Web Design Kerry, Cork and all over Ireland.

Privacy policy for websites: the Irish small business guide

A privacy policy for websites is a mandatory legal document under GDPR and Irish data protection law that tells visitors how you collect, use, store, and share their personal data. Every Irish website that processes personal data must publish one. The Data Protection Commission (DPC) enforces compliance, and the consequences of getting it wrong range from formal warnings to fines reaching into the millions. Getting this right from the start is far cheaper than fixing it after a complaint.

What are the mandatory elements of a GDPR-compliant privacy policy?

GDPR Article 13 mandates 12 specific elements that every website privacy policy must include when data is collected directly from users. Missing even one of these creates a compliance gap that the DPC can act on.

The 12 required elements are:

  • Controller identity and contact details: Your full business name, address, and email address.
  • Data Protection Officer (DPO) contact: Required if you are a public body or process data at scale; include name and email if applicable.
  • Purposes and legal basis for processing: Every purpose must have a named legal basis under Article 6 GDPR (consent, contract, legal obligation, vital interests, public task, or legitimate interests).
  • Categories of personal data collected: Be specific. “Contact information” is too vague; list name, email address, IP address, and so on.
  • Recipients and third-party processors: Name the companies that receive data, such as Google Analytics, Mailchimp, or your hosting provider.
  • International data transfers: Disclose any transfers outside the EEA and the safeguards in place, such as Standard Contractual Clauses.
  • Retention periods: State how long you keep each category of data and why.
  • Data subject rights: Cover the rights to access, rectification, erasure, portability, restriction, and objection.
  • Right to withdraw consent: Explain how users can withdraw consent at any time.
  • Right to complain to the DPC: Include the DPC’s name, website (dataprotection.ie), and contact details.
  • Whether data provision is obligatory or voluntary: Tell users what happens if they do not provide their data.
  • Automated decision-making and profiling: Disclose any automated decisions that produce legal or similarly significant effects.
Element GDPR Article Common mistake
Legal basis for processing Art. 6 Listing “legitimate interests” without specifics
Retention periods Art. 13(2)(a) Omitting entirely
Third-party processors Art. 13(1)(e) Naming only categories, not companies
DPC complaint right Art. 13(2)(d) Missing DPC contact details
Automated decision-making Art. 13(2)(f) Skipped when profiling is in use

Significant fines have been issued for incomplete policies, including multimillion-euro penalties for transparency failures. The DPC issued a €1.2 billion fine against Meta for exactly this type of breach. Small businesses typically receive a warning first, but repeat violations attract heavier penalties.

How do you write a clear and accessible privacy notice?

GDPR Article 12 requires that privacy notices be written in plain language that an ordinary person can understand. The DPC’s own guidance reinforces this: layered privacy notices with a concise summary at the top and detailed sections below are the preferred approach. This structure lets a casual visitor understand the basics quickly, while a more curious reader can dig into the full detail.

Person typing privacy notice at modern coworking desk

Plain language means avoiding legal and technical jargon wherever possible. Instead of writing “the data controller processes personal data pursuant to Article 6(1)(f) GDPR,” write “we use your data to prevent fraud, which is a legitimate interest we have identified.” Concrete language builds trust and reduces complaints.

Practical steps for writing a clear digital privacy statement:

  • Use short sentences and everyday vocabulary.
  • Define technical terms the first time you use them. For example, explain that “data controller” means the business responsible for deciding how your data is used.
  • Include specific retention schedules. “We keep your enquiry form data for two years” is compliant. “We keep data for as long as necessary” is not.
  • Name your third-party processors explicitly. Vague references to “analytics providers” do not meet the transparency standard.
  • Use tables or bullet lists for rights and retention periods so readers can scan them quickly.
  • Proactively communicate material changes. Transparency requires active notification of updates, not just posting a new version online.

Pro Tip: Run your draft privacy policy through a free readability tool such as the Hemingway Editor. Aim for a reading level of Grade 8 or below. If the tool flags long, complex sentences, rewrite them before publishing.

What are the specific Irish requirements beyond GDPR?

Irish law adds obligations that sit on top of the GDPR baseline. The Companies Act 2014 and the Consumer Rights Act 2022 require Irish businesses to display their company registration number (CRO number), VAT number, and registered office address on their website. These details belong in the footer, not buried in the privacy policy itself.

Infographic outlining GDPR privacy policy key steps

A compliant Irish website footer contains four distinct sections: company information, legal notices, consumer information, and contact links. The privacy policy is one of the legal notices, but it sits alongside a separate cookie policy and terms of use. Merging these documents into one page does not meet transparency standards.

Key Irish-specific obligations at a glance:

  • Footer placement: Privacy notices must be linked from the footer on every page of the site, not just the homepage.
  • DPC contact details: Include the Data Protection Commission by name, with its website URL (dataprotection.ie) and postal address.
  • Cookie consent: Under the ePrivacy Regulations 2011, non-essential cookie consent must be opt-in and genuine. Pre-ticked boxes and loading tracking scripts before consent is given are direct violations.
  • Data Processing Agreements (DPAs): Article 28 GDPR requires written DPAs with every processor, including Google Analytics, Mailchimp, and your hosting provider. These are separate from your privacy policy.
  • Separate legal documents: Your privacy policy, cookie policy, and terms of use must each be distinct, named documents linked individually in the footer.

For businesses building or rebuilding a site, integrating these requirements from the outset is far simpler than retrofitting them later. Egg Design’s approach to EU law compliance covers both accessibility and data protection obligations as part of every website build.

What are the most common privacy policy mistakes to avoid?

The single most damaging mistake Irish website owners make is downloading a US-style privacy policy template and publishing it unchanged. US-style templates routinely omit mandatory GDPR details such as retention periods, specific legal bases, and data subject rights. They also lack any reference to the DPC, making them non-compliant from the moment they go live.

Other frequent failures include:

  • Vague legal bases: Listing “legitimate interests” without specifying what those interests are. Detailed legitimate interests such as fraud prevention or customer service improvement are required following CJEU rulings.
  • Missing retention periods: Stating that data is kept “as long as necessary” without specifying a timeframe.
  • Unnamed processors: Referring to “third-party analytics tools” instead of naming Google Analytics, Hotjar, or whichever platform you actually use.
  • No consent withdrawal mechanism: Failing to explain clearly how a user can withdraw consent, particularly for marketing emails or cookies.
  • Outdated policies: Installing a new plugin or switching email providers without updating the privacy policy to reflect the change.
  • Cookie consent failures: Loading tracking scripts before consent is a direct violation of the ePrivacy Regulations 2011 and GDPR.

Pro Tip: Check the DPC’s published investigation decisions at dataprotection.ie at least once a year. The DPC publishes the specific failures it found in each case. Reading three or four decisions gives you a practical checklist of what inspectors actually look for.

How do you maintain and update your privacy policy over time?

A privacy policy is a living document, not a one-off task. Failure to update policies when new tools or processors are added creates transparency gaps that the DPC treats as active violations. Treating your privacy policy as a static page is one of the most common reasons small businesses receive enforcement notices.

A practical maintenance schedule for small businesses:

  1. Quarterly review: Check whether any new plugins, tools, or third-party services have been added to the site since the last review. Update the policy to name each new processor and its legal basis.
  2. Annual full audit: Review every section of the policy against the current DPC guidance. Confirm that retention periods still reflect actual practice and that all data subject rights are accurately described.
  3. Prompt updates for material changes: When you add a new processor or change a processing purpose, update the policy immediately and notify users proactively by email or on-site notification.
  4. Version history: Keep a dated record of every version of the policy. This demonstrates accountability to the DPC if a complaint arises.
  5. DSAR readiness: The DPC expects responses to Data Subject Access Requests within one calendar month, with a possible two-month extension for complex cases. Prepare internal templates and assign a named person to handle requests.
  6. DPA currency: Review your Data Processing Agreements with all third parties annually. Processors update their own terms, and your DPA must reflect the current version.

Integrating privacy reviews into regular business operations is the most reliable way to stay compliant without it becoming a burden. Pair your privacy review with your annual accounts or your website performance audit so it never gets skipped.

Pro Tip: Create a simple spreadsheet listing every third-party tool on your site, its purpose, its legal basis, the data it receives, and the date your DPA was last reviewed. Update it every time you add or remove a tool. This record alone will satisfy most DPC enquiries about your processing activities.

For businesses that want to understand how privacy compliance fits into the broader picture of building a trustworthy online presence, this guide to European data privacy covers the specific elements required by European supervisory authorities.

Egg Design builds privacy compliance into every website

Building a compliant website from the ground up is the most cost-effective approach for Irish small businesses. Retrofitting legal notices, cookie consent mechanisms, and properly structured footers into an existing site takes significantly more time than getting it right at the start.

https://eggdesign.ie

Egg Design specialises in WordPress development for Irish businesses, with GDPR compliance and accessibility built into every project. That means your privacy policy, cookie consent tool, legal footer, and data subject rights process are all in place before your site goes live. As an approved vendor in Ireland’s Digital That Delivers programme, Egg Design brings over 17 years of experience to websites that need to perform legally as well as commercially. If your current site is missing compliant legal notices or your privacy policy has not been reviewed recently, get in touch with the Egg Design team to discuss a compliance-focused audit and rebuild.

FAQ

What must a privacy policy for websites include under GDPR?

GDPR Article 13 requires 12 elements, including controller identity, legal bases for processing, retention periods, third-party processors, data subject rights, and the right to complain to the DPC. Missing any element makes the policy non-compliant.

Does every Irish website need a privacy policy?

Any Irish website that collects personal data, including contact forms, analytics cookies, or email sign-ups, must publish a privacy policy. This applies regardless of business size.

How often should I update my website privacy policy?

Review your policy at least annually and update it immediately whenever you add a new processor, plugin, or data collection method. Failure to update promptly creates transparency gaps that the DPC treats as active violations.

Where should the privacy policy be placed on my website?

Privacy policies must be linked from the footer on every page of the site as a separate, named document. Burying it inside your terms of use does not meet the GDPR transparency standard.

What happens if my privacy policy is non-compliant in Ireland?

The DPC typically issues a formal warning for a first offence, but repeat or aggravated violations can result in significant fines. The DPC issued a €1.2 billion fine against Meta for transparency failures, demonstrating that the regulator takes incomplete disclosures seriously at every scale.

Are you ready to grow your business online?

Book a free 30-minute consultation to discuss your web design needs, boosting online sales, or getting top-notch support and maintenance.

BOOK A FREE CONSULTATION