privacy-policy-malik-taiar

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Privacy Policy Guide - GDPR

GDPR合规隐私政策撰写指南

Overview

概述

The privacy policy is the main document for informing data subjects under Articles 13 and 14 of the GDPR. It must be clear, accessible, and comprehensive.
根据GDPR第13条和第14条规定,隐私政策是告知数据主体相关信息的核心文件,必须清晰、易获取且内容全面。

Policy Objectives

政策目标

ObjectiveGDPR Requirement
TransparencyClearly inform about data processing (Art. 12)
InformationProvide all mandatory disclosures (Art. 13-14)
RightsEnable exercise of data subject rights (Art. 15-22)
TrustReassure users about data protection

目标GDPR要求
透明度清晰告知数据处理相关信息(第12条)
信息完整性提供所有强制披露内容(第13-14条)
权利保障支持数据主体行使各项权利(第15-22条)
建立信任向用户保证数据保护措施到位

Reference Resources

参考资源

Templates

模板

TemplateDescription
assets/sample_template_politique_confidentialite.docx
Default template to use if no private template is provided
Internal template provided by lawyerUse if the lawyer has a more suitable private template
IMPORTANT: The default template
sample_template_politique_confidentialite
is designed for a brochure website without user accounts. If the request concerns an application or platform with users, additional data categories will need to be added, such as:
  • User account management (creation, authentication, profile)
  • Login data and activity history
  • Data generated by application usage
  • User-to-user communications (messages, comments, etc.)
  • User preferences and settings
Adapt the template according to the platform type (brochure site, e-commerce, SaaS, mobile app, marketplace, etc.).
模板说明
assets/sample_template_politique_confidentialite.docx
若无专用模板,可使用此默认模板
律师提供的内部模板若律师有更合适的专用模板,优先使用
重要提示:默认模板
sample_template_politique_confidentialite
专为无用户账户的宣传型网站设计。若需求针对含用户功能的应用或平台,则需添加额外数据类别,例如:
  • 用户账户管理(创建、认证、个人资料)
  • 登录数据与活动历史
  • 应用使用生成的数据
  • 用户间通信(消息、评论等)
  • 用户偏好与设置
需根据平台类型(宣传型网站、电商、SaaS、移动应用、 marketplace等)调整模板。

CNIL Documentation

CNIL文档

DocumentContent
CNIL_droits_personnes.pdfGuide on data subject rights (access, rectification, erasure, etc.)
CNIL_durees_conservation.pdfRetention period recommendations by data type
CNIL_finalites.pdfHow to properly define processing purposes
CNIL_transparence.pdfGuide on information and transparency towards data subjects
CNIL_principes_rgpd.pdfFundamental GDPR principles
RGPD_texte_officiel.pdfFull text of EU Regulation 2016/679
文档内容
CNIL_droits_personnes.pdf数据主体权利指南(访问、更正、删除等)
CNIL_durees_conservation.pdf按数据类型划分的保留期限建议
CNIL_finalites.pdf如何合理定义数据处理目的
CNIL_transparence.pdf面向数据主体的信息披露与透明度指南
CNIL_principes_rgpd.pdfGDPR核心原则
RGPD_texte_officiel.pdf欧盟第2016/679号法规全文

Knowledge Base

知识库

DocumentContent
BASES_LEGALES.mdThe 6 legal bases for processing (Art. 6 GDPR) with examples and wording
DROITS_PERSONNES.mdThe 8 data subject rights (Art. 15-22 GDPR) with exercise procedures
COOKIES.mdCNIL 2020 recommendations on cookies, categories, banners, sanctions
DUREES_CONSERVATION.mdRetention period tables by data type with legal justifications

文档内容
BASES_LEGALES.md6种数据处理合法依据(GDPR第6条)及示例与表述方式
DROITS_PERSONNES.md8项数据主体权利(GDPR第15-22条)及行使流程
COOKIES.mdCNIL 2020年关于Cookie的建议、类别、弹窗要求及处罚规定
DUREES_CONSERVATION.md按数据类型划分的保留期限表格及法律依据

Information to Collect from Client

需向客户收集的信息

IMPORTANT: Before drafting the policy, collect ALL the information below from the client.
重要提示:开始撰写政策前,需收集以下所有客户信息。

1. Data Controller Information

1. 数据控制方信息

  • Full company name
  • Legal form (SAS, SARL, Ltd, etc.)
  • Company registration number (SIREN/SIRET)
  • Registered office address
  • Legal representative (name and title)
  • General contact email
  • DPO appointed? If yes, contact details
  • 公司全称
  • 法律形式(SAS、SARL、Ltd等)
  • 公司注册号(SIREN/SIRET)
  • 注册地址
  • 法定代表人(姓名及职务)
  • 通用联系邮箱
  • 是否已任命DPO?若有,提供联系方式

2. Nature of the Site/Application

2. 网站/应用性质

  • Existing website URL (for analysis)
  • Platform type:
    • Brochure website
    • E-commerce
    • SaaS / Web application
    • Mobile application
    • Marketplace
    • Other: ___________
  • Business sector
  • Target audience (B2B, B2C, both)
  • Target countries (France only, EU, international)
  • 现有网站URL(用于分析)
  • 平台类型:
    • 宣传型网站
    • 电商平台
    • SaaS / Web应用
    • 移动应用
    • 交易市场
    • 其他:___________
  • 业务领域
  • 目标受众(B2B、B2C、两者兼顾)
  • 目标国家(仅法国、欧盟、全球)

3. Data Collected

3. 收集的数据

For each category, specify if applicable:
  • IDENTIFICATION DATA
    • First name, last name
    • Email
    • Phone
    • Postal address
    • Date of birth
    • Photo / Avatar
  • CONNECTION DATA
    • IP address
    • Connection logs
    • Device ID
    • Account identifiers
  • BROWSING DATA
    • Pages visited
    • Time spent
    • Clicks
    • Traffic source
  • TRANSACTION DATA
    • Order history
    • Payment data (via provider)
    • Invoices
  • SENSITIVE DATA (special attention)
    • Health data
    • Political/religious opinions
    • Ethnic origin
    • Biometric data
针对每个类别,标注是否适用:
  • 身份识别数据
    • 姓名
    • 邮箱
    • 电话
    • 邮寄地址
    • 出生日期
    • 照片/头像
  • 连接数据
    • IP地址
    • 连接日志
    • 设备ID
    • 账户标识
  • 浏览数据
    • 访问页面
    • 停留时长
    • 点击行为
    • 流量来源
  • 交易数据
    • 订单历史
    • 支付数据(通过服务商)
    • 发票
  • 敏感数据(需特别注意)
    • 健康数据
    • 政治/宗教观点
    • 种族出身
    • 生物识别数据

4. Legal Bases for Processing

4. 数据处理的合法依据

KEY QUESTION: For each processing activity, what is the legal basis?
Legal BasisWhen to UseExample
Contract Performance (Art. 6.1.b)Processing necessary to provide the serviceOrder delivery, account creation
Consent (Art. 6.1.a)Free choice by the person, withdrawable at any timeNewsletter, marketing cookies, sharing with partners
Legitimate Interest (Art. 6.1.f)Company interest, balanced against data subject rightsAnonymized statistics, security, B2B prospecting
Legal Obligation (Art. 6.1.c)Required by lawInvoice retention 10 years, tax obligations
TABLE TO COMPLETE WITH CLIENT:
Processing PurposeLegal BasisData Concerned
Order management
Account creation
Newsletter
Statistics
Customer service
Commercial prospecting
___________________
核心问题:针对每项处理活动,合法依据是什么?
合法依据使用场景示例
合同履行(第6.1.b条)为提供服务必须进行的处理订单配送、账户创建
同意(第6.1.a条)数据主体自由选择,可随时撤回新闻通讯、营销Cookie、与合作伙伴共享数据
合法利益(第6.1.f条)公司利益与数据主体权利平衡后可行的处理匿名统计、安全防护、B2B潜在客户开发
法定义务(第6.1.c条)法律要求的处理发票保留10年、税务义务
需与客户共同填写的表格:
处理目的合法依据涉及数据
订单管理
账户创建
新闻通讯
统计分析
客户服务
商业潜在客户开发
___________________

5. Recipients and Processors

5. 接收方与处理商

  • TECHNICAL PROCESSORS
    • Host: ___________
    • Email provider: ___________
    • Payment provider: ___________
    • Analytics: ___________
    • CRM: ___________
    • Support/Ticketing: ___________
  • TRANSFERS OUTSIDE EU
    • Yes / No
    • If yes, to which countries? ___________
    • Safeguards in place:
      • Standard contractual clauses
      • Adequacy decision
      • Other: ___________
  • 技术处理商
    • 主机服务商:___________
    • 邮件服务商:___________
    • 支付服务商:___________
    • 分析工具:___________
    • CRM系统:___________
    • 支持/工单系统:___________
  • 欧盟外数据传输
    • 是 / 否
    • 若是,传输至哪些国家?___________
    • 已采取的保障措施:
      • 标准合同条款
      • 充分性认定
      • 其他:___________

6. Cookies and Trackers

6. Cookie与追踪器

  • COOKIES USED
    • Strictly necessary cookies (session, cart, authentication)
    • Analytics cookies (Google Analytics, Matomo, etc.)
    • Advertising cookies (Facebook Pixel, Google Ads, etc.)
    • Social media cookies (share buttons)
    • Other: ___________
  • CONSENT MANAGEMENT PLATFORM
    • None
    • Axeptio
    • Didomi
    • Cookiebot
    • Other: ___________
  • 使用的Cookie类型
    • 严格必要Cookie(会话、购物车、认证)
    • 分析Cookie(Google Analytics、Matomo等)
    • 广告Cookie(Facebook Pixel、Google Ads等)
    • 社交媒体Cookie(分享按钮)
    • 其他:___________
  • 同意管理平台
    • Axeptio
    • Didomi
    • Cookiebot
    • 其他:___________

7. Retention Periods

7. 数据保留期限

Data TypeProposed DurationJustification
Active customer accountDuration of relationship
Inactive customer account3 years after last activityProspecting
Prospects3 years without interactionCNIL recommendation
Invoices10 yearsLegal obligation
Connection logs1 yearLCEN
Cookies13 months maxCNIL recommendation

数据类型建议保留时长依据
活跃客户账户合作关系存续期
非活跃客户账户最后一次活动后3年潜在客户开发
潜在客户无互动后3年CNIL建议
发票10年法定义务
连接日志1年LCEN法规
Cookie最长13个月CNIL建议

Drafting Workflow

撰写工作流

Step 1: Template Selection (MANDATORY)

步骤1:选择模板(强制要求)

NEVER DRAFT A POLICY FROM SCRATCH. Always start from a given template for drafting, either:
  • the default template in
    assets/sample_template_politique_confidentialite.docx
    ;
  • another internal template provided by the user.
This template is your base reference. You must:
  • Faithfully reproduce the template's structure and wording
  • Keep the exact template phrasing (they are validated)
  • Only replace placeholders with client information
  • Do NOT rewrite sentences even if you think you can phrase them better
  • Do NOT add sections that are not in the template
The collected information (T&Cs, site, etc.) is used to fill in the template, not to rewrite it.
1. FIRST ACTION: Confirm the template to use BEFORE any drafting. Ask the user:
"I will draft the privacy policy starting from the provided default template. Do you have an internal template that would be more suitable as a starting point?"
OptionAction
Default templateUse
assets/sample_template_politique_confidentialite.docx
Internal templateUse the document provided by the lawyer
2. Consider the user's choice and select the starting template.

绝对禁止:从零开始撰写隐私政策。 必须从给定模板开始撰写,可选:
  • assets/sample_template_politique_confidentialite.docx
    中的默认模板;
  • 用户提供的其他内部模板。
该模板为核心参考,你必须:
  • 严格遵循模板的结构与表述
  • 保留模板的准确措辞(已通过合规验证)
  • 仅替换占位符为客户信息
  • 不得改写句子,即使你认为可以优化表述
  • 不得添加模板中未包含的章节
收集到的信息(条款、网站内容等)仅用于填充模板,而非重写模板。
1. 首要操作:开始撰写前确认使用的模板。向用户询问:
"I will draft the privacy policy starting from the provided default template. Do you have an internal template that would be more suitable as a starting point?"
选项操作
默认模板使用
assets/sample_template_politique_confidentialite.docx
内部模板使用律师提供的文档
2. 根据用户选择确定初始模板。

Step 2: Understand the Client's Business

步骤2:理解客户业务

MAIN OBJECTIVE: Truly understand what the client does, their business, the user journey on their platform.
1. Ask the lawyer for available information:
"To draft a perfectly tailored policy, please provide:
- Information you have about the client and their business
- Existing documents (T&Cs, sales conditions, order forms, contracts...)
- Exchanges or key points raised by the client
- The site/application URL (if accessible)
- Points that must absolutely be included according to you

You may anonymize this information if necessary for confidentiality reasons.

The more information you provide, the better adapted the policy will be to the actual case. Otherwise, we will conduct our own research but it will be limited to publicly accessible information."
2. Analyze the documents provided:
DocumentWhat we extract
T&Cs / Sales ConditionsPlatform operation, services offered, obligations
Order formsData collected, services, potential processors
Client exchangesKey points, specific concerns, business particularities
3. Additional research on the site (if accessible):
Note: Some sites only display a "Request a quote" form without access to the platform. In that case, rely primarily on the documents provided.
The objective is to understand the business AND identify technical elements:
  • Understand what the company actually does
  • Read the existing privacy policy (if present)
  • Read the existing T&Cs/Legal notices
  • Identify the typical user journey (if visible)
  • Identify data collection forms (registration, contact, order...)
  • Spot cookies/trackers via the banner
  • List features (account, newsletter, chat, payment...)
4. Summary before drafting:
CLIENT: [Name]
BUSINESS: [Description in 2-3 sentences]
PLATFORM TYPE: [SaaS, e-commerce, mobile app, etc.]
USER JOURNEY: [Key steps]
DATA COLLECTED: [List by collection point]
COOKIES IDENTIFIED: [Types of cookies spotted]
FORMS: [List of collection points]
KEY LAWYER POINTS: [What must absolutely be included]
SPECIFICITIES: [What makes this case particular]
Once the summary is ready → Proceed to Draft 1

核心目标:真正了解客户的业务内容、平台用户旅程。
1. 向律师索要可用信息:
"To draft a perfectly tailored policy, please provide:
- Information you have about the client and their business
- Existing documents (T&Cs, sales conditions, order forms, contracts...)
- Exchanges or key points raised by the client
- The site/application URL (if accessible)
- Points that must absolutely be included according to you

You may anonymize this information if necessary for confidentiality reasons.

The more information you provide, the better adapted the policy will be to the actual case. Otherwise, we will conduct our own research but it will be limited to publicly accessible information."
2. 分析提供的文档:
文档提取内容
条款/销售条件平台运营方式、提供的服务、各方义务
订单表单收集的数据、服务内容、潜在处理商
与客户的沟通记录核心要点、客户特别关注的问题、业务特殊性
3. 对网站进行额外分析(若可访问):
注意:部分网站仅显示“请求报价”表单,无法访问平台核心内容。这种情况下,优先依赖提供的文档。
目标是理解业务识别技术要素
  • 了解公司实际业务内容
  • 阅读现有隐私政策(若存在)
  • 阅读现有条款/法律声明
  • 识别典型用户旅程(若可见)
  • 识别数据收集表单(注册、联系、订单等)
  • 通过弹窗识别Cookie/追踪器
  • 列出功能模块(账户、新闻通讯、聊天、支付等)
4. 撰写前的总结:
CLIENT: [Name]
BUSINESS: [Description in 2-3 sentences]
PLATFORM TYPE: [SaaS, e-commerce, mobile app, etc.]
USER JOURNEY: [Key steps]
DATA COLLECTED: [List by collection point]
COOKIES IDENTIFIED: [Types of cookies spotted]
FORMS: [List of collection points]
KEY LAWYER POINTS: [What must absolutely be included]
SPECIFICITIES: [What makes this case particular]
总结完成后 → 开始撰写第一版草稿

Step 3: Draft 1

步骤3:第一版草稿

ABSOLUTE RULE: The template is your validated base.
  • START from the template: structure, wording, tone → this is your reference
  • ADAPT to the client case: integrate the specific information collected
  • DO NOT rewrite everything: keep the template wording, only adapt what needs to be
In summary: Template + client information = Draft 1. Not a complete rewrite.
Complete the template section by section with the collected information:
  1. Identity of the data controller
  2. Data collected (by category)
  3. Purposes and legal bases (table)
  4. Recipients and processors
  5. International transfers
  6. Retention periods (table)
  7. Data subject rights
  8. How to exercise rights
  9. Cookies and trackers
  10. Data security
  11. Policy changes
  12. Contact
Immediate compliance check: Before presenting Draft 1, verify the mandatory disclosures checklist (Art. 13 GDPR):
  • Controller identity and contact details
  • DPO contact details (if appointed)
  • Processing purposes
  • Legal basis for each purpose
  • Legitimate interests pursued (if applicable)
  • Recipients or categories of recipients
  • Transfers outside EU and safeguards
  • Retention period or criteria for determination
  • Data subject rights (access, rectification, erasure, restriction, portability, objection)
  • Right to withdraw consent (if applicable)
  • Right to lodge a complaint with the CNIL
  • Whether data provision is mandatory/optional
  • Existence of automated decision-making (if applicable)
If Draft 1 is compliant → Proceed to Step 3.

绝对规则:模板为已验证的核心依据。
  • 从模板出发:结构、措辞、语气均以模板为参考
  • 适配客户场景:整合收集到的客户特定信息
  • 不得全盘重写:保留模板措辞,仅调整必要内容
总结:模板 + 客户信息 = 第一版草稿,而非完全重写。
逐节用收集到的信息填充模板:
  1. 数据控制方身份
  2. 收集的数据(按类别划分)
  3. 处理目的与合法依据(表格)
  4. 接收方与处理商
  5. 国际数据传输
  6. 数据保留期限(表格)
  7. 数据主体权利
  8. 权利行使方式
  9. Cookie与追踪器
  10. 数据安全
  11. 政策变更
  12. 联系方式
即时合规检查:提交第一版草稿前,验证GDPR第13条强制披露清单是否完整:
  • 控制方身份与联系方式
  • DPO联系方式(若已任命)
  • 处理目的
  • 每项目的对应的合法依据
  • 追求的合法利益(若适用)
  • 接收方或接收方类别
  • 欧盟外数据传输及保障措施
  • 保留期限或期限判定标准
  • 数据主体权利(访问、更正、删除、限制处理、数据可携、反对)
  • 撤回同意的权利(若适用)
  • 向CNIL投诉的权利
  • 数据提供是否为强制性/可选
  • 自动化决策的存在(若适用)
若第一版草稿合规 → 进入步骤3。

Step 4: Deliver Draft 1 + Benchmark + Improvement Suggestions

步骤4:提交第一版草稿 + 基准对比 + 改进建议

1. Deliver Draft 1 with explanation:
Here is Draft 1 of the privacy policy.

**What I took into account:**
- [Summary of key elements integrated]
- [Client specificities considered]
- [Particular points mentioned by the lawyer]

**Compliance:** The document meets Art. 13 GDPR requirements.
2. Present the benchmark (systematic):
Research 3-5 privacy policies from companies in the same sector, then present:
**Benchmark conducted:**

I analyzed the privacy policies of:
- [Company 1] - [what we noted]
- [Company 2] - [what we noted]
- [Company 3] - [what we noted]

**Identified possible improvements:**
- [Improvement 1]: [explanation]
- [Improvement 2]: [explanation]
- [Improvement 3]: [explanation]

Would you like to incorporate these elements into the provided Draft?
3. If the lawyer approves improvements → Produce Draft 2.

1. 提交第一版草稿并说明:
Here is Draft 1 of the privacy policy.

**What I took into account:**
- [Summary of key elements integrated]
- [Client specificities considered]
- [Particular points mentioned by the lawyer]

**Compliance:** The document meets Art. 13 GDPR requirements.
2. 展示基准对比(强制要求):
调研3-5家同行业公司的隐私政策,然后说明:
**Benchmark conducted:**

I analyzed the privacy policies of:
- [Company 1] - [what we noted]
- [Company 2] - [what we noted]
- [Company 3] - [what we noted]

**Identified possible improvements:**
- [Improvement 1]: [explanation]
- [Improvement 2]: [explanation]
- [Improvement 3]: [explanation]

Would you like to incorporate these elements into the provided Draft?
3. 若律师认可改进建议 → 生成第二版草稿。

Step 5: Final Verification

步骤5:最终验证

Final review before definitive delivery:
  • All Art. 13 GDPR disclosures present
  • Client information correctly integrated
  • Clear and accessible language
  • No internal references (template, sources) in final document
  • Update date present

正式交付前的最终审核:
  • GDPR第13条所有披露内容齐全
  • 客户信息整合正确
  • 语言清晰易懂
  • 最终文档中无内部参考(模板、来源)
  • 包含更新日期

Standard Policy Structure

标准政策结构

PRIVACY POLICY
[Company Name]
Last updated: [DATE]

TABLE OF CONTENTS (if long document)

1. WHO ARE WE?
   - Controller identity
   - DPO contact details

2. WHAT DATA DO WE COLLECT?
   - Identification data
   - Browsing data
   - Transaction data
   - Etc.

3. WHY DO WE COLLECT YOUR DATA?
   - Purposes / legal bases table

4. WITH WHOM DO WE SHARE YOUR DATA?
   - Internal services
   - Processors
   - Partners (if consent)
   - Authorities (legal obligations)

5. IS YOUR DATA TRANSFERRED OUTSIDE THE EU?
   - Countries concerned
   - Safeguards

6. HOW LONG DO WE KEEP YOUR DATA?
   - Retention periods table by data type

7. WHAT ARE YOUR RIGHTS?
   - List of rights with simple explanation
   - How to exercise them

8. COOKIES AND TRACKERS
   - Types of cookies used
   - Preference management

9. SECURITY
   - Measures in place (without sensitive technical details)

10. CHANGES TO THIS POLICY
    - Notification procedure

11. CONTACT US
    - Email
    - Postal address
    - Link to form

PRIVACY POLICY
[Company Name]
Last updated: [DATE]

TABLE OF CONTENTS (if long document)

1. WHO ARE WE?
   - Controller identity
   - DPO contact details

2. WHAT DATA DO WE COLLECT?
   - Identification data
   - Browsing data
   - Transaction data
   - Etc.

3. WHY DO WE COLLECT YOUR DATA?
   - Purposes / legal bases table

4. WITH WHOM DO WE SHARE YOUR DATA?
   - Internal services
   - Processors
   - Partners (if consent)
   - Authorities (legal obligations)

5. IS YOUR DATA TRANSFERRED OUTSIDE THE EU?
   - Countries concerned
   - Safeguards

6. HOW LONG DO WE KEEP YOUR DATA?
   - Retention periods table by data type

7. WHAT ARE YOUR RIGHTS?
   - List of rights with simple explanation
   - How to exercise them

8. COOKIES AND TRACKERS
   - Types of cookies used
   - Preference management

9. SECURITY
   - Measures in place (without sensitive technical details)

10. CHANGES TO THIS POLICY
    - Notification procedure

11. CONTACT US
    - Email
    - Postal address
    - Link to form

Drafting Best Practices

撰写最佳实践

Writing Style

写作风格

DoAvoid
Use "you" / "your data"Use "the user" / "the data subject"
Short and simple sentencesExcessive legal jargon
Concrete examplesVague wording ("various data")
Tables for clarityDense paragraphs
Clear and explicit headingsMultiple cross-references without explanation
建议做法避免做法
使用“您”/“您的数据”使用“用户”/“数据主体”
短句、简单句过度使用法律术语
具体示例模糊表述(如“各类数据”)
用表格提升清晰度密集段落
清晰明确的标题大量交叉引用但无说明

Accessibility

易访问性

  • Clear language: understandable by a non-lawyer user
  • Visible structure: table of contents, numbered headings
  • Layered information: summary + details if needed
  • Update date: visible at top of document

  • 语言清晰:非法律从业者也能理解
  • 结构清晰:目录、编号标题
  • 分层信息:摘要 + 详细内容(若需)
  • 更新日期:显示在文档顶部

Common Mistakes to Avoid

需避免的常见错误

MistakeConsequenceSolution
Copy-paste from generic templateNon-compliance, inconsistencyAdapt to each case
Incorrect legal basesUnlawful processingAnalyze each purpose
Missing retention periodsNon-compliance Art. 13Systematic table
Forgetting transfers outside EUPotential fineCheck processors
Rights mentioned without proceduresRights unexercisableDedicated email address
Cookie wallProhibited by CNILRefusing as easy as accepting

错误后果解决方案
直接复制通用模板不合规、内容不一致针对每个场景调整模板
合法依据错误处理行为违法针对每项目的进行分析
遗漏保留期限违反第13条要求统一使用保留期限表格
忽略欧盟外数据传输可能面临罚款核查所有处理商
仅提及权利但未说明行使流程权利无法实际行使提供专用联系邮箱
Cookie墙被CNIL禁止拒绝Cookie需与接受同样便捷

CNIL Reference Sanctions

CNIL参考处罚案例

CompanyAmountMain Reason
Google€150MCookies: refusing more difficult than accepting
Facebook€60MCookies: no "reject all" button
Carrefour€3MInsufficient information, excessive retention
Amazon€35MCookies placed without consent
These sanctions illustrate the importance of a compliant policy and rigorous cookie management.

公司罚款金额主要原因
Google1500万欧元Cookie:拒绝操作比接受更复杂
Facebook600万欧元Cookie:无“全部拒绝”按钮
Carrefour30万欧元信息披露不足、保留期限过长
Amazon350万欧元未经同意设置Cookie
这些处罚案例表明,合规的隐私政策与严谨的Cookie管理至关重要。

Frequently Asked Questions

常见问题

1. Must the policy be in French?

1. 政策必须用法语撰写吗?

Yes, if the site targets French users. It can be bilingual if the site is international.
是的,若网站面向法国用户。若为国际网站,可提供双语版本。

2. Is a separate policy needed for the mobile app?

2. 移动应用需要单独的隐私政策吗?

Not necessarily, but the policy must cover app-specific aspects (permissions, data collected by the device).
不一定,但政策必须覆盖应用特有的内容(权限、设备收集的数据)。

3. How to handle updates?

3. 如何处理政策更新?

  • Date each version
  • Inform users of substantial changes
  • Keep previous versions
  • 为每个版本标注日期
  • 向用户通知重大变更
  • 保留历史版本

4. Is a DPO mandatory?

4. 必须任命DPO吗?

Not systematically. Mandatory if:
  • Public authority
  • Large-scale processing of sensitive data
  • Regular and systematic large-scale monitoring

并非强制。仅在以下情况需要:
  • 公共机构
  • 大规模处理敏感数据
  • 定期、系统性地大规模监控

Using This Guide

本指南使用流程

  1. Step 1 - Choose the template: Default, or lawyer's internal template
  2. Step 2 - Understand the business: Collect lawyer docs + site research
  3. Step 3 - Draft Draft 1: Complete template + compliance check
  4. Step 4 - Deliver + Benchmark: Present Draft 1 + systematic benchmark + improvement suggestions
  5. Step 5 - Finalize: Integrate approved improvements + final verification
TEMPLATE REMINDER: Never draft from scratch. Always start from the template and adapt it.
SOURCES REMINDER: The CNIL and GDPR references in this guide are for the drafter. They should not appear in the final document, except for mandatory legal disclosures (right to lodge a complaint with CNIL, etc.).
  1. 步骤1 - 选择模板:默认模板或律师提供的内部模板
  2. 步骤2 - 理解业务:收集律师提供的文档 + 网站调研
  3. 步骤3 - 撰写第一版草稿:填充模板 + 合规检查
  4. 步骤4 - 提交 + 基准对比:提交第一版草稿 + 系统性基准对比 + 改进建议
  5. 步骤5 - 最终定稿:整合获批的改进内容 + 最终验证
模板提醒:禁止从零开始撰写,必须从模板出发进行调整。
来源提醒:本指南中的CNIL与GDPR参考内容仅供撰写者使用,最终文档中不得包含这些内部参考,仅需保留强制法律披露内容(如向CNIL投诉的权利等)。",