GDPR Clauses – we provide templates

21 January 2026

The development of privacy notices and consent content is one of the fundamental obligations of data controllers, and at the same time, an area where errors most frequently occur in practice. Meanwhile, a poorly prepared privacy notice or incorrectly constructed consent may lead to a violation of GDPR provisions, intervention by the President of the Polish DPA, and consequently result in administrative liability.

In Polish practice, the term “GDPR clause” most commonly refers to the privacy notice, which is a mandatory communication provided to individuals whose data is being processed.

Depending on the method of data collection, this obligation is fulfilled based on Article 13 of the GDPR (data collected directly) or Article 14 of the GDPR (data collected from other sources). This term is also used in relation to consent clauses, which constitute one of the legal bases for the processing of personal data.

In this document:

  • we explain the differences between the clauses from Article 13 and Article 14 of the GDPR,
  • we indicate how to construct them correctly, in accordance with current guidelines and case law,
  • and we provide practical templates for GDPR clauses that can be adapted to specific data processing activities.

The text serves as a practical guide – without unnecessary theory, but with an emphasis on legal correctness, clarity of communication, and realistic expectations of the supervisory authority.

GDPR Privacy Notice

The GDPR privacy notice is a concise document that is intended to be easily understood – clear, written in plain and simple language. It is provided to the individual to whom the data relates:

  • when collecting data directly from that individual (Article 13 of the GDPR),
  • when obtaining data from sources other than that individual (Article 14 of the GDPR).

The scope of mandatory information that must be provided in the notice depends on how the data controller collects the data – whether directly from the individual to whom the data relates or from other sources. The GDPR privacy notice builds trust: it explains the principles and purposes of data processing, indicates recipients, and informs how long the data will be used.

Clause from Article 13 of the GDPR

The clause from Article 13 of the GDPR is a mandatory set of information that the data controller must provide to the individual from whom data is collected, directly at the time of collection. This information should be concise and accessible, so that the individual knows what will happen to their data and what rights they have.

The clause from Article 13 of the GDPR must include the following information:

  • the identity and contact details of the data controller (e.g., the name of the company, address, email, phone), and where applicable – also the identity and contact details of the data controller's representative (this applies only to controllers without an organizational unit in the European Union),
  • contact details of the Data Protection Officer (DPO) – if appointed (e.g., email address),
  • purposes and legal basis for processing (e.g., performance of a contract with the data subject – in accordance with Article 6(1)(b) of the GDPR),
  • legitimate interest – if processing is based on Article 6(1)(f) of the GDPR, i.e., legitimate interest (the data controller should specify their legitimate interest, e.g., pursuing claims and defending against claims),
  • data retention period or criteria for determining that period (e.g., data collected during recruitment will be retained for 3 months from the end of the recruitment process),
  • recipients or categories of recipients of the data (e.g., recruitment agencies and services, IT service providers, telecommunication systems, hosting services),
  • data transfer to third countries – where applicable (the information should allow to determine whether data will be transferred outside the European Economic Area, and if so, on what basis),
  • rights of data subjects – including the right to request access to data, rectification, erasure (right to be forgotten), restriction of processing, data portability, and objection,
  • right to withdraw consent at any time – if processing is based on consent (it should be indicated that the withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal),
  • right to lodge a complaint with a supervisory authority,
  • information on whether providing data is mandatory – whether it is a statutory or contractual requirement or a condition for entering into a contract, and whether the data subject is obliged to provide such data and what the potential consequences of not providing it are, 
  • information on automated decision-making, including profiling, which produces legal effects or similarly significantly affects the individual – if processing is carried out in an automated manner (in such cases, the logic and consequences of such processing should also be explained).

GDPR. Support is useful!

Clause from Article 13 of the GDPR – general template

This type of clause should be provided to the data subject at the time of data collection. Below we present a general template of the privacy notice from Article 13 of the GDPR:

In accordance with Article 13(1) and (2) of the Regulation of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016, on the protection of natural persons in relation to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: “GDPR”), we inform you that:

  1. The data controller of your personal data is … [name of the data controller] with its registered office at … [address].
  2. For matters related to personal data protection, you can contact our Data Protection Officer … [provide email address or other contact details] and at the address of the data controller's registered office.
  3. Your personal data will be processed for the purpose of … [state the purpose of processing] based on … [state the legal basis for processing, e.g., Article 6(1)(f) GDPR; when indicating the basis from Article 6(1)(f) GDPR, also specify the legitimate interest of the data controller or a third party].
  4. The recipients of your personal data will be: … [specify categories of recipients or specific entities].
  5. Your personal data will be stored for a period of … [if it is not possible to specify a specific period – provide the criteria for determining this period, e.g., until the recruitment process is completed].
  6. Within the limits set by the GDPR, you have the right to:
    1. access your personal data,
    2. rectify your personal data,
    3. erase your personal data,
    4. restrict the processing of your personal data,
    5. withdraw your consent to the processing of personal data at any time by … [if possible – specify how consent can be withdrawn, noting that the withdrawal of consent should be as easy as giving it] – if the processing of your data is based on it,
    6. transfer your personal data.
  1. Within the limits set by the GDPR, you also have the right to object to the processing of your personal data.
  2. If you believe that the processing of your personal data violates the provisions of the GDPR, you have the right to lodge a complaint with the supervisory authority, i.e., the President of the Polish Data Protection Authority.
  3. Providing personal data is …… [select appropriately: voluntary, a legal requirement, a condition resulting from a concluded contract, or a condition for concluding a contract]. In the event that you do not provide personal data …… [if the data subject is obliged to provide them – indicate any consequences of not providing the data].
  4. Your personal data will not be transferred outside the territory of the European Economic Area or to an international organization.

[or]

Your personal data will be transferred outside the territory of the European Economic Area or to an international organization [to choose from]:

  • on the basis of a decision by the European Commission determining an adequate level of protection …… [indicate the relevant decision].

[or]

  • despite the absence of a decision by the European Commission determining an adequate level of protection, provided that the data will be appropriately secured using …… [indicate the safeguards and information on how to obtain copies of the safeguards or where they are made available].
  1. Your personal data will not be processed in an automated manner, including profiling, leading to decisions that have legal effects or similarly significantly affect your situation.

[or]

Your data will be processed in an automated manner, including profiling. Automated decision-making will take place on the basis of …… [provide the principles of automated decision-making], and the consequence of such processing will be …… [indicate significant information about the principles of automated decision-making and the significance and anticipated consequences of such processing for the data subject].

Clause from Article 14 of the GDPR

If the data controller obtains personal data from sources other than the data subject, the privacy notice is formulated based on Article 14 of the GDPR. Unlike the situation described in Article 13 of the GDPR, the information obligation referred to in Article 14 of the GDPR can, for obvious reasons, be fulfilled later, i.e.:

  • within a reasonable time after obtaining the personal data – no later than within one month,
  • if the personal data are to be used for communication with the data subject – no later than at the first such communication,
  • if the personal data are to be disclosed to another recipient – no later than at their first disclosure.

Practical DPO Course
Practical DPO Course
will confirm your high competencies
Prepare to fulfill the role of Data Protection Officer. We invite you!
CHOOSE A DATE
The moment of fulfilling the information obligation is not the only difference between the clauses in Article 13 and Article 14 of the GDPR. They also differ in the catalog of mandatory elements. The clause in Article 14 of the GDPR does not need to include information on whether providing data is mandatory, but must additionally contain elements such as:

  • categories of relevant personal data, meaning information about what data concerning the data subject has been obtained (e.g., “The data we have obtained includes your first name, last name, position, work email address, work phone number”),
  • source of the personal data, and where applicable – also information on whether the data comes from publicly available sources (e.g., “We obtained your data from your employer, our contractor, who provided it to us for the purposes of the ongoing execution of the contract concluded with him”).

Key Principles for Creating Correct Privacy Notices

  1. Transparency and Plain Language – information must be concise, clear, understandable, and easily accessible, as well as formulated in clear and simple language,
  2. Complete Scope of Required Information from Article 13 or Article 14 of the GDPR – the clause must include all elements indicated in Article 13 or Article 14 of the GDPR, including, among others, the identity and contact details of the data controller, the purposes and legal bases for processing, recipients of the data, retention period, and information about rights.
  3. Layered Structure and Adaptation of Communication Channel – the guidelines of the Article 29 Working Party on transparency allow for a layered approach in fulfilling the information obligation. This means that the most important information (e.g., about the data controller, purposes of processing, and rights of the data subject) is provided in the first layer, while the full content is provided in subsequent layers, for example, upon clicking “more.” The form and channel of information delivery (paper document, email, website, mobile application) should be adapted to the situation so that the individual can realistically access them at the moment of data collection or before the processing begins.
  4. Relevance and consistency with the actual state – the privacy notice must reflect the actual processing operations. The data controller should clearly communicate the required information, rather than repeating general statements that do not correspond to the specific processing process.

Examples of decisions by the President of the Polish DPA regarding privacy notices

  • Decision ZSPR.421.3.2018 – one of the first and most frequently discussed decisions by the President of the Polish DPA, in which an administrative monetary penalty was imposed, among other things, for failing to fulfill the information obligation under Article 14 of the GDPR towards individuals whose data was obtained from public registers (e.g., CEIDG).
  • Decision DKE.523.18.2021 – in which the obligation to supplement the information obligation in full scope resulting from Article 14 of the GDPR was ordered.
  • Decision ZSPU.421.2.2018 – in which the necessity to identify and include in the privacy notice all recipients of personal data was emphasized, as well as the necessity to clearly specify the planned retention period (or the criteria for its determination) and to formulate the notice in simple, understandable language – in accordance with Article 12 of the GDPR.

DPO Function - it is well communicated

Consent clause

The term “GDPR clause” is often equated with the consent clause. According to Recital 42 of the GDPR, for consent to be informed, the data subject should at least know the identity of the data controller and the intended purposes of the processing of personal data. Therefore, these elements are best included directly in the content of the consent – as in the examples below.

Consent for future recruitment

I consent to the processing by …… [name and registered office of the data controller] of my personal data contained in my CV and recruitment documents for the purpose of using them in future recruitment processes conducted by …… [name of the data controller] for a period of …… [e.g., 12 months] from the date of giving consent. I am aware that I can withdraw this consent at any time, which does not affect the lawfulness of the processing carried out based on the consent before its withdrawal.

 Consent to use a private phone number

I consent to the processing of my contact data in the form of my private phone number …… [phone number] by my employer …… [name and registered office of the data controller] for the purpose of contacting me regarding business matters. I am aware that I can withdraw this consent at any time, which does not affect the lawfulness of the processing carried out based on the consent prior to its withdrawal.

In order for such consent to meet the requirements of the GDPR, it must be voluntary, meaning it is given in an unforced manner and without manipulation, in conditions of decision-making freedom. This means that the employee can refuse to give consent without any negative consequences.

Note! In an employment relationship, the voluntariness of consent can be problematic due to the employee's dependence on the employer and the imbalance of power. An employee usually does not have full freedom to refuse, as they may fear negative consequences. Consent to the employer's use of the employee's private phone number for contacting them regarding business matters can only serve as a basis for processing if such a method of contact is genuinely optional, and the lack of consent does not affect employment or working conditions in any way.

Key Principles of Giving Consent

  1. Voluntariness – consent is valid only if the data subject has a real choice and can refuse to give it or withdraw it without the threat of negative consequences.
  2. Specificity and clarity – consent must be linked to a clearly defined purpose and formulated in such a way that it leaves no doubt as to what the data subject has actually consented to.
  3. Awareness – before giving consent, the data subject must know at least the identity of the data controller and the specific purposes of data processing.
  4. Information about the right to withdraw consent (available before giving consent) – the data subject has the right to withdraw consent at any time, and the withdrawal of consent does not affect the lawfulness of processing carried out based on the consent prior to its withdrawal. This principle must be communicated to the individual before they give consent.
  5. Withdrawal of consent as easy as giving it – in practice, this means the necessity to create mechanisms that allow for a seamless and unconditional “opt-out” from those data processing activities to which consent was previously given.
  6. Archiving consent – the data controller must be able to demonstrate that consent has been effectively granted. The EDPB Guidelines 05/2020 indicate that the data controller may maintain a record of obtained consent statements for this purpose, so as to be able to demonstrate when and how consent was obtained and what information was provided to the data subject at the time of obtaining consent.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.