Skip to content
PeekWellThe Rulebook
Join now

GDPR privacy policy: a page visitors can find

At a glance

EU-09HighGDPR Arts. 12(1), 13 and 14; penalties in Art. 83(5)(b)

Peeky looks for a privacy policy that exists, opens, is written in the language of the site and can be reached in two clicks or fewer from any page.

Last checked against the source:

I need to fix thisI need the rule

The rule

Article 13(1) of the GDPR requires a controller that collects personal data from the person it concerns to provide certain information “at the time when personal data are obtained”. The list starts with the identity and contact details of the controller, then the purposes and legal basis, and goes on to recipients and transfers. Paragraph 2 adds retention, the rights of the person, the right to lodge a complaint and whether providing the data is required. Article 12(1) governs the manner: the controller must provide it “in a concise, transparent, intelligible and easily accessible form, using clear and plain language.”

Article 14 covers data that came from somewhere else, and Article 5(1)(a) makes transparency a principle of processing. None of them uses the phrase “privacy policy” or says where a notice sits on a website. The guidance does that work. This check is about the form of the duty, whether the information can be found, and leaves its content to EU-08.

The Article 29 Working Party, the EDPB’s predecessor, explains “easily accessible” this way: the person “should not have to seek out the information; it should be immediately apparent to them where and how this information can be accessed”. Its example for websites is direct: “Every organisation that maintains a website should publish a privacy statement/ notice on the website. A direct link to this privacy statement/ notice should be clearly visible on each page of this website under a commonly used term (such as ‘Privacy’, ‘Privacy Policy’ or ‘Data Protection Notice’). Positioning or colour schemes that make a text or link less noticeable, or hard to find on a webpage, are not considered easily accessible.” On language, the guidelines say a translation should be provided “where the controller targets data subjects speaking those languages” (para. 13).

Penalties follow the rights chapter. Article 83(5)(b) places “the data subjects’ rights pursuant to Articles 12 to 22” in the upper tier, with a ceiling of EUR 20 million or 4% of worldwide annual turnover, whichever is higher. The check’s own citation lists Articles 12(1) and 13; the penalty tier and Article 14 are added here.

The enforcement record shows two different failures. In the CNIL’s Google decision, the information existed but was spread across layers. France’s Council of State, upholding the decision, recorded that “a user must first of all carry out three actions starting from the first level of information before returning to the initial document and carrying out two more actions, a total of five actions altogether, while six actions are required to obtain exhaustive information on geolocation” (para. 18). It concluded that the Restricted Committee “was right in characterising a breach of the obligations of information and transparency defined by the aforementioned Articles 12 and 13” (para. 20). In Italy’s D’Anna decision, by contrast, the notice for a web form was missing altogether.

What PeekWell checks and how

EU-09 asks one question: can a visitor reach a privacy policy from any page without hunting? The scan answers it from the pages it opened, not from what the site says about itself.

The scan crawls the footer and navigation of the public pages it visits and collects links that look like a privacy policy. It follows each one to confirm it opens, counts how many clicks it takes to reach it from each page, and compares the language of the policy with the site’s main language. It flags three things: no policy link found, a link that does not open, and a policy in a different language from the site. A policy that sits more than two clicks from a page is flagged too. Two clicks is the scan’s working measure. It is not a figure from the GDPR, and the guidance asks for a link on each page.

The decision is made by code. Whether a link exists, opens, how many clicks it took and which language the text is in are matters of record, and a language model plays no part. The method is the same as UK-10 and the first half of US-13; only the rules the findings are read against differ.

The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. It checks that a policy can be found and opens, and does not judge whether it is complete or accurate; that is EU-08 and EU-05. A link that appears only inside an app or after a sign-in is outside what a browser visit can see. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.

Why it matters for a company

A missing or hidden policy is one of the easiest facts for an authority to establish, because anyone can check it from a browser. The Garante did exactly that in the D’Anna case. Its notice of the allegations said no information text for the quote form could be found on the page, in other sections or in the footer. On 8 August 2024 its office checked the form and found it still took a name, contact details and an email address. The company argued that the form never worked in practice. The Garante noted that it was still live and that notice text had been inserted only recently, and said a notice has to match what the company actually does with the data.

The Google decision shows the other pattern. The company had a policy, but the information a person needed sat behind a chain of clicks and a long document. The court treated that structure as the problem, given how intrusive the processing was.

For a company the practical consequences are of three kinds. The check is visible from outside, so a complaint about something else, such as marketing emails in the Italian case, can lead an authority to look at the website too. The information has to be there when the data is collected (Art. 13(1)), so adding it later does not undo the earlier period. And the guidelines treat a link that is hard to find as not easily accessible, whatever the text says.

Smaller companies and larger companies

The rule has no size threshold. It applies to a one-person consultancy with a contact form in the same way as to a platform with millions of accounts. What differs is how the gap appears.

In a small company the website is usually a template or a hosted builder. A privacy page is written once, often from a generator, and linked from the footer of the home page only. A later redesign drops the footer, a landing page is built on a separate tool without one, or a quote or contact form is added months after the policy was written and nobody links the two. The Italian insurance intermediary is that pattern: a form that collected names and contact details, with no notice attached. Smaller companies are within reach of authorities. The Garante’s decision there ended in one fine of 5,000 euros covering this and a separate failure to act on an opt-out, and an order to provide a suitable notice.

In a larger company the difficulty is spread. There are many domains, campaign microsites, regional versions and apps, owned by different teams and agencies. One site links the policy; another, launched for a promotion, does not. A French page may link an English policy written for another market, which raises the language point in the guidelines. A group policy may grow into a long document with the key points deep inside it, the situation the Google decision describes. Scale changes the stakes as well, since Article 83(5) ties the ceiling to turnover.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • Google LLC

    CNIL (France), 2019€50 million

    The CNIL's Restricted Committee found that essential information on some processing was reachable only after a long series of actions: five actions to learn about personalised advertising and six for geolocation, with data retention periods behind a link on the sixty-eighth page of a document. France's Council of State confirmed the transparency finding, and the fine, on 19 June 2020. The decision also covered consent for ad personalisation.

    Read the CNIL (France) publication about Google LLC

Smaller companies

  • D'Anna Assicurazioni S.r.l.

    Garante (Italy), 2024€5,000

    The Garante's decision followed a complaint about marketing emails sent after the recipient objected. It found the company had not acted on that objection (Arts. 12, 17 and 21) and, separately, that its website quote form had no privacy notice when the Garante opened proceedings, with text added only afterwards that did not match how the form was used (Arts. 12 and 13). It ordered a suitable notice and imposed a single fine of 5,000 euros covering both findings.

    Read the Garante (Italy) publication about D'Anna Assicurazioni S.r.l.

How to fix it

The goal in the guidelines is a direct link, clearly visible, on every page, under a common name. These steps put that in place on most sites and site builders.

  1. List every public page type and domain. Home, product pages, blog, landing pages, checkout, regional versions and any microsite. Anything with its own template needs its own check.
  2. Put one link in the shared footer. Add a link labelled “Privacy policy” or “Privacy” to the footer template, so it is inherited by every page type. Do not hide it in a menu that opens only on small screens. Keep it at normal size and contrast.
  3. Point every form at the notice. Next to each contact form, newsletter box or quote request, add a short line with a link to the policy, so the information is available at the point where the data is entered.
  4. Match the language. If a page is in French, link a French policy. If you run several language versions, give each its own link to the right translation.
  5. Check that the link opens. Open it from a private window on a phone and on a computer. A policy that returns an error, redirects to the home page or needs a sign-in does not count.
  6. Re-scan. Run a scan again. The finding should disappear once each page type shows a working link within two clicks, in the site’s language.
<footer>
  <a href="/privacy/">Privacy policy</a>
</footer>

What goes inside the policy is a separate question, and EU-08 covers the Article 13 list. Whether a setup meets an authority’s view is for your legal adviser, and Peeky reports only what it sees.

Questions

Does every website need a privacy policy under GDPR?

Any site that collects personal data from visitors needs to give them the information in Article 13, and a privacy policy page is the usual way to do it. A contact form, a newsletter box, an account or analytics all count as collecting data. The GDPR does not use the words privacy policy, but the Article 29 Working Party's guidelines say every organisation with a website should publish one.

What does GDPR Article 13 require in a privacy notice?

Who you are and how to contact you, why you use the data and on what legal basis, who receives it, and any transfers outside the EU. Paragraph 2 adds how long you keep it, the rights people have, the right to complain to an authority and whether giving the data is required. The rule sets out where it must appear and when.

Where should the privacy policy link go on a website?

On every page, in a place people expect, with a common name such as Privacy or Privacy Policy. The Article 29 Working Party's guidelines say a direct link should be clearly visible on each page, and that positioning or colours that make it hard to notice do not count as easily accessible. The footer is the usual home.

How many clicks away can a privacy policy be?

The GDPR sets no number. The rule is that people should not have to seek the information out. PeekWell uses two clicks from any page as its working measure, and the French court decision on Google shows the other end: it upheld a transparency finding where information took five actions, or six for geolocation, to reach through layered documents.

How does Peeky check for a missing privacy policy?

Peeky reads the footer and navigation of the public pages it visits, follows the policy link, counts the clicks from each page and compares the policy's language with the site's. It never signs in or fills in a form. How a scan works has the full path.

Filed with

The rule

GDPR (Regulation (EU) 2016/679), Arts. 5(1)(a), 12(1), 13, 14 and 83(5)(b)

Read the rule (GDPR (Regulation (EU) 2016/679), Arts. 5(1)(a), 12(1), 13, 14 and 83(5)(b))

A case

Google LLC

CNIL (France), 2019

Read the decision (Google LLC)

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. Regulation (EU) 2016/679 (GDPR), Official Journal L 119, 4.5.2016 (Publications Office copy)
  2. Article 29 Working Party, Guidelines on transparency under Regulation 2016/679 (WP260 rev.01), adopted 29 November 2017, last revised and adopted 11 April 2018
  3. Conseil d'Etat, decision no. 430810, Google LLC, 19 June 2020 (courtesy translation by the CNIL)
  4. Garante per la protezione dei dati personali, provvedimento of 14 November 2024 on D'Anna Assicurazioni S.r.l. (doc. web no. 10107986)

Last checked against the source:

For information only. Not legal advice.