All the information to include in the privacy notice
All the information below should be treated as suggestions. We advise you always to review your privacy rules with qualified professionals.
Having a GDPR-compliant privacy notice is compulsory for all professionals and others who collect and process their clients' data.
A correct privacy notice must necessarily contain the following sections
The data controller
The first information to enter in the privacy notice is the name of the data controller, the registered office and, where necessary, the legal representative of the business.
Type of data processed
You will therefore have to list all the data you collect from your customers, such as first name, last name, phone number, email, etc. If you have a website and/or run marketing campaigns, do not forget the data you collect online, such as IP address, Place of use, etc.
Purposes of data processing
In this section you will have to list why you collect the data: to meet accounting and tax obligations, for scientific research or analysis of your business, for marketing. Remember that the customer will also have to sign consent for communications from your business, such as appointment reminders or any phone contact.
Communication and dissemination of data
You will have to list everyone the data collected will be disclosed to, for example your accountant, banks, BeebeeBoard. Remember that if you use IT services, for instance to send email, you must enter all that information in this section, paying particular attention to where the companies are based, as they may be outside the European Union.
Data protection officer RPD or DPO
Consider whether your business needs to appoint an external RPD or DPO. Businesses with fewer than 250 employees are not required to appoint a DPO. However, if your business processes data considered sensitive, the Italian Garante della Privacy recommends the appointment anyway.




