The GDPR.eu privacy notice guide covers the legal requirements. This article condenses them into a minimalist template that satisfies regulators and is actually readable by users. Six sections, around 1,000 words, designed for the human reader rather than the lawyer.
The 6-section structure
1. Who you are (1 paragraph)
Legal name, address, contact email. If you have a DPO, name them. If you do not, say why.
2. What data you collect (3-5 bullets)
Categories, not exhaustive lists. "Account data (name, email)", "usage data (pages visited, clicks)", "billing data (card last 4, name on card)".
3. Why you collect it (table)
Two columns: data category vs purpose. Each row maps a category to one or more purposes (account management, billing, support, analytics).
4. Legal basis for each purpose
One sentence per purpose: "Contract performance" for account, "Legitimate interest" for analytics, "Consent" for marketing.
5. Who else sees the data (sub-processor list)
Named third parties with the role each plays (payment, email delivery, hosting). Link to a longer page if the list is dynamic.
6. User rights and how to exercise them (1 paragraph + contact)
List the rights (access, correction, deletion, portability, objection), one sentence on the process, the contact email or URL.
| Section | Target length | Common mistake |
|---|---|---|
| Who you are | 1 paragraph | Hidden behind "Contact Us" link |
| What you collect | 3-5 bullets | Exhaustive 30-item list |
| Why you collect | Table | Vague "to serve you" |
| Legal basis | 1 line per purpose | "Multiple legal bases apply" |
| Sub-processors | Named list | "Third-party providers" |
| Rights | 1 paragraph | Buried in legal language |
The minimalist template is not less compliant; it is more readable. Article 12 GDPR requires "concise, transparent, intelligible" language. The 20-page legalese policy fails Article 12 in spirit even when it passes in form.
What to omit
- The "Definitions" section. Users do not want a glossary; if a term is unclear, replace it.
- The acceptance language at the bottom. By using your product, the user accepts; explicit acceptance text is theater.
- The "changes to this policy" boilerplate. Replace with a real changelog.
- Repeated jurisdiction notes ("if you are in the EU... if you are in California..."). Group user rights once.
Conclusion
A privacy notice is documentation, not literature. The shortest version that contains all the required information passes both regulators and humans. The six-section template is the proven minimum.
To generate this minimalist template per jurisdiction in one pass, try Termerly free.
