Privacy policy

A privacy policy is a document through which a company fulfils its information obligation towards the people whose data it processes. It must be comprehensible and must correspond to reality, which is almost never the case with adopted templates. It contains the identification of the controller and, where applicable, the Data Protection Officer, the categories of data processed, the purposes and legal bases for each purpose, the recipients of the data including tool providers, information on transfers outside the European Union, retention periods, the rights of the data subject and how to exercise them, and information on the possibility of lodging a complaint with the supervisory authority. The document must be available at the moment the data is collected, that is, at the form, not hidden in the footer. Update it with every new tool or purpose. It is also worthwhile to keep an internal overview of which tool collects what data and who has access to it, otherwise the document will over time stop corresponding to reality.

See also: Consent to data processing, Data processing agreement, Data transfers outside the EU.