traffic, track user behaviour, personalise advertising or create profiles, they require clear information and, in many cases, prior consent.

Why is this distinction important, and should two separate documents be provided?

The distinction between a privacy policy and a cookie policy is important in order to ensure the website’s compliance with the GDPR. A website may have a privacy policy, but still remain incomplete if it does not explain the cookies used. Conversely, a cookie policy does not replace a privacy policy.

If the website uses tools such as Google Analytics, Meta Pixel, LinkedIn Insight Tag, an emailing platform, a CRM or a payment module, these tools must be identified and explained on the website through the appropriate notices or URLs. For a professional website, we recommend providing a separate privacy policy and cookie policy. This distinction makes it possible to properly inform users, strengthen the transparency of the website and limit the risks of non-compliance with the GDPR.

💡 Privacy and cookie policies must reflect the actual reality of the website, the tools used and the data actually collected.

European GDPR framework, cookies and case law of the Court of Justice

A website privacy policy is first and foremost part of a European legal framework. The central text is the General Data Protection Regulation, better known as the GDPR. It applies throughout the European Union and requires the data controller to inform users.

In practical terms, when a website collects personal data, it must explain to the user who is processing their data, why the data is being used, on what legal basis, how long it will be stored, with whom it may be shared, and what rights may be exercised. These obligations arise in particular from Articles 12, 13 and 14 of the GDPR.

Cookies are also governed by European law

Cookies and other trackers are also regulated at European level, in particular by the ePrivacy Directive. Article 5(3) of that Directive provides that storing information, or accessing information already stored on the user’s device, generally requires prior information and prior consent, unless the cookie is strictly necessary for the provision of the service requested.

💡 In practice, this explains why strictly necessary technical cookies can generally be used without prior consent, whereas analytical, advertising or marketing cookies must be assessed with much greater caution.

European case law has strengthened the consent requirement

The Court of Justice of the European Union clarified these rules in the Planet judgment. In that case, the Court held that a pre-ticked box could not constitute valid consent for the use of cookies. Consent must therefore result from a positive action by the user, and not from passive or ambiguous acceptance. This case law is particularly important for websites.

External tools and social networks must be analysed carefully

European case law has also recalled that the operator of a website may bear responsibility when it integrates certain third-party tools. In the Fashion ID case, the Court of Justice held that a website integrating Facebook’s “Like” button could be jointly responsible with Facebook for the collection and transmission of certain data relating to visitors. This decision shows that a website cannot ignore the tools it installs. Social media buttons, advertising pixels, statistical tools, plugins or marketing tags must be analysed, because they may lead to the collection or transmission of personal data. You can also read our article dedicated to how to exercise the right to be forgotten on Google.

Transfers of data outside the European Union must be mentioned

The privacy policy must also take into account any transfers of data outside the European Union. This issue is important when the website uses providers or digital tools established outside the EU, including certain analytics, marketing, payment, cloud or CRM services. In the Schrems II judgment, the Court of Justice of the European Union recalled that transfers of data to third countries must guarantee a level of protection essentially equivalent to that provided within the European Union. Our law firm is specialised in European Union Law.

💡 In practice, when a website uses providers that involve a transfer of data outside the EU, the privacy policy must mention this and explain, in an accessible manner, the safeguards put in place.

What must a privacy policy contain?

The document must contain several elements. This information must allow your users to understand your role, your practices, and how they can exercise their rights. The privacy policy must indicate the following:

Identity of the data controller

The privacy policy must include the full identity of the data controller. In other words, it is necessary to identify the person, company or organisation — or, in certain cases, the processor — that collects and uses personal data through the website. It is important to include all information allowing identification, namely the full name, the address of the registered office, the email address and the telephone number.

💡 For example, if a person fills in a contact form, they must be able to know which company is processing their data, where that company is located, and have an email address available in order to ask questions regarding the protection of their data.

The type of data collected

The website must indicate what information is collected. This data may vary depending on the activity carried out. For example, it may include an email address, a name, a telephone number, an address, an account number, or the delivery method.

The purpose of the processing

It is necessary to indicate for what reason or reasons the data has been collected. In other words, the privacy policy must explain what the collected data is actually used for. This point is important because it allows the user to understand the usefulness of the collection. For example, data may be collected for the purpose of analysing statistics and website performance, improving the customer experience, processing an order, ensuring delivery, sending an invoice, etc.

The legal basis

The GDPR does not allow personal data to be processed without a legal ground. In order to process data, data controllers must rely on a “legal basis”. This requirement helps prevent abusive and unjustified data collection. This concept may seem technical, but it is based on a simple idea: you cannot process personal data without a valid reason provided for by law. Without justification, the processing is unlawful.

  • The GDPR provides several possible legal bases:
  • The consent of the data subjects;
  • The performance of a contract;
  • A legal obligation under EU law or national law;
  • Where the processing is necessary for the performance of a task carried out in the public interest;
  • To protect the vital interests of a person;
  • The legitimate interests of the organisation, but only if this does not infringe the fundamental rights of individuals.

💡 When drafting your privacy policy, it is not enough to state what you do. You must also be able to explain why you do it.

The retention period

The privacy policy must indicate how long personal data will be kept. GDPR provides that this data may not be kept “longer than necessary in relation to the purpose for which it was collected”.

💡 In practice, this means that a website cannot keep its users’ data indefinitely. The retention period must be adapted on a case-by-case basis, depending on the online activity.

When drafting a privacy policy, it is necessary to ask, for each type of data, how long it remains useful, and then provide for its archiving or deletion.

Users’ rights

The role of the privacy policy is to inform website visitors about the rights they may exercise in relation to their personal data. To this end, the GDPR provides several rights allowing each user to retain control over their information. The website operator must be able to guarantee the right of access to personal data to every user who requests it. In this way, the user can know whether their data is being processed and, if so, how. The user has the right to request and obtain from the data controller the rectification of their personal data if it is inaccurate, and this must be done without undue delay. Data subject has the right to request and obtain the erasure of their personal data.

The user has the right to obtain the restriction of the processing of their data in the situations provided for by Article 18 of the GDPR. The user has the right to receive from the website operator the personal data concerning them “in a structured, commonly used and readable format”. Finally, the user has the right to lodge a complaint concerning the processing of their personal data with the data protection authority competent for the territory of the EU Member State, if they consider that their rights have not been respected.

Contact details

Finally, in order to ensure that the document is serious and that the privacy policy is effective, it is necessary to provide contact details for all questions or complaints relating to the privacy policy. This makes it possible to give practical effect to the exercise of users’ rights.

💡 In practice, this means indicating the identity of the data controller, a contact email address and a postal address.

Lastly, the privacy policy must be fully consistent with the activity of the website. Each statement must correspond to your actual practices. The purpose is not to draft the longest possible privacy policy, but the most accurate one possible, faithfully reflecting the reality of your data processing.

Elements of a privacy policy

Element to be mentionedPractical explanation
Identity of the data controllerThe policy must clearly state who operates the website and processes the data: the company name, address, contact email and, where applicable, company registration number.
Data collectedIt is necessary to specify what data is collected: surname, first name, email address, telephone number, postal address, order data, payment data, IP address, browsing data, etc.
Purposes of the processingThe policy must explain why the data is used: to respond to a contact request, process an order, issue an invoice, manage a newsletter, improve the website, ensure security or comply with a legal obligation.
Legal basis for the processingEach processing activity must be based on a legal ground: consent, performance of a contract, legal obligation, legitimate interest or another legal basis provided for by the GDPR.
Recipients of the dataIt is necessary to indicate who may have access to the data: internal staff, hosting provider, IT service provider, payment tool, emailing platform, accountant, carrier or other processor.
Transfers outside the European UnionIf certain data is transferred outside the European Union, the policy must mention this and explain the safeguards put in place.
Retention periodData cannot be stored indefinitely. The policy must indicate how long the data is kept, depending on the type of data and the purpose pursued.
Users’ rightsUsers must be informed of their rights: access, rectification, erasure, restriction, objection, portability and withdrawal of consent where the processing is based on consent.
How to exercise rightsThe policy must explain how the user can exercise their rights: email address, postal address, response period and any information that may be necessary to identify the request.
Right to lodge a complaintThe user must be informed that they may lodge a complaint with the competent data protection authority if they consider that their rights have not been respected.
Cookies and trackersIf the website uses cookies, the policy must refer to a cookie policy or clearly explain the categories of cookies used, their purposes and the consent mechanisms.
Data securityIt is recommended to indicate that technical and organisational measures are implemented to protect the data against unauthorised access, loss, alteration or disclosure.
Updating the policyThe policy must provide that it may be amended in the event of changes to the website, the tools used or legal obligations. The date of the last update must be indicated.

GDPR can become a commercial advantage

For a company, a self-employed professional or a liberal profession, GDPR compliance can also become a real commercial advantage. Today, users are increasingly attentive to how their personal data is used. Before requesting a quote, subscribing to a newsletter or placing an online order, they want to know whether the website is serious and trustworthy. A company that explains how it collects, uses and protects personal data therefore sends a positive message to its clients. It shows that it takes data security, privacy protection and transparency seriously. At our firm, we are specialised in business consultancy and Corporate law.

The privacy policy strengthens trust

A well-drafted privacy policy allows the user to understand what is done with their data. It reassures the visitor and reduces doubts when they are asked to provide personal information. This trust can have a direct impact on the user’s behaviour. A reassured visitor will be more likely to contact the company, request a consultation, create an account, subscribe to a newsletter or complete a purchase. Conversely, a vague, missing or copied privacy policy may give a poor impression and immediately create distrust.

GDPR compliance as a sign of professionalism

Respecting the GDPR is not only about complying with the law. It is also a way of showing that the company is responsible and attentive to its relationship with its clients. For certain activities, this aspect is even more important, especially where sensitive data is processed. It may even make the difference compared with a competitor whose website does not offer the same guarantees.

A way to stand out from the competition

Many websites still have privacy policies that are too general, incomplete or poorly adapted to their activity. A company that invests in data protection can therefore stand out. A tailor-made privacy policy, a cookie policy and properly structured forms show that the company acts in a professional and responsible manner. This can become a commercial argument and strengthen the brand image.

The privacy policy as a protection tool

Good GDPR compliance protects users, but it also protects the company. It helps clarify processing activities, identify the tools used, better regulate external service providers and limit risks. It also helps avoid inconsistencies. In practice, a privacy policy is a tool for trust, prevention and commercial differentiation.

privacy policy website

The privacy policy must be updated regularly

A privacy policy must evolve together with your website, your tools and your business activity. A document that was compliant at the time it was drafted may become incomplete a few months later if your website changes or if new data processing activities are introduced. This regular update is important for your GDPR compliance, but also for your professional image. An up-to-date privacy policy shows that your company genuinely follows the evolution of its website. Conversely, an old, vague or clearly outdated policy can weaken visitors’ trust.

It is recommended to indicate the date of the last update in the privacy policy. This mention allows users to know whether the information published is recent and still relevant. A regular review of your privacy policy therefore helps limit legal risks, improve transparency towards your clients and maintain compliance adapted to the evolution of your online activity.

External service providers must be identified

Most websites do not operate on their own. They generally use several external service providers. For example: hosting provider, web agency, payment tool, emailing platform, CRM, analytics tool, booking module, delivery service, invoicing software or IT provider.

💡 These service providers may, directly or indirectly, have access to certain personal data. For example, a hosting provider may store website data, an emailing platform may process the email addresses of newsletter subscribers, a payment tool may be involved in managing transactions, and a CRM may centralise information relating to clients or prospects.

The user must be able to understand that their data is not always processed only by the company operating the website. Certain data may be transmitted or made accessible to third parties, whether technical or professional, only when this is necessary for the functioning of the website or for the provision of the requested service. The privacy policy must therefore indicate the categories of recipients who may receive the data.

An issue of transparency and trust

Mentioning external service providers helps strengthen the transparency of the website. The user then knows that their data may be processed by certain technical partners, but within a defined framework and for specific purposes. Conversely, a privacy policy that does not mention any service provider, even though the website uses a payment tool, a newsletter system, a CRM or analytics cookies, is incomplete or inconsistent. It is therefore important to adapt the privacy policy to the tools actually used by the website.

Drafting adapted to your activity

A well-drafted privacy policy must identify the relevant service providers according to the activity carried out. For example, an e-commerce website will need to mention, among others, payment, delivery and invoicing providers. A services firm should rather refer to contact tools, appointment booking tools, client management tools or emailing tools. An online platform, for its part, will need to analyse its technical, statistical and commercial tools more precisely. The objective is not to make the document unnecessarily complex, but to allow the user to understand, in simple terms, who may access their data, for what reasons and within what framework.

Why should you not use standard templates?

It may be tempting to use an existing template found online or to copy and paste the privacy policy of another website. However, each website has its own specific features, and a privacy policy must reflect the actual reality of your website and your activity. It must be consistent with your practices, including data processing and data collection. Indeed, from one activity to another, you will not collect and use the same data.

By using a standardised, overly vague or poorly adapted template, your privacy policy may not truly correspond to the reality of your activity. The template used may include practices that you do not actually carry out, or, conversely, fail to mention essential elements. This may be considered a breach of your obligation to provide information. It is therefore strongly advisable and recommended to draft a tailor-made privacy policy adapted to your online activity.

‼️ Examples and risks: For example, a website may state in its privacy policy that it only collects the user’s surname, first name and email address through a contact form. In reality, that same website may also use Google Analytics, a newsletter, a payment module, an external CRM or advertising cookies. If the information provided to the user is inaccurate or incomplete, this may create a lack of transparency, inconsistency, or even a risk of sanctions in the event of a breach of the GDPR. This is why the privacy policy must be drafted on a tailor-made basis, according to the data collected, the tools used and the actual activity of the website.

Why should you be assisted by a specialised lawyer and professional?

Drafting a privacy policy may seem simple at first glance, but in practice, it requires a great deal of time and a high level of precision. It is not merely a matter of producing a text, but of identifying a whole series of legal elements and explaining them using precise legal terminology, while remaining accessible to the general public.

Furthermore, being assisted by a professional helps avoid many omissions or errors. A professional can easily identify the risks, structure the information that must be provided, and draft a policy adapted to your activity.

Some questions about privacy policy

Question to checkWhy it is important
Is the data controller clearly identified?The user must know which person, company or organisation is processing their personal data.
Are the contact details up to date and easily accessible?Users must be able to ask a question or exercise their rights easily.
Are the categories of data collected described accurately?The policy must explain what data is collected: name, email address, telephone number, IP address, order data, etc.
Has the legal basis for each processing activity been correctly identified?Each processing activity must be based on a valid ground: consent, contract, legal obligation, legitimate interest, etc.
Does each processing activity have a clear, specific and legitimate purpose?The user must understand why their data is collected and used.
Has a retention period been set?Data cannot be kept indefinitely.
Are the rights of the data subjects clearly presented?The policy must inform users of their rights: access, rectification, erasure, objection, restriction, portability, etc.
Does the privacy policy truly correspond to the activities of the website?The document must reflect the website’s actual practices: forms, cookies, newsletter, payment, CRM, external service providers, etc.

Success stories regarding privacy policies

Within our firm, we are regularly called upon to assist self-employed professionals, companies, liberal professions and website operators with bringing their privacy policies and GDPR documents into compliance. Each case is different. The objective is to understand how the website works, what data is collected, which tools are used, and which service providers are involved.

Case 1 | Adaptation of a privacy policy for a professional website

In a recent case, a client already had a privacy policy, but it was too general and did not correspond to the actual functioning of the website. The document did not mention certain tools used by the website, such as the contact form, an analytics tool, an emailing platform and several external service providers. Our intervention consisted of analysing how the website worked, identifying the data processing activities, clarifying the applicable legal bases, adapting the retention periods and reformulating the policy. The result was a privacy policy adapted to the client’s activity.

If you would like to obtain more information about the right to be forgotten for entrepreneurs and professionals, we invite you to read our article on the right to be forgotten for entrepreneurs and professionals.

Case 2 | Creation of a privacy policy for an online activity

We also assisted a company that was launching a new online activity and wanted to have, from the outset, a legally well-structured website. In this context, we drafted a tailor-made privacy policy, taking into account contact forms, quotation requests, prospect management and technical service providers. This approach allowed the client to launch its website while strengthening users’ trust.

Case 3 | Consistency between the privacy policy, cookies and marketing tools

In another case, the main difficulty did not come only from the privacy policy itself, but from its lack of consistency with the tools used on the website: analytics cookies, a newsletter tool, marketing tags and an appointment booking module. We therefore checked the consistency between the privacy policy, the cookie policy, the forms and the tools integrated into the website. This analysis made it possible to identify missing information, better inform users and reduce risks.

Case 4 | Compliance of an e-commerce website with forms, payment, newsletter and cookies

We also assisted a company operating an e-commerce website whose activity involved several data processing operations: creation of customer accounts, online orders, electronic payment, delivery, invoicing, newsletter, tools and advertising cookies. The privacy policy merely stated that certain data could be collected in order to respond to users’ requests, without explaining the actual processing activities.

Our intervention consisted of carrying out a complete analysis of the user journey: browsing the website, registration, purchase, payment, delivery, newsletter subscription and cookie management. This compliance work allowed the company to have a professional website. It also strengthened customer trust when providing personal data, creating an account or completing an online order.

These examples show that a privacy policy must be designed as a genuine compliance tool, but also as an element of trust for the website’s clients, prospects and users.

📍 Our firm assists clients in apersonalised manner.

The privacy policy protects your website and reassures your clients

Drafting a privacy policy is not simply a matter of inserting a standard text at the bottom of a website. It is a much more delicate exercise than it may seem, because it requires a detailed analysis of your activity and of the objectives pursued. Sometimes, it can be difficult to identify precisely the applicable legal bases and the data collected. Indeed, it is not always easy to determine what must be mentioned, nor how this information should be presented in order to meet the requirements of Belgian law and the GDPR.

In this context, having a privacy policy that is poorly adapted to your activities can weaken your business and expose you to legal difficulties. Conversely, a tailor-made text drafted with proper legal understanding creates trust among your users, clients and prospects. Our firm provides personalised assistance at every stage.

Contact us at info@arthurmarin.com or by telephone on +32 465 345 345 to benefit from tailor-made support.

💡 To bring your website into compliance with the GDPR, our firm can assist you. Contact us for tailor-made support.

Latest posts

we talk?

Let´s work together

Contact us

info@arthurmarin.com

Call us

+32 465 34 53 45

Scroll to Top