Privacy & Data Protection
Comprehensive privacy policies, data protection agreements, and compliance documentation for GDPR, CCPA/CPRA, and global privacy regulations.
Privacy Policies
External Privacy Policy
Annual Update RequiredCustomer-facing privacy policy covering data collection, use, sharing, and individual rights. CCPA requires annual review and update.
Internal Data Privacy Policy
Annual ReviewEmployee-facing policy defining how personal data is handled internally, including HR data, customer data access, and privacy responsibilities.
Cookie Policy & Consent
Annual ReviewDetailed cookie policy with consent management framework. Includes cookie categories, purposes, retention periods, and opt-out mechanisms.
Data Subject Rights
DSAR Response Procedures
CriticalComplete procedures for handling Data Subject Access Requests including intake, verification, data gathering, response templates, and timeline tracking (30/45 days).
Right to Deletion Procedures
Annual ReviewSpecific procedures for handling deletion requests, including scope determination, backup handling, vendor notification, and exception documentation.
Data Portability Procedures
As NeededProcedures for providing personal data in machine-readable format, including export specifications, transfer mechanisms, and format standards.
Data Processing Agreements
Data Processing Agreement (DPA)
Required by LawGDPR Article 28 compliant DPA for use with vendors processing personal data. Includes standard contractual clauses, sub-processor requirements, and audit rights.
Standard Contractual Clauses (SCCs)
Required for TransfersEU Commission approved SCCs for international data transfers (2021 version). Includes all four modules with implementation guidance and TIA template.
Transfer Impact Assessment (TIA)
Per TransferAssessment template for evaluating international data transfers post-Schrems II. Documents legal basis, supplementary measures, and third-country law analysis.
Records & Documentation
Records of Processing Activities (ROPA)
Required by GDPRArticle 30 compliant register documenting all processing activities including purposes, categories, recipients, transfers, retention, and security measures.
Data Protection Impact Assessment (DPIA)
Required for High RiskComprehensive template for assessing privacy risks of new processing activities. Includes necessity/proportionality assessment, risk evaluation, and mitigation measures.
Data Retention Schedule
Annual ReviewComprehensive data retention schedule defining retention periods by data type, legal basis, and destruction procedures. Includes regulatory requirement mappings.
All 12 privacy & data protection documents with implementation guides and ongoing updates.
CCPA Annual Requirement
California law requires privacy policies to be reviewed and updated annually, including the effective date. Last update must be within 12 months.
Related Categories
Important Notice
These templates are provided for informational purposes and must be customized for your specific situation. Privacy requirements vary by jurisdiction, business type, and data processing activities. Consult with a privacy attorney before finalizing any documents.
Need Help With Privacy Compliance?
Our team can help you implement these documents, customize them for your specific requirements, and develop a comprehensive privacy program.