MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Having a privacy policy drafted by a specialized SME lawyer typically costs between 500 and 1,500 euros, depending on the size of your organization, the number of processing activities, and the sensitivity of the data. The privacy policy is the internal document that sets out how your company handles personal data, and this requires alignment with your own working methods. You can write it yourself or have it drafted; the choice depends on the number of staff and systems involved. Below are the costs, the process, and the point at which outsourcing pays off.
The short answer
- Self-writing: suitable for a small organization with straightforward processing.
- Legal counsel: 500 to 1,500 euros, depending on scope and sensitivity.
- Lead time: one to three weeks, including intake and coordination.
- Factors determining the price: personnel, special data, number of processors, and locations.
- Often together with: a processing register, processor agreements, and the data breach procedure.
How much does it cost to have a privacy policy drafted?
Unlike an external statement, a privacy policy concerns your entire organization. The price therefore depends primarily on the scope and complexity:
- Small organization with a few employees and standard data: 500 to 800 euros.
- Medium-sized organization with multiple systems and processors: 800 to 1,200 euros.
- Sensitive processing, such as medical or other special data, or multiple locations: 1,200 euros and higher, often within a broader process.
- Additional components, such as a processing register or a set of processor agreements, at an extra cost.
A policy is custom-made, because it must align with your roles, systems, and procedures. A standard template without alignment results in a document that looks good but is not followed in practice.
The process step by step
If you have the policy drafted by a lawyer, it usually proceeds as follows:
- Intake: you discuss your processing activities, systems, processors, and the roles within your organization.
- Inventory: the legal expert maps out what is missing, often in conjunction with the processing register under Article 30.
- Concept: you receive a policy with roles, retention periods, protection under Article 32, and a data breach procedure.
- Alignment: you check whether the procedures are workable and adjust where necessary.
- Implementation: you share the policy with employees and document that you have done so.
The better you prepare the intake, the faster it goes. An overview of your systems, processors, and retention periods saves questions afterwards.
Do it yourself or outsource
The decision revolves around scope and risk. If you work alone or with a small team and only process standard data, writing a policy yourself is perfectly feasible. The components are manageable and the risks are limited.
As soon as you have staff across multiple locations, work with sensitive data, use many processors, or store camera footage, coordination becomes more difficult. In such cases, the value of a legal expert lies in aligning security levels and procedures with the risks, and in aligning policies, registers, and data processing agreements. A failure in this coherence will stand out during an audit.
What you get and what you don't
A privacy policy governs the internal rules of the game. It is not the same as the external privacy statement, the processing register, or data processing agreements, although these often belong in the same process. Ask in advance what is and is not included, so that you are not left with a standalone policy while the register is still missing.
A brief example. An accounting firm from Nijmegen with eighteen employees has a privacy policy drafted because it works with financial client data and with multiple software vendors. The legal expert aligns the policy with the processing register, reviews the data processing agreements, and outlines a data breach procedure. The firm pays more than a small business, but in doing so, it has arranged the most important components in a coordinated manner.
Honest recommendation
If you are a small organization with straightforward processing operations and no special categories of data, you do not need a lawyer. A policy that you draft yourself, aligns with your processing register, and matches practice is sufficient and saves costs.
Have the policy drafted as soon as you have staff across multiple locations, work with sensitive data, or use many processors. In those situations, the additional cost is small compared to the risk of a policy that does not fit the data. Choose an SME lawyer who thoroughly reviews your working methods and aligns the policy with your register and processor agreements.
Want to know more or have it arranged immediately? View the privacy policy of MKB Juristen, but first read what a privacy policy is and how drafting a privacy policy .
Frequently Asked Questions
For a specialized SME lawyer, you can generally expect to pay between 500 and 1,500 euros. A small organization with standard data falls at the lower end, while an organization with multiple systems and processors falls at the higher end. For special data or multiple locations, the price exceeds 1,200 euros.
A template is a starting point, but a privacy policy must align with your roles, systems, and procedures. A generic document that does not match practice will not be followed and fails to fulfill accountability obligations. Always align the policy with your own working methods.
Usually one to three weeks, including intake and coordination. The turnaround time depends on how completely you provide the information regarding your systems, processors, and retention periods. Good preparation speeds up the process.
An overview of your processing activities, the systems you use, external processors, retention periods, and roles within your organization. The more complete this picture, the better the legal expert can align the policy with the risks associated with your organization.
Not automatically. A processing register under Article 30 is a separate component, although it is often part of the same process. Ask in advance what is included so that you are not left with a separate policy while the register still needs to be created.
Yes. A privacy statement is external and informs visitors and customers. A privacy policy is internal and describes how your organization operates. Drafting a policy requires more alignment with your own processes and is therefore typically more labor-intensive.
With personnel across multiple locations, sensitive data, many processors, or camera footage, the difficulty lies in aligning security and procedures with the risks. For a small organization with manageable processing operations, you can perfectly well draft the policy yourself.