GDPR Privacy Policy Checklist for Freelancers & Micro-Businesses
Practical guide · EU GDPR · applies whether you're based in Italy, elsewhere in the EU, or outside the EU and serving EU customers
If you're a freelancer or run a small business and collect any personal data —
client emails, a contact form, invoicing details, website analytics, a mailing list —
GDPR requires you to publish a privacy policy (technically called a "privacy notice"
under Articles 13 and 14). Most freelancer privacy policies fail compliance not
because they're missing entirely, but because they're copy-pasted from a template
that skips half of what's legally required. Here's what actually has to be in there.
The seven things a GDPR privacy policy legally must state
Who you are. Your legal name/business name, address, and contact
details (email is fine) — the "identity of the controller."
What data you collect and why. Each category of personal data (name,
email, IP address, payment details, etc.) needs its own stated purpose — "to
process your order," "to respond to your enquiry," not a vague catch-all.
Your legal basis for each purpose. One of: consent, contract necessity,
legal obligation, legitimate interest, vital interest, or public task. Freelancers
almost always rely on contract necessity (fulfilling a service) or legitimate
interest (e.g. basic analytics) — but you must name which one applies to which data.
How long you keep the data. A retention period or the criteria used to
determine one (e.g. "invoicing data is kept for 10 years per Italian tax law").
"As long as necessary" alone, with no criteria, does not satisfy Art. 13(2)(a).
Who else sees it. Any processors or sub-processors — your email
provider, hosting company, payment processor, accounting software — and, if any
are outside the EU/EEA, what safeguard applies (adequacy decision, Standard
Contractual Clauses, etc.).
Data subject rights. Access, rectification, erasure, restriction,
portability, objection, and the right to lodge a complaint with a supervisory
authority (in Italy, the Garante per la protezione dei dati personali) — stated
explicitly, not implied.
Whether disclosure is mandatory. If someone must give you data to use
your service (e.g. an email to deliver a purchased file), say so, and say what
happens if they don't provide it.
The most common mistake: a privacy policy that describes the business in
general terms ("we care about your privacy") but never actually lists the specific
legal basis per processing activity. Under Art. 13, generic language is not
sufficient — regulators (including Italy's Garante) have fined small businesses
specifically for vague, boilerplate policies that don't map data categories to
legal bases.
Do you also need a cookie policy?
If your site sets any non-essential cookies (analytics, embedded video, ad
pixels), yes — that's a separate disclosure requirement layered on top of GDPR via
the ePrivacy rules, and it needs prior opt-in consent (no pre-ticked boxes, no
"by continuing to browse you accept cookies" banners — those don't count as valid
consent under current EDPB guidance).
What about a Data Processing Agreement (DPA)?
If you personally process data on behalf of a client (e.g. you're a
freelance developer, marketer, or VA with access to their customer data), Art. 28
GDPR requires a written DPA between you and that client — separate from your own
site's privacy policy. This is easy to overlook because it's about you as a
processor, not just a controller. See our
DPA guide for freelancers
for what it must contain and when it applies.
Quick self-audit
Open your current privacy policy (if you have one).
For each type of data you collect, can you point to the sentence that states
its specific legal basis?
Does it name a retention period or retention criteria?
Does it list your actual sub-processors (or at least categories), including
any outside the EU?
Is there a cookie banner with genuine opt-in, if you use non-essential
cookies?
If you answered "no" or "not sure" to more than one of those, the policy likely
needs a rewrite rather than a patch.
Don't want to draft all of this from scratch?
NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this
situation: a ready-to-edit Privacy Policy, Cookie Policy, consent clauses, a full
Art. 28 DPA, a mini Records-of-Processing (ROPA) template, and a breach-notification
checklist — €29 one-time, instant download, editable .docx and .pdf.
Not legal advice. This guide is general information,
not a substitute for advice from a qualified lawyer or data protection professional
about your specific situation. NormaKit's templates are likewise informational
starting points, not legal advice, and should be reviewed and adapted before use.