The GDPR.eu privacy notice guide covers the legal requirements. This article condenses them into a minimalist template that satisfies regulators and is actually readable by users. Six sections, around 1,000 words, designed for the human reader rather than the lawyer.

The 6-section structure

1. Who you are (1 paragraph)

Legal name, address, contact email. If you have a DPO, name them. If you do not, say why.

2. What data you collect (3-5 bullets)

Categories, not exhaustive lists. "Account data (name, email)", "usage data (pages visited, clicks)", "billing data (card last 4, name on card)".

3. Why you collect it (table)

Two columns: data category vs purpose. Each row maps a category to one or more purposes (account management, billing, support, analytics).

One sentence per purpose: "Contract performance" for account, "Legitimate interest" for analytics, "Consent" for marketing.

5. Who else sees the data (sub-processor list)

Named third parties with the role each plays (payment, email delivery, hosting). Link to a longer page if the list is dynamic.

6. User rights and how to exercise them (1 paragraph + contact)

List the rights (access, correction, deletion, portability, objection), one sentence on the process, the contact email or URL.

SectionTarget lengthCommon mistake
Who you are1 paragraphHidden behind "Contact Us" link
What you collect3-5 bulletsExhaustive 30-item list
Why you collectTableVague "to serve you"
Legal basis1 line per purpose"Multiple legal bases apply"
Sub-processorsNamed list"Third-party providers"
Rights1 paragraphBuried in legal language

The minimalist template is not less compliant; it is more readable. Article 12 GDPR requires "concise, transparent, intelligible" language. The 20-page legalese policy fails Article 12 in spirit even when it passes in form.

What to omit

  • The "Definitions" section. Users do not want a glossary; if a term is unclear, replace it.
  • The acceptance language at the bottom. By using your product, the user accepts; explicit acceptance text is theater.
  • The "changes to this policy" boilerplate. Replace with a real changelog.
  • Repeated jurisdiction notes ("if you are in the EU... if you are in California..."). Group user rights once.

Conclusion

A privacy notice is documentation, not literature. The shortest version that contains all the required information passes both regulators and humans. The six-section template is the proven minimum.

To generate this minimalist template per jurisdiction in one pass, try Termerly free.