NormaKit Guide

GDPR Privacy Policy Checklist for Freelancers & Micro-Businesses

Practical guide · EU GDPR · applies whether you're based in Italy, elsewhere in the EU, or outside the EU and serving EU customers

If you're a freelancer or run a small business and collect any personal data, client emails, a contact form, invoicing details, website analytics, a mailing list, GDPR requires you to publish a privacy policy (technically called a "privacy notice" under Articles 13 and 14). Most freelancer privacy policies fail compliance not because they're missing entirely, but because they're copy-pasted from a template that skips half of what's legally required. Here's what actually has to be in there.

The seven things a GDPR privacy policy legally must state

The most common mistake: a privacy policy that describes the business in general terms ("we care about your privacy") but never actually lists the specific legal basis per processing activity. Under Art. 13, generic language is not sufficient, regulators (including Italy's Garante) have fined small businesses specifically for vague, boilerplate policies that don't map data categories to legal bases.

Do you also need a cookie policy?

If your site sets any non-essential cookies (analytics, embedded video, ad pixels), yes, that's a separate disclosure requirement layered on top of GDPR via the ePrivacy rules, and it needs prior opt-in consent (no pre-ticked boxes, no "by continuing to browse you accept cookies" banners, those don't count as valid consent under current EDPB guidance). See our cookie consent banner guide for exactly what a compliant banner has to do.

What about a Data Processing Agreement (DPA)?

If you personally process data on behalf of a client (e.g. you're a freelance developer, marketer, or VA with access to their customer data), Art. 28 GDPR requires a written DPA between you and that client, separate from your own site's privacy policy. This is easy to overlook because it's about you as a processor, not just a controller. See our DPA guide for freelancers for what it must contain and when it applies.

What if something goes wrong?

A privacy policy is what you tell people before anything happens. If a security incident does happen, a lost laptop, a misdirected email, a hack, a separate, time-sensitive obligation kicks in: a 72-hour clock to assess whether you must notify the Garante, and possibly the affected people directly. See our guide to the first 72 hours after a data breach for the decision tree.

Do you need a Record of Processing Activities (ROPA)?

Your privacy policy tells visitors what you do with their data, a ROPA is the internal record proving it, and answering it fast if someone asks. The "under 250 employees" exemption has an exception that catches most freelancers anyway. See our ROPA basics guide for what a minimal one needs to contain.

Quick self-audit

  1. Open your current privacy policy (if you have one).
  2. For each type of data you collect, can you point to the sentence that states its specific legal basis?
  3. Does it name a retention period or retention criteria?
  4. Does it list your actual sub-processors (or at least categories), including any outside the EU?
  5. Is there a cookie banner with genuine opt-in, if you use non-essential cookies?

If you answered "no" or "not sure" to more than one of those, the policy likely needs a rewrite rather than a patch.

Related reading

A privacy policy is one piece of a wider compliance picture. Next to your actual forms, you also need short consent clauses, the notice people see before they tick a box, not the full policy itself. For the six legal bases, the DPO question, and a day-one checklist covering everything else, see our plain-language GDPR guide.

Want a first draft instantly instead of writing one from these rules? Try the free privacy policy generator, fill in your details, get a ready-to-use policy in English or Italian, right in your browser, no signup.

Don't want to draft all of this from scratch?

NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this situation: a ready-to-edit Privacy Policy, Cookie Policy, consent clauses, a full Art. 28 DPA, a mini Records-of-Processing (ROPA) template, and a breach-notification checklist, €29 one-time, instant download, editable .docx and .pdf.

See what's included →

Not legal advice. This guide is general information, not a substitute for advice from a qualified lawyer or data protection professional about your specific situation. NormaKit's templates are likewise informational starting points, not legal advice, and should be reviewed and adapted before use.