If you're a freelancer or run a small business and collect any personal data — client emails, a contact form, invoicing details, website analytics, a mailing list — GDPR requires you to publish a privacy policy (technically called a "privacy notice" under Articles 13 and 14). Most freelancer privacy policies fail compliance not because they're missing entirely, but because they're copy-pasted from a template that skips half of what's legally required. Here's what actually has to be in there.
If your site sets any non-essential cookies (analytics, embedded video, ad pixels), yes — that's a separate disclosure requirement layered on top of GDPR via the ePrivacy rules, and it needs prior opt-in consent (no pre-ticked boxes, no "by continuing to browse you accept cookies" banners — those don't count as valid consent under current EDPB guidance). See our cookie consent banner guide for exactly what a compliant banner has to do.
If you personally process data on behalf of a client (e.g. you're a freelance developer, marketer, or VA with access to their customer data), Art. 28 GDPR requires a written DPA between you and that client — separate from your own site's privacy policy. This is easy to overlook because it's about you as a processor, not just a controller. See our DPA guide for freelancers for what it must contain and when it applies.
A privacy policy is what you tell people before anything happens. If a security incident does happen — a lost laptop, a misdirected email, a hack — a separate, time-sensitive obligation kicks in: a 72-hour clock to assess whether you must notify the Garante, and possibly the affected people directly. See our guide to the first 72 hours after a data breach for the decision tree.
Your privacy policy tells visitors what you do with their data — a ROPA is the internal record proving it, and answering it fast if someone asks. The "under 250 employees" exemption has an exception that catches most freelancers anyway. See our ROPA basics guide for what a minimal one needs to contain.
If you answered "no" or "not sure" to more than one of those, the policy likely needs a rewrite rather than a patch.
A privacy policy is one piece of a wider compliance picture. Next to your actual forms, you also need short consent clauses — the notice people see before they tick a box, not the full policy itself. For the six legal bases, the DPO question, and a day-one checklist covering everything else, see our plain-language GDPR guide.
Want a first draft instantly instead of writing one from these rules? Try the free privacy policy generator — fill in your details, get a ready-to-use policy in English or Italian, right in your browser, no signup.
NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this situation: a ready-to-edit Privacy Policy, Cookie Policy, consent clauses, a full Art. 28 DPA, a mini Records-of-Processing (ROPA) template, and a breach-notification checklist — €29 one-time, instant download, editable .docx and .pdf.
See what's included →Not legal advice. This guide is general information, not a substitute for advice from a qualified lawyer or data protection professional about your specific situation. NormaKit's templates are likewise informational starting points, not legal advice, and should be reviewed and adapted before use.