When a company publishes its website —a simple corporate page, a contact form, a newsletter or an online shop— it starts to process personal data of the people who visit it. From that moment, the privacy policy stops being a footer ornament and becomes the document with which the organisation fulfils its duty to inform towards those who entrust it with their data.
This guide is intended for the company that needs to understand what the privacy policy of its website must contain: what it is exactly, why the regulations require it, what minimum information it must include and how it differs from the legal notice and the cookie policy. The approach is operational and informative, without an alarmist tone.
What the privacy policy of a website is (and what it is not)
The privacy policy is the document in which the controller —the company that owns the website— explains clearly and accessibly what personal data it collects through the site, for what purposes it processes them, on what legal basis it relies, with whom it shares them and what rights the user can exercise. In legal terms, it is the instrument through which the duty to inform that the GDPR imposes on the controller is fulfilled.
It is worth clarifying from the outset what the privacy policy is not:
- It is not a contract that the user signs, nor a text that imposes obligations on them. It is information the company provides to them.
- It is not the legal notice. The legal notice identifies the company as the service provider; the privacy policy explains the processing of data.
- It is not the cookie policy. Cookies and other tracking devices have their own regime and their own document.
- It is not a copyable formality. It must reflect the real processing of that specific website, not that of someone else's template.
Why it is mandatory: the duty to inform under art. 13 GDPR
The obligation to have a privacy policy does not arise from a rule that literally says "every website shall have a privacy policy". It arises from the duty to inform that art. 13 of the GDPR (Regulation (EU) 2016/679) imposes on the controller whenever it obtains personal data directly from the data subject. And a website with a contact form, a newsletter sign-up, a customer registration or a shopping cart obtains data directly from the data subject.
Art. 13 GDPR requires that, at the moment the data is obtained, certain information be provided to the data subject. The privacy policy is simply the usual and orderly way of delivering that information in a web environment. Two further pieces of the Spanish framework are added to this:
- Art. 12 GDPR: the information must be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language. It is not enough for the information to exist: it has to be understandable.
- Art. 14 GDPR: when the data is not obtained from the data subject themselves but from a third party (for example, a professional directory or an intermediary), the duty to inform still exists, with some particularities regarding the deadline and the source of the data. A complete privacy policy also covers this scenario when the company captures data through those channels.
- Art. 11 of the LOPDGDD (Organic Law 3/2018): it regulates transparency and the data subject's right to information and enables the layered-information model, very useful on the web: a brief first layer at the collection point, with the essential information and a link to the full policy as a second layer.
Alongside the privacy policy, the website also needs its legal notice, which responds to a different rule: art. 10 of Law 34/2002 (LSSI-CE), which requires the provider of information society services to identify itself (name, NIF/CIF, address, contact details and, where applicable, registration or professional membership data). These are two different duties that coexist in the same footer.
For the detail of the obligations that the LSSI-CE imposes on a website, see the complete guide to the LSSI-CE. And for a picture of all the legal pieces a website needs, the checklist of legal requirements for a website.
What the privacy policy must include: minimum content
The minimum content of the privacy policy is derived from art. 13 GDPR (and art. 14 where applicable). Translated to a company website, the complete policy must inform, as a minimum, of the following:
- Controller. Identity and contact details of the company that owns the website. It is the "who processes my data".
- Data Protection Officer (DPO). Their contact details, if the company has appointed one. Not all organisations are required to appoint one; if one exists, it must be reported.
- Purposes of the processing. What the data is used for, specifically: to respond to a form enquiry, manage the customer relationship, send the newsletter, process an order, etc. A generic "managing the relationship" that says nothing is not enough.
- Legal basis for each purpose (art. 6 GDPR). Each purpose needs its basis: performance of a contract or pre-contractual measures, consent, legitimate interest, legal obligation. A single website usually combines several.
- Recipients or categories of recipients. To whom the data is communicated or transferred, including the processors (hosting providers, email marketing platforms, CRM, payment gateways) that access it to provide a service to the company.
- International transfers. If any provider processes data outside the European Economic Area, this must be reported and the safeguard on which the transfer relies must be indicated. It is common when using tools with servers in the United States.
- Retention periods. How long the data is kept or, if a closed period cannot be given, the criteria used to determine it.
- Rights of the data subject. Access, rectification, erasure, restriction of processing, objection and portability, with an explanation of how to exercise them and before whom.
- Right to lodge a complaint with the supervisory authority. The user must know that they can lodge a complaint with the Spanish Data Protection Agency (AEPD) if they consider that their rights are not being respected.
- Source of the data, when it has not been obtained from the data subject themselves (the art. 14 GDPR scenario).
An important detail about providers and cloud tools: when the company uses a CRM, a newsletter platform or hosting, those providers act as processors (art. 28 GDPR). The relationship is governed by a processing agreement, and the privacy policy must reflect that those third parties access the data. When the relationship with a provider ends, the rule is that it must return or allow the export of the data to the company before destroying it, never simply delete it and leave the company without it.
Privacy policy, legal notice and cookie policy: three different documents
One of the most frequent misconceptions is treating these three texts as if they were a single one or as if they were interchangeable. Each responds to a different rule and a different purpose:
| Document | Reference rule | What it is for |
|---|---|---|
| Legal notice | Art. 10 LSSI-CE | Identifies who is behind the website: name, NIF/CIF, address, contact and registration or professional membership data. |
| Privacy policy | Arts. 12 to 14 GDPR + art. 11 LOPDGDD | Informs about what personal data is processed, for what purpose, on what legal basis and what rights the user has. |
| Cookie policy | Art. 22.2 LSSI-CE | Informs about the storage and tracking devices on the user's equipment, and collects their consent when they are not strictly necessary. |
The practical rule is simple: the legal notice talks about the company, the privacy policy talks about people's data and the cookie policy talks about the tracking technology. All three must be permanently accessible from the footer, and none of them covers the function of the others.
Common mistakes in a website's privacy policy
Most problems are not due to bad faith, but to copying without analysing. These are the failures that recur most frequently:
- The generic template that does not reflect the real processing. This is the root error. A template is downloaded and published as is. The result is a policy that describes non-existent processing and omits what is actually done. The duty to inform under art. 13 GDPR is fulfilled by informing about what really happens on that website, and that requires starting from the company's actual record of processing activities.
- Vague purposes. "Managing the commercial relationship" says nothing. Each purpose must be specific and associated with its legal basis under art. 6 GDPR.
- Wrongly assigned legal bases. Asking for consent for something that is actually based on the performance of a contract, or vice versa, is a frequent error that confuses the user about their real options.
- Omitting the processors. Not mentioning the providers (hosting, email marketing, CRM, analytics) that access the data leaves the information on recipients incomplete.
- Ignoring international transfers. Using tools with servers outside the EEA without reporting it or indicating the applicable safeguard is a common omission.
- Confusing the policy with the legal notice or merging both into a single text that does not fully fulfil either of the two functions.
- Publishing it and forgetting it. When the company adds a new form, changes CRM or incorporates a new purpose, the policy must be updated. A frozen policy ends up describing a website that no longer exists.
"A privacy policy is not copied, it is built from the company's real processing activities. The text is the last layer; underneath there has to be an analysis of what data comes in through the website, what for and with whom it is shared. Without that analysis, the document informs about a website that does not exist."
Mario P. Talamillo · Managing Partner, Certix®
Quick checklist to review your privacy policy
A quick check that a project manager can carry out on the privacy policy of their website:
- Does it clearly identify the controller (the company) and its contact details?
- Does it describe the real purposes, one by one, with their legal basis under art. 6 GDPR?
- Does it mention the providers that access the data as processors?
- Does it inform about international transfers if tools outside the EEA are used?
- Does it indicate retention periods or the criteria to set them?
- Does it list the data subject's rights and how to exercise them?
- Does it inform about the right to lodge a complaint with the AEPD?
- Is it permanently accessible from the footer and linked from each form (layered information)?
- Does what it says match what the website really does today?
Frequently asked questions
What must the privacy policy of a company website include?
The information required by art. 13 GDPR: controller, DPO details if one exists, purposes and legal basis for each (art. 6 GDPR), recipients, international transfers, retention periods, rights of the data subject (access, rectification, erasure, restriction, objection and portability) and the right to lodge a complaint with the AEPD. All of it referring to the real processing of that website.
Is the privacy policy the same as the legal notice?
No. The legal notice identifies the company as the service provider (art. 10 LSSI-CE: name, NIF/CIF, address, contact). The privacy policy fulfils the duty to inform about the processing of data (art. 13 GDPR). The cookie policy is a third document (art. 22.2 LSSI-CE). They are three different texts with different functions.
Is a generic template downloaded from the internet enough?
As a reference it may help; as a definitive document, almost never. Art. 13 GDPR requires informing about the company's real processing. A template describes processing that may not be carried out and omits others that are. The policy must be built from the organisation's own record of processing activities.
Where must the privacy policy be accessible?
Permanently, normally through a link in the footer of the whole site. In addition, art. 11 LOPDGDD allows the layered model: a brief first layer next to each form, with a link to the full policy. The information must be available at the moment the data is collected.
How Certix approaches the data protection of a website
At Certix the starting point is never the template, but the analysis: what data comes in through the website, through which forms, for what purpose, on what legal basis and with which providers. From there, the information clauses and the privacy policy that truly reflect the organisation's processing are drafted. The initial contact is made directly with a compliance specialist, without commercial intermediaries or generic documents.
If you want to review how the privacy of your company's website is set up, you can learn about our data protection consultancy or write to us through the contact page.
References and resources to go deeper
- What your website needs to comply with the GDPR and the LSSI-CE (complete checklist)
- Complete guide to the LSSI-CE
- Certix data protection consultancy
This content is purely informational and educational; it does not constitute specialised legal advice in any case. The application of the regulations to each specific case requires individual analysis. Spanish regional sectoral regulations may extend or modify the general requirements described.