Fill in the Privacy Notice

All the information to include in the privacy notice

All the information below should be treated as suggestions. We advise you always to review your privacy rules with qualified professionals.

Having a GDPR-compliant privacy notice is compulsory for all professionals and others who collect and process their clients' data.

A correct privacy notice must necessarily contain the following sections

The data controller

The first information to enter in the privacy notice is the name of the data controller, the registered office and, where necessary, the legal representative of the business.

Type of data processed

You will therefore have to list all the data you collect from your customers, such as first name, last name, phone number, email, etc. If you have a website and/or run marketing campaigns, do not forget the data you collect online, such as IP address, Place of use, etc.

Purposes of data processing 

In this section you will have to list why you collect the data: to meet accounting and tax obligations, for scientific research or analysis of your business, for marketing. Remember that the customer will also have to sign consent for communications from your business, such as appointment reminders or any phone contact.

Communication and dissemination of data

You will have to list everyone the data collected will be disclosed to, for example your accountant, banks, BeebeeBoard. Remember that if you use IT services, for instance to send email, you must enter all that information in this section, paying particular attention to where the companies are based, as they may be outside the European Union.

Data protection officer RPD or DPO 

Consider whether your business needs to appoint an external RPD or DPO. Businesses with fewer than 250 employees are not required to appoint a DPO. However, if your business processes data considered sensitive, the Italian Garante della Privacy recommends the appointment anyway.

Avatar photo
Laura M.

Laura M. is the editorial content lead at BeebeeBoard. She writes about digital health, regulation for medical practices and healthcare technology. Her articles cover FSE 2.0, GDPR in healthcare and electronic invoicing, with the aim of making complex subjects usable for healthcare professionals.