
Use this template
A solid data protection policy protects your company, your employees and your customers. With Trupeer, you can save hours on policy writing by starting with a free data protection policy template, customizing it with your brand guidelines, and turning the policy into a video walkthrough that employees and partners can quickly understand.
Most organisations download a data protection policy, change the company name, and file it. It satisfies nobody: not the staff who never read it, not the auditor who asks how it is applied, and not the regulator if something goes wrong.
A useful data protection policy does one thing. It tells the people in your organisation what they must and must not do with personal data, specifically enough that they could follow it. This template is structured around the seven principles the policy has to satisfy, so every section exists for a reason you can explain.
Download the data protection policy template
Format | Best for |
|---|---|
Word (.docx) | Editing the policy. Free download, no sign-up |
The issued version, and staff acknowledgment | |
Google Docs | Review with your DPO, legal advisor or leadership |
Excel (.xlsx) | The supporting registers: retention schedule, processing record, breach log |
.doc | Older document systems |
Free, editable, no watermark. The Excel workbook matters more than it looks, because a policy without a retention schedule and a processing record behind it is a statement of intent rather than a working system.
Data protection policy or privacy policy?
The most common and most consequential confusion in this area. They are different documents with different audiences and different legal status.
Data protection policy | Privacy policy or privacy notice | |
|---|---|---|
Audience | Your own staff | The people whose data you hold |
Purpose | Tells employees how to handle personal data | Tells individuals what you do with their data and their rights |
Published? | Internal only, usually | Yes, publicly, and legally required |
Contains | Responsibilities, rules, procedures, consequences | What you collect, why, lawful basis, who you share with, retention, rights, contact |
Where it lives | Handbook, intranet | Website footer, at the point of collection |
Required by | Accountability principle, in practice | Directly required by GDPR Articles 13 and 14 |
If you need the public-facing document for your website, this template is not it, and publishing an internal policy in its place will not satisfy your obligations. You need a privacy notice, which describes your specific processing activities and is usually best produced with legal input or a reputable generator.
You almost certainly need both. This page covers the internal one.
How to customize this template in Trupeer
Step 1: Open the Templates Section
Go to the Templates section from the main navigation.

Step 2: Select and Open a Template
Click on any template you want to work with to open it.

Step 3: Expand the Template View
If needed, expand the template view to see the full layout and details clearly.

Step 4: Edit the Template
Click on Edit to start modifying the selected template.

Within the editor, you can:
Add new sections
Define or update formatting rules
Add a logo and adjust its position and related settings
Step 5: Save Your Customized Template
After making all necessary changes, click Save to store the updated template as your own.

Step 6: Preview and Fine-Tune the Template
When you want to see how your customized template looks, open the Preview.

From the preview screen, you can continue to make adjustments directly if needed, ensuring the template appears exactly as you want.
With a data protection policy template you can:
Save hours on writing: Skip the blank page with a structure built for privacy regulations.
Stay compliant: Aligned with GDPR, CCPA, HIPAA and other privacy laws.
Stay on-brand: Apply your logo, fonts and colors using Trupeer's brand kit.
Train every employee: Pair the policy with video walkthroughs for privacy awareness.
Stay audit-ready: Built-in sections support SOC 2, ISO 27001 and privacy audits.
Reach global teams: Translate the policy into 65+ languages with one click.
What a data protection policy is
An internal policy setting out how your organisation handles personal data: who is responsible, what staff may and may not do, how the legal principles apply in practice, and what happens when something goes wrong.
Its function is twofold. It tells your people how to behave, and it demonstrates accountability, which under GDPR is not optional. Being able to show you have considered and documented your approach is itself a compliance requirement, separate from whether your practices are good.
The seven principles, and what each requires
Article 5 of the GDPR sets out seven principles. Every section of a good data protection policy exists to satisfy one of them, and structuring the policy this way makes it defensible.
Lawfulness, fairness and transparency
Personal data must be processed lawfully, fairly, and in a way people would expect and understand.
What the policy must contain. A statement that all processing requires a lawful basis, the list of bases your organisation relies on and for what, a requirement that privacy notices are provided at the point of collection, and a rule that staff must not use personal data for purposes people were not told about.
Where it goes wrong. Collecting data for one purpose and quietly using it for another. Marketing to people who gave you their address for delivery is the classic example.
Purpose limitation
Data collected for one specified purpose must not be used for incompatible purposes.
What the policy must contain. A rule that new uses of existing data must be assessed before they happen, and named responsibility for that assessment. In practice this is the section that stops a well-meaning team building something with data they should not use.
Data minimisation
Collect what you need and no more.
What the policy must contain. A requirement that forms and systems are reviewed for unnecessary fields, and a rule against collecting data speculatively because it might be useful later. This principle is enforced at the design stage, so the policy should require it to be considered when new processes or systems are introduced.
Accuracy
Personal data must be accurate and kept up to date where necessary.
What the policy must contain. How individuals can correct their data, how corrections propagate to other systems, and how often key records are reviewed. The propagation point matters, because most organisations update the record someone complained about and leave three copies elsewhere.
Storage limitation
Do not keep personal data longer than you need it.
What the policy must contain. A reference to your retention schedule, which should be a separate document because it changes more often than the policy. Plus a rule on secure deletion, and a requirement that backups and archives are covered rather than quietly exempt.
This is the principle organisations most often fail, because keeping everything is easier than deciding what to delete.
Integrity and confidentiality
Personal data must be kept secure, against both unauthorised access and accidental loss.
What the policy must contain. Access on a need-to-know basis, rules on devices and removable media, encryption requirements, home and remote working rules, what may and may not be emailed, and how data is shared with third parties. Plus the requirement that suppliers processing data on your behalf are under a written contract.
Accountability
You must be able to demonstrate compliance, not merely achieve it.
What the policy must contain. Named roles and responsibilities, the requirement to maintain records of processing, when a data protection impact assessment is needed, training requirements, and the review cycle for the policy itself.
Accountability is why the supporting registers matter. A policy with no processing record, no retention schedule and no training log demonstrates very little.
The policy template structure
Section | Contents |
|---|---|
Document control | Version, owner, approver, dates, review date |
Purpose and scope | Who and what it applies to, including contractors and volunteers |
Definitions | Personal data, special category data, processing, controller, processor, data subject |
Roles and responsibilities | Leadership, DPO or lead, managers, all staff, IT |
The principles | How each applies in your organisation |
Lawful bases | Which you rely on, for what |
Special category data | Additional conditions and extra care |
Data subject rights | The rights, and how requests are handled |
Retention | Reference to the retention schedule |
Security | Access, devices, encryption, remote working, email |
Third parties and sharing | Contracts, due diligence, international transfers |
Data protection by design | When DPIAs are required |
Breach response | Recognising, reporting internally, timescales, notification |
Training | Who, how often, and records |
Non-compliance | Consequences, linked to the disciplinary procedure |
Related documents | Privacy notices, retention schedule, ROPA, breach log |
Review | Cycle and owner |
Lawful bases for processing
Every processing activity needs one. There are six under GDPR, and staff should know which ones your organisation relies on.
Basis | Use it when | Common example |
|---|---|---|
Consent | The person has genuinely chosen, and can withdraw | Marketing emails |
Contract | Processing is necessary to deliver what they asked for | Fulfilling an order |
Legal obligation | A law requires it | Retaining payroll records |
Vital interests | Life or death | Emergency medical situations |
Public task | Official functions or public interest | Public authorities |
Legitimate interests | Your interest, balanced against their rights | Fraud prevention, some analytics |
Two practical points worth putting in the policy. Consent is often the weakest choice, because it can be withdrawn and must be freely given, so it is a poor basis for anything you need to do regardless. And legitimate interests requires a documented balancing assessment, not simply an assertion that your interest exists.
Data subject rights
Eight rights under GDPR, and your policy should say how each is handled and by whom.
The right to be informed. The right of access, commonly called a subject access request. The right to rectification. The right to erasure. The right to restrict processing. The right to data portability. The right to object. And rights relating to automated decision-making and profiling.
The practical part is the procedure. Requests can arrive by any channel, to any member of staff, in any wording, and the person does not have to use the correct legal terminology or even mention data protection. So the policy must tell every employee to recognise and forward a request immediately rather than trying to handle it.
The response deadline is one month, extendable by a further two months for complex or numerous requests, provided you tell the person within the first month. That clock starts when the request arrives anywhere in your organisation, not when it reaches the right person, which is why the recognition rule matters so much.
Breach response
The section most likely to be tested and least likely to be read in advance.
Recognising a breach. Personal data breaches are not only hacks. A misdirected email, a lost laptop, a document left on a train, an incorrectly configured share, or the wrong person given access all qualify.
Internal reporting. Immediately, to a named role, with no gatekeeping. The policy should say explicitly that reporting a breach you caused yourself will not be punished, because a culture of concealment is the most expensive thing a breach policy can create.
Assessment and notification. Where a breach is likely to result in a risk to people's rights and freedoms, it must be reported to the supervisory authority within 72 hours of becoming aware. Where the risk is high, affected individuals must also be told without undue delay. Both assessments should be made by a named role, not by whoever discovered it.
The breach log. Every breach recorded, including ones you decide not to report and the reasoning for that decision. Maintaining that record is itself an obligation.
Records of processing and retention
Records of processing activities. A record of what personal data you hold, why, who it is shared with, how long you keep it, and how it is secured. Article 30 requires this, with a narrow exemption for organisations under 250 employees that does not apply if processing is more than occasional, involves special category data, or poses a risk to individuals. Most organisations that think they are exempt are not.
Retention schedule. A separate document listing data types, retention periods and the justification for each. Keep it separate from the policy because it changes far more often, and reference it rather than embedding it.
Both live in the Excel workbook that comes with this template, with the breach log alongside them.
The wider document set
A data protection policy rarely stands alone. Most organisations need several of these:
Document | Purpose | Who sees it |
|---|---|---|
Data protection policy | How staff handle personal data | Internal |
Privacy notice | What you do with people's data and their rights | Public |
Cookie policy and banner | Website tracking and consent | Public |
Employee privacy notice | What you do with staff data specifically | Employees |
Records of processing | Inventory of processing activities | Internal, regulator on request |
Retention schedule | How long each data type is kept | Internal |
DSAR procedure | How access requests are handled | Internal |
Breach log and procedure | Recording and responding to incidents | Internal |
DPIA template | Assessing high-risk processing | Internal |
Processor agreements | Contracts with suppliers handling your data | Contractual |
If you only have one of these, the privacy notice is the one legally required to be published. If you only have two, add this policy.
The small business version
Smaller organisations need a shorter policy, not a lighter approach. The obligations do not scale down, but the documentation should be proportionate.
Keep: scope, responsibilities, the principles in plain terms, security rules, data subject request recognition, breach reporting, and retention. Cut: elaborate governance structures, committee references, and anything describing roles you do not have. Name a real person as responsible rather than inventing a data protection function.
Four to six pages is usually enough. A twenty-page policy in a ten-person company will not be read, which makes it worse than a shorter one that is.
Training staff on it
A policy nobody has read demonstrates nothing.
Train at induction and annually, keep records of who was trained and when, and focus on the four things that actually cause breaches: recognising a data subject request, not emailing data to the wrong person, not putting personal data somewhere unapproved, and reporting an incident immediately.
Scenario-based training works better than reciting principles. Most breaches come from ordinary mistakes rather than ignorance of the law.
How to write your data protection policy
Find out what data you actually hold before writing anything. The processing record comes first in practice, even though it is referenced later in the policy.
Identify your lawful basis for each activity, and document the balancing assessment where you rely on legitimate interests.
Use the template structure and write in plain language, since the audience is your staff rather than a regulator.
Make the rules specific. "Handle data securely" is unenforceable. "Do not store personal data on personal devices or unapproved cloud accounts" is.
Build the retention schedule separately and reference it.
Write the breach procedure before you need it, with a named role and a no-blame reporting rule.
Have it reviewed by a data protection specialist or legal advisor, particularly if you process special category data, operate across jurisdictions, or make automated decisions.
Approve, issue with notice, and collect acknowledgment.
Train, and record the training.
Set a review date, annually and after any material change.
Reviewing the policy
Annually as a default. Immediately when you introduce a new system or processing activity, when you start operating in a new jurisdiction, after any breach, when data protection law changes, or when the responsible person leaves.
Record each review in the version history, including reviews that resulted in no change, since demonstrating that you reviewed it is part of the point.
Legal notice
This template and the guidance on this page are provided for general information and are not legal advice. Data protection law varies by jurisdiction, and requirements differ under the EU GDPR, UK GDPR, and regimes such as the CCPA and CPRA in the United States. Obligations also vary considerably depending on what data you process, at what scale, and in which sectors.
Have your policy reviewed by a qualified data protection advisor or legal counsel before adopting it, particularly if you process special category data, children's data, or operate internationally.
Best practices
Keep the internal policy and the public privacy notice as separate documents.
Write rules staff can actually follow, in specific terms.
Keep the retention schedule out of the policy so it can be updated independently.
Name real people, not aspirational roles.
State explicitly that self-reported breaches will not be punished.
Train on recognition of data subject requests, since the clock starts on arrival.
Log every breach, including unreported ones and the reasoning.
Maintain the processing record. It is an obligation and it makes everything else easier.
Keep the policy proportionate to the organisation.
Record reviews, including no-change reviews.
Common mistakes
Publishing the internal policy as if it were a privacy notice.
A generic downloaded policy with the company name changed and nothing else.
Rules too vague to follow or enforce.
Retention periods embedded in the policy, so updating them requires reapproving it.
Assuming the under-250-employee exemption from processing records applies when it does not.
Relying on consent where another lawful basis would be more robust.
Legitimate interests claimed without a documented balancing assessment.
No breach procedure, so the 72-hour clock is discovered during an incident.
Blame culture around breaches, which produces concealment.
Staff not trained to recognise a data subject request in ordinary language.
Backups and archives quietly excluded from retention and deletion rules.
Never reviewed, so it describes systems you no longer use.
Make the rules something people can follow
Open the template in Trupeer AI, apply your brand kit so it matches your handbook and other policies, and edit any section directly. Setup is in the template guide.
The gap between a data protection policy and actual compliance is almost always behavioural. Staff know they should handle data carefully and do not know what that means when they are about to share a spreadsheet, respond to an unusual email, or set up a new tool.
Record the procedures once and Trupeer AI produces the written guide and a narrated video walkthrough from the same pass, so the rules for sharing files, redacting a subject access response, or reporting an incident are things people can watch rather than clauses they skimmed. Translate it into 65+ languages, which matters where staff are being asked to follow rules with legal consequences. Keep the set in your knowledge base and use it for induction and annual training, with a completion record you can show.
Record it. Brand it. Translate it. Trupeer it.
Frequently Asked Questions
Is there a free data protection policy template in Word?
Yes. Word is the main format, with every section drafted and bracketed placeholders for the details that must be yours. Free download, no sign-up, no watermark.
Is there a free data protection policy template in PDF?
Yes, as the issued version with an acknowledgment block for staff signature, which is what you need if you intend to rely on the policy in a disciplinary context.
Is there a data protection policy template in Word for employees?
Yes. The template includes an employee-facing summary, a two-page version covering what staff must and must not do without the governance detail. That is the version most people should actually read, with the full policy available behind it.
Where can I get a data protection policy PDF?
Here, as both the blank template and a completed sample so you can see a finished policy end to end before writing your own.
What is the difference between a data protection policy and a privacy policy?
A data protection policy is internal and tells your staff how to handle personal data. A privacy policy or privacy notice is public and tells individuals what you do with their data and what rights they have. The second is directly required by GDPR and must be published. Publishing the internal policy in its place will not satisfy that obligation.
Is there a free website privacy policy template?
Not on this page, and it is worth explaining why rather than offering a generic one. A privacy notice has to describe your actual processing: what you collect, on what lawful basis, who you share it with, how long you keep it, and where it is transferred. A template that does not match your real practices is worse than none, because it is a published statement that is inaccurate. Use a reputable privacy policy generator or a lawyer, and base it on your records of processing.
Is there a sample privacy policy in PDF?
Sample privacy notices are widely available from regulators and privacy tooling providers, and those are better starting points than a generic template, because they are written against current requirements. What this page provides is the internal policy and the processing record that any accurate privacy notice has to be built from.
Is there a privacy policy generator?
Several exist and they are a reasonable option for a straightforward website, particularly for cookie and analytics disclosures. What they cannot do is know your processing activities, so review the output against your actual practices rather than publishing it unread. Generators produce a document. Accuracy is still your responsibility.
What is a data protection policy?
An internal policy setting out how your organisation handles personal data: who is responsible, what staff may and may not do, how the legal principles apply in practice, and what happens when something goes wrong. It also demonstrates accountability, which is a requirement in its own right.
What should a data protection policy include?
Document control, scope, definitions, roles and responsibilities, how each of the seven principles applies, lawful bases, special category data, data subject rights and how requests are handled, retention, security rules, third party sharing, when DPIAs are required, breach response, training requirements, consequences of non-compliance, related documents and a review cycle.
What are the 7 principles of GDPR?
Lawfulness, fairness and transparency. Purpose limitation. Data minimisation. Accuracy. Storage limitation. Integrity and confidentiality. Accountability. Article 5 sets out the first six as principles relating to processing, with accountability requiring you to demonstrate compliance with them.
What are the lawful bases for processing personal data?
Consent, contract, legal obligation, vital interests, public task and legitimate interests. Every processing activity needs one. Consent is often the weakest choice because it can be withdrawn, and legitimate interests requires a documented balancing assessment rather than an assertion.
How long do you have to respond to a subject access request?
One month, extendable by a further two months for complex or numerous requests provided you notify the individual within the first month. The clock starts when the request reaches anyone in your organisation, in any wording, which is why training staff to recognise and forward requests matters more than the procedure itself.
How quickly must a data breach be reported?
Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, it must be reported to the supervisory authority within 72 hours of becoming aware of it. Where there is a high risk to individuals, they must also be informed without undue delay. Breaches you assess as not requiring notification should still be logged, with the reasoning.
Do small businesses need a data protection policy?
Yes, if you process personal data, which nearly every business does. The obligations do not scale down with headcount, though the documentation should be proportionate. Four to six pages naming a real responsible person is more useful than twenty pages describing governance structures you do not have.
Do I need a Data Protection Officer?
A DPO is mandatory in specific circumstances, including public authorities and organisations whose core activities involve large-scale regular and systematic monitoring or large-scale processing of special category data. Many organisations fall outside those criteria and still benefit from naming someone responsible. Check your position with a specialist, since the thresholds involve judgement.
How often should a data protection policy be reviewed?
Annually as a default, and immediately after any breach, new system or processing activity, change in the law, expansion into a new jurisdiction, or departure of the responsible person. Record every review including those that result in no changes.
Can I customise this data protection policy template?
Yes, every version is fully editable, and you should. Generic policies fail precisely because they describe nobody's actual practices. Replace the placeholders, cut sections that do not apply, and have the result reviewed by a qualified advisor before adopting it.
