NormaKit Guide

GDPR Privacy Policy Checklist for Freelancers & Micro-Businesses

Practical guide · EU GDPR · applies whether you're based in Italy, elsewhere in the EU, or outside the EU and serving EU customers

If you're a freelancer or run a small business and collect any personal data — client emails, a contact form, invoicing details, website analytics, a mailing list — GDPR requires you to publish a privacy policy (technically called a "privacy notice" under Articles 13 and 14). Most freelancer privacy policies fail compliance not because they're missing entirely, but because they're copy-pasted from a template that skips half of what's legally required. Here's what actually has to be in there.

The seven things a GDPR privacy policy legally must state

The most common mistake: a privacy policy that describes the business in general terms ("we care about your privacy") but never actually lists the specific legal basis per processing activity. Under Art. 13, generic language is not sufficient — regulators (including Italy's Garante) have fined small businesses specifically for vague, boilerplate policies that don't map data categories to legal bases.

Do you also need a cookie policy?

If your site sets any non-essential cookies (analytics, embedded video, ad pixels), yes — that's a separate disclosure requirement layered on top of GDPR via the ePrivacy rules, and it needs prior opt-in consent (no pre-ticked boxes, no "by continuing to browse you accept cookies" banners — those don't count as valid consent under current EDPB guidance).

What about a Data Processing Agreement (DPA)?

If you personally process data on behalf of a client (e.g. you're a freelance developer, marketer, or VA with access to their customer data), Art. 28 GDPR requires a written DPA between you and that client — separate from your own site's privacy policy. This is easy to overlook because it's about you as a processor, not just a controller. See our DPA guide for freelancers for what it must contain and when it applies.

Quick self-audit

  1. Open your current privacy policy (if you have one).
  2. For each type of data you collect, can you point to the sentence that states its specific legal basis?
  3. Does it name a retention period or retention criteria?
  4. Does it list your actual sub-processors (or at least categories), including any outside the EU?
  5. Is there a cookie banner with genuine opt-in, if you use non-essential cookies?

If you answered "no" or "not sure" to more than one of those, the policy likely needs a rewrite rather than a patch.

Don't want to draft all of this from scratch?

NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this situation: a ready-to-edit Privacy Policy, Cookie Policy, consent clauses, a full Art. 28 DPA, a mini Records-of-Processing (ROPA) template, and a breach-notification checklist — €29 one-time, instant download, editable .docx and .pdf.

See what's included →

Not legal advice. This guide is general information, not a substitute for advice from a qualified lawyer or data protection professional about your specific situation. NormaKit's templates are likewise informational starting points, not legal advice, and should be reviewed and adapted before use.