Blog

Protect yourself and your consumers with a privacy statement!

Privacy statement for websites and apps: GDPR requirements, content, and how to draft it. Against fines from the Dutch Data Protection Authority.

Published on July 7, 2026 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

A privacy statement is mandatory for every website or service that processes personal data under the GDPR. Content: who processes which data, for what purposes, how long it is stored, with whom it is shared, and what the rights of data subjects are. In case of non-compliance: a fine by the Dutch Data Protection Authority of up to 4% of global turnover (or €20 million). Almost always mandatory for SMEs — even a simple contact form requires a privacy statement. Below are the legal requirements, template structure, and pitfalls.

The short answer

  • What: Mandatory declaration for websites/services that process personal data.
  • Legal basis: Art. 13-14 GDPR.
  • Mandatory content: identity of processor, purposes, legal basis, retention periods, rights of data subject.
  • Location: easily found on website (footer link).
  • Sanctions: AP fine of up to 4% of global turnover or €20 million.

What should it contain?

Privacy statement on website
  1. Identity of data controller: BV name, address, contact.
  2. Purposes of processing: e.g. customer service, marketing, account management.
  3. Legal basis: consent, contract, legitimate interest, statutory obligation.
  4. Categories of personal data: name, address, and place of residence, email, payment details, etc.
  5. Recipients: with whom data is shared (processors, partners).
  6. Retention periods: how long per category of data.
  7. Rights of data subjects: access, rectification, deletion, objection, data portability.
  8. DPA complaint procedure: link to the Dutch Data Protection Authority.
  9. Data Protection Officer (DPO): contact if available.
  10. Automated decision-making and profiling: if applicable.
  11. Transfer outside the EU: if applicable, with safeguards.

Placement and findability

Privacy statement checklist

The privacy statement must be “easy to find”:

  • Link in website footer (general section).
  • Link in forms where data is entered.
  • Link in account settings.
  • Text in readable Dutch (no legal jargon).

Plus cookie notification on homepage for cookies and tracking.

Cookies and privacy statement

Cookies require separate consent (cookie notification) plus mention in the privacy statement. Distinction:

  • Functional cookies: necessary for operation — no consent required.
  • Analytical cookies: consent required (anonymous, privacy-friendly, often exempt).
  • Marketing/tracking cookies: explicit opt-in required.

Cookiebot, Onetrust, and CookieFirst are standard cookie tools for compliance.

Legal foundations

Under the GDPR, you can process personal data on six legal grounds:

  1. Consent: explicit, freely given, revocable.
  2. Contract: required for execution of customer agreement.
  3. Statutory obligation: e.g. accounting obligation.
  4. Legitimate interest: after balancing of interests — often used for marketing.
  5. Vital interest: life or safety — rarely applicable.
  6. Public interest: for government tasks.

Specify the legal basis for each processing operation.

Common pitfalls

  • Too general: “for various purposes” — not specific enough.
  • No retention periods: the AP wants concrete periods per category.
  • Forgot cookies: separate cookie statement or full statement.
  • Outdated: not updated after changes to services or partners.
  • English template: translation not adapted to Dutch practice.
  • No data processing agreements:hoster, marketing tool, payment provider — all “processors” that require a contract.

In the event of a data breach

The privacy statement must explain what the customer can expect in the event of a data breach — notification obligation (72 hours to the Dutch Data Protection Authority), and potential communication to data subjects. See data breach.

Honest recommendation

GDPR lawyer reviews privacy statement

For SMEs with a website or customer data: privacy statement mandatory — not optional. Start with a template (Chamber of Commerce, NLdigital), adapt to the specific situation. For more complex situations (e-commerce, app, international presence): draft or review GDPR legal expert (€500-€2,500). Update with every change in services. Combine with a cookie tool and data processing agreements for a complete compliance package.

For other topics: data breach, UBO declaration and cyber insurance.

Frequently Asked Questions

What is a privacy statement?

Mandatory statement (Art. 13-14 GDPR) for websites and services that process personal data. Contains information about which data, for what purposes, for how long, and what the rights of data subjects are.

Do I always need one?

Almost always for SME limited companies. Even a simple contact form processes personal data (email) — privacy statement mandatory. Exceptions are very limited (purely B2B business without customer contact).

What should it contain?

Identity of processor, purposes, legal basis, categories of data, recipients, retention periods, rights of the data subject, right to lodge a complaint with the Dutch Data Protection Authority (AP), and possibly the Data Protection Officer (DPO), automated decision-making, transfer outside the EU.

What are the sanctions?

The Dutch Data Protection Authority can impose fines of up to 4% of global turnover or €20 million (whichever is higher). In practice, for SMEs, this is often €10,000–€250,000 for serious violations.

Cookies in privacy statement?

Cookies require separate consent (cookie notification) plus mention in the privacy statement. Functional: no consent. Analytical: often yes. Marketing/tracking: explicit opt-in required.

What are legal foundations?

Six under the GDPR: consent, contract, statutory obligation, legitimate interest, vital interest, public interest. Specify the legal basis for each processing activity — not generically “all applicable”.

When to update?

With every change in processing: new partner, new service, different retention period, new processor location (within/outside the EU). Plus an annual review for up-to-date status.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 24, 2026

Having a non-compete clause drafted: costs and process

Having a non-compete clause drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom draft over a template.

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

July 24, 2026

Having general terms and conditions drafted for contractors: costs and process

Having general terms and conditions for contractors drafted by a lawyer: what does it cost, how does the process work, and when do you choose custom work over...

July 23, 2026

Having general terms and conditions drafted: costs and process

Having general terms and conditions drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom-made version over a template.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation