Image 1 of 1
Data Protection Policy Template — GDPR Compliant | People Stack Now
Data protection compliance is legally mandatory in Ireland and the UK and practically required in every jurisdiction where the Company operates. This policy gives organizations the documented foundation that GDPR and equivalent legislation demands.
Covers: the seven data protection principles, what personal data is held and why, lawful bases for processing (including the special category data warning), six individual rights with jurisdiction-specific response timelines, a five-step breach response process with notification windows (GDPR 72 hours, AU NDB 30 days, US state law timelines), and employee obligations. Jurisdiction flags for GDPR/UK GDPR, US (CCPA/CPRA, HIPAA), PIPEDA/Law 25, and Australian Privacy Principles.
FAQS
Q Is a written data protection policy legally required?
Under the GDPR (which applies in Ireland and to any company processing EU residents' personal data regardless of location), a documented policy is a core element of the accountability obligation under Article 5(2) and the record of processing activities required under Article 30. Its absence is itself an indicator of non-compliance. For UK employers, the UK GDPR imposes equivalent requirements.
Q What is the difference between a data protection policy and a privacy notice?
A data protection policy is an internal document covering how the organization handles personal data — the principles applied, lawful bases, individual rights, and employee obligations. A privacy notice is an external-facing document provided to individuals explaining how their data is used. Both are required under GDPR; this document covers the internal policy. Separate employee and customer privacy notices should be prepared for external publication.
Q What is a Subject Access Request and how long do we have to respond?
A SAR is a request from an individual to receive a copy of their personal data and information about how it is used. Response timelines: GDPR/UK GDPR — 1 calendar month (extendable to 3 for complex requests); PIPEDA (Canada) — 30 days; Australian Privacy Act — 30 days; CCPA (California) — 45 days. The policy sets out the SAR handling process and the limited grounds on which a request can be refused.
Q What does the 72-hour breach notification requirement mean?
Where a personal data breach creates a risk to individuals' rights and freedoms, GDPR requires notification to the supervisory authority within 72 hours of becoming aware — not from the breach itself. This requires a documented breach response process enabling rapid triage and notification. The policy includes a five-step breach response framework with specific timelines for each stage.
Data protection compliance is legally mandatory in Ireland and the UK and practically required in every jurisdiction where the Company operates. This policy gives organizations the documented foundation that GDPR and equivalent legislation demands.
Covers: the seven data protection principles, what personal data is held and why, lawful bases for processing (including the special category data warning), six individual rights with jurisdiction-specific response timelines, a five-step breach response process with notification windows (GDPR 72 hours, AU NDB 30 days, US state law timelines), and employee obligations. Jurisdiction flags for GDPR/UK GDPR, US (CCPA/CPRA, HIPAA), PIPEDA/Law 25, and Australian Privacy Principles.
FAQS
Q Is a written data protection policy legally required?
Under the GDPR (which applies in Ireland and to any company processing EU residents' personal data regardless of location), a documented policy is a core element of the accountability obligation under Article 5(2) and the record of processing activities required under Article 30. Its absence is itself an indicator of non-compliance. For UK employers, the UK GDPR imposes equivalent requirements.
Q What is the difference between a data protection policy and a privacy notice?
A data protection policy is an internal document covering how the organization handles personal data — the principles applied, lawful bases, individual rights, and employee obligations. A privacy notice is an external-facing document provided to individuals explaining how their data is used. Both are required under GDPR; this document covers the internal policy. Separate employee and customer privacy notices should be prepared for external publication.
Q What is a Subject Access Request and how long do we have to respond?
A SAR is a request from an individual to receive a copy of their personal data and information about how it is used. Response timelines: GDPR/UK GDPR — 1 calendar month (extendable to 3 for complex requests); PIPEDA (Canada) — 30 days; Australian Privacy Act — 30 days; CCPA (California) — 45 days. The policy sets out the SAR handling process and the limited grounds on which a request can be refused.
Q What does the 72-hour breach notification requirement mean?
Where a personal data breach creates a risk to individuals' rights and freedoms, GDPR requires notification to the supervisory authority within 72 hours of becoming aware — not from the breach itself. This requires a documented breach response process enabling rapid triage and notification. The policy includes a five-step breach response framework with specific timelines for each stage.