privacy-policy-malik-taiar
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
ChinesePrivacy Policy Guide - GDPR
GDPR合规隐私政策撰写指南
Overview
概述
The privacy policy is the main document for informing data subjects under Articles 13 and 14 of the GDPR. It must be clear, accessible, and comprehensive.
根据GDPR第13条和第14条规定,隐私政策是告知数据主体相关信息的核心文件,必须清晰、易获取且内容全面。
Policy Objectives
政策目标
| Objective | GDPR Requirement |
|---|---|
| Transparency | Clearly inform about data processing (Art. 12) |
| Information | Provide all mandatory disclosures (Art. 13-14) |
| Rights | Enable exercise of data subject rights (Art. 15-22) |
| Trust | Reassure users about data protection |
| 目标 | GDPR要求 |
|---|---|
| 透明度 | 清晰告知数据处理相关信息(第12条) |
| 信息完整性 | 提供所有强制披露内容(第13-14条) |
| 权利保障 | 支持数据主体行使各项权利(第15-22条) |
| 建立信任 | 向用户保证数据保护措施到位 |
Reference Resources
参考资源
Templates
模板
| Template | Description |
|---|---|
| Default template to use if no private template is provided |
| Internal template provided by lawyer | Use if the lawyer has a more suitable private template |
IMPORTANT: The default templateis designed for a brochure website without user accounts. If the request concerns an application or platform with users, additional data categories will need to be added, such as:sample_template_politique_confidentialite
- User account management (creation, authentication, profile)
- Login data and activity history
- Data generated by application usage
- User-to-user communications (messages, comments, etc.)
- User preferences and settings
Adapt the template according to the platform type (brochure site, e-commerce, SaaS, mobile app, marketplace, etc.).
| 模板 | 说明 |
|---|---|
| 若无专用模板,可使用此默认模板 |
| 律师提供的内部模板 | 若律师有更合适的专用模板,优先使用 |
重要提示:默认模板专为无用户账户的宣传型网站设计。若需求针对含用户功能的应用或平台,则需添加额外数据类别,例如:sample_template_politique_confidentialite
- 用户账户管理(创建、认证、个人资料)
- 登录数据与活动历史
- 应用使用生成的数据
- 用户间通信(消息、评论等)
- 用户偏好与设置
需根据平台类型(宣传型网站、电商、SaaS、移动应用、 marketplace等)调整模板。
CNIL Documentation
CNIL文档
| Document | Content |
|---|---|
| CNIL_droits_personnes.pdf | Guide on data subject rights (access, rectification, erasure, etc.) |
| CNIL_durees_conservation.pdf | Retention period recommendations by data type |
| CNIL_finalites.pdf | How to properly define processing purposes |
| CNIL_transparence.pdf | Guide on information and transparency towards data subjects |
| CNIL_principes_rgpd.pdf | Fundamental GDPR principles |
| RGPD_texte_officiel.pdf | Full text of EU Regulation 2016/679 |
| 文档 | 内容 |
|---|---|
| CNIL_droits_personnes.pdf | 数据主体权利指南(访问、更正、删除等) |
| CNIL_durees_conservation.pdf | 按数据类型划分的保留期限建议 |
| CNIL_finalites.pdf | 如何合理定义数据处理目的 |
| CNIL_transparence.pdf | 面向数据主体的信息披露与透明度指南 |
| CNIL_principes_rgpd.pdf | GDPR核心原则 |
| RGPD_texte_officiel.pdf | 欧盟第2016/679号法规全文 |
Knowledge Base
知识库
| Document | Content |
|---|---|
| BASES_LEGALES.md | The 6 legal bases for processing (Art. 6 GDPR) with examples and wording |
| DROITS_PERSONNES.md | The 8 data subject rights (Art. 15-22 GDPR) with exercise procedures |
| COOKIES.md | CNIL 2020 recommendations on cookies, categories, banners, sanctions |
| DUREES_CONSERVATION.md | Retention period tables by data type with legal justifications |
| 文档 | 内容 |
|---|---|
| BASES_LEGALES.md | 6种数据处理合法依据(GDPR第6条)及示例与表述方式 |
| DROITS_PERSONNES.md | 8项数据主体权利(GDPR第15-22条)及行使流程 |
| COOKIES.md | CNIL 2020年关于Cookie的建议、类别、弹窗要求及处罚规定 |
| DUREES_CONSERVATION.md | 按数据类型划分的保留期限表格及法律依据 |
Information to Collect from Client
需向客户收集的信息
IMPORTANT: Before drafting the policy, collect ALL the information below from the client.
重要提示:开始撰写政策前,需收集以下所有客户信息。
1. Data Controller Information
1. 数据控制方信息
- Full company name
- Legal form (SAS, SARL, Ltd, etc.)
- Company registration number (SIREN/SIRET)
- Registered office address
- Legal representative (name and title)
- General contact email
- DPO appointed? If yes, contact details
- 公司全称
- 法律形式(SAS、SARL、Ltd等)
- 公司注册号(SIREN/SIRET)
- 注册地址
- 法定代表人(姓名及职务)
- 通用联系邮箱
- 是否已任命DPO?若有,提供联系方式
2. Nature of the Site/Application
2. 网站/应用性质
- Existing website URL (for analysis)
- Platform type:
- Brochure website
- E-commerce
- SaaS / Web application
- Mobile application
- Marketplace
- Other: ___________
- Business sector
- Target audience (B2B, B2C, both)
- Target countries (France only, EU, international)
- 现有网站URL(用于分析)
- 平台类型:
- 宣传型网站
- 电商平台
- SaaS / Web应用
- 移动应用
- 交易市场
- 其他:___________
- 业务领域
- 目标受众(B2B、B2C、两者兼顾)
- 目标国家(仅法国、欧盟、全球)
3. Data Collected
3. 收集的数据
For each category, specify if applicable:
-
IDENTIFICATION DATA
- First name, last name
- Phone
- Postal address
- Date of birth
- Photo / Avatar
-
CONNECTION DATA
- IP address
- Connection logs
- Device ID
- Account identifiers
-
BROWSING DATA
- Pages visited
- Time spent
- Clicks
- Traffic source
-
TRANSACTION DATA
- Order history
- Payment data (via provider)
- Invoices
-
SENSITIVE DATA (special attention)
- Health data
- Political/religious opinions
- Ethnic origin
- Biometric data
针对每个类别,标注是否适用:
-
身份识别数据
- 姓名
- 邮箱
- 电话
- 邮寄地址
- 出生日期
- 照片/头像
-
连接数据
- IP地址
- 连接日志
- 设备ID
- 账户标识
-
浏览数据
- 访问页面
- 停留时长
- 点击行为
- 流量来源
-
交易数据
- 订单历史
- 支付数据(通过服务商)
- 发票
-
敏感数据(需特别注意)
- 健康数据
- 政治/宗教观点
- 种族出身
- 生物识别数据
4. Legal Bases for Processing
4. 数据处理的合法依据
KEY QUESTION: For each processing activity, what is the legal basis?
| Legal Basis | When to Use | Example |
|---|---|---|
| Contract Performance (Art. 6.1.b) | Processing necessary to provide the service | Order delivery, account creation |
| Consent (Art. 6.1.a) | Free choice by the person, withdrawable at any time | Newsletter, marketing cookies, sharing with partners |
| Legitimate Interest (Art. 6.1.f) | Company interest, balanced against data subject rights | Anonymized statistics, security, B2B prospecting |
| Legal Obligation (Art. 6.1.c) | Required by law | Invoice retention 10 years, tax obligations |
TABLE TO COMPLETE WITH CLIENT:
| Processing Purpose | Legal Basis | Data Concerned |
|---|---|---|
| Order management | ||
| Account creation | ||
| Newsletter | ||
| Statistics | ||
| Customer service | ||
| Commercial prospecting | ||
| ___________________ |
核心问题:针对每项处理活动,合法依据是什么?
| 合法依据 | 使用场景 | 示例 |
|---|---|---|
| 合同履行(第6.1.b条) | 为提供服务必须进行的处理 | 订单配送、账户创建 |
| 同意(第6.1.a条) | 数据主体自由选择,可随时撤回 | 新闻通讯、营销Cookie、与合作伙伴共享数据 |
| 合法利益(第6.1.f条) | 公司利益与数据主体权利平衡后可行的处理 | 匿名统计、安全防护、B2B潜在客户开发 |
| 法定义务(第6.1.c条) | 法律要求的处理 | 发票保留10年、税务义务 |
需与客户共同填写的表格:
| 处理目的 | 合法依据 | 涉及数据 |
|---|---|---|
| 订单管理 | ||
| 账户创建 | ||
| 新闻通讯 | ||
| 统计分析 | ||
| 客户服务 | ||
| 商业潜在客户开发 | ||
| ___________________ |
5. Recipients and Processors
5. 接收方与处理商
-
TECHNICAL PROCESSORS
- Host: ___________
- Email provider: ___________
- Payment provider: ___________
- Analytics: ___________
- CRM: ___________
- Support/Ticketing: ___________
-
TRANSFERS OUTSIDE EU
- Yes / No
- If yes, to which countries? ___________
- Safeguards in place:
- Standard contractual clauses
- Adequacy decision
- Other: ___________
-
技术处理商
- 主机服务商:___________
- 邮件服务商:___________
- 支付服务商:___________
- 分析工具:___________
- CRM系统:___________
- 支持/工单系统:___________
-
欧盟外数据传输
- 是 / 否
- 若是,传输至哪些国家?___________
- 已采取的保障措施:
- 标准合同条款
- 充分性认定
- 其他:___________
6. Cookies and Trackers
6. Cookie与追踪器
-
COOKIES USED
- Strictly necessary cookies (session, cart, authentication)
- Analytics cookies (Google Analytics, Matomo, etc.)
- Advertising cookies (Facebook Pixel, Google Ads, etc.)
- Social media cookies (share buttons)
- Other: ___________
-
CONSENT MANAGEMENT PLATFORM
- None
- Axeptio
- Didomi
- Cookiebot
- Other: ___________
-
使用的Cookie类型
- 严格必要Cookie(会话、购物车、认证)
- 分析Cookie(Google Analytics、Matomo等)
- 广告Cookie(Facebook Pixel、Google Ads等)
- 社交媒体Cookie(分享按钮)
- 其他:___________
-
同意管理平台
- 无
- Axeptio
- Didomi
- Cookiebot
- 其他:___________
7. Retention Periods
7. 数据保留期限
| Data Type | Proposed Duration | Justification |
|---|---|---|
| Active customer account | Duration of relationship | |
| Inactive customer account | 3 years after last activity | Prospecting |
| Prospects | 3 years without interaction | CNIL recommendation |
| Invoices | 10 years | Legal obligation |
| Connection logs | 1 year | LCEN |
| Cookies | 13 months max | CNIL recommendation |
| 数据类型 | 建议保留时长 | 依据 |
|---|---|---|
| 活跃客户账户 | 合作关系存续期 | |
| 非活跃客户账户 | 最后一次活动后3年 | 潜在客户开发 |
| 潜在客户 | 无互动后3年 | CNIL建议 |
| 发票 | 10年 | 法定义务 |
| 连接日志 | 1年 | LCEN法规 |
| Cookie | 最长13个月 | CNIL建议 |
Drafting Workflow
撰写工作流
Step 1: Template Selection (MANDATORY)
步骤1:选择模板(强制要求)
NEVER DRAFT A POLICY FROM SCRATCH. Always start from a given template for drafting, either:
- the default template in
;assets/sample_template_politique_confidentialite.docx- another internal template provided by the user.
This template is your base reference. You must:
- Faithfully reproduce the template's structure and wording
- Keep the exact template phrasing (they are validated)
- Only replace placeholders with client information
- Do NOT rewrite sentences even if you think you can phrase them better
- Do NOT add sections that are not in the template
The collected information (T&Cs, site, etc.) is used to fill in the template, not to rewrite it.
1. FIRST ACTION: Confirm the template to use BEFORE any drafting. Ask the user:
"I will draft the privacy policy starting from the provided default template. Do you have an internal template that would be more suitable as a starting point?"| Option | Action |
|---|---|
| Default template | Use |
| Internal template | Use the document provided by the lawyer |
2. Consider the user's choice and select the starting template.
绝对禁止:从零开始撰写隐私政策。 必须从给定模板开始撰写,可选:
中的默认模板;assets/sample_template_politique_confidentialite.docx- 用户提供的其他内部模板。
该模板为核心参考,你必须:
- 严格遵循模板的结构与表述
- 保留模板的准确措辞(已通过合规验证)
- 仅替换占位符为客户信息
- 不得改写句子,即使你认为可以优化表述
- 不得添加模板中未包含的章节
收集到的信息(条款、网站内容等)仅用于填充模板,而非重写模板。
1. 首要操作:开始撰写前确认使用的模板。向用户询问:
"I will draft the privacy policy starting from the provided default template. Do you have an internal template that would be more suitable as a starting point?"| 选项 | 操作 |
|---|---|
| 默认模板 | 使用 |
| 内部模板 | 使用律师提供的文档 |
2. 根据用户选择确定初始模板。
Step 2: Understand the Client's Business
步骤2:理解客户业务
MAIN OBJECTIVE: Truly understand what the client does, their business, the user journey on their platform.
1. Ask the lawyer for available information:
"To draft a perfectly tailored policy, please provide:
- Information you have about the client and their business
- Existing documents (T&Cs, sales conditions, order forms, contracts...)
- Exchanges or key points raised by the client
- The site/application URL (if accessible)
- Points that must absolutely be included according to you
You may anonymize this information if necessary for confidentiality reasons.
The more information you provide, the better adapted the policy will be to the actual case. Otherwise, we will conduct our own research but it will be limited to publicly accessible information."2. Analyze the documents provided:
| Document | What we extract |
|---|---|
| T&Cs / Sales Conditions | Platform operation, services offered, obligations |
| Order forms | Data collected, services, potential processors |
| Client exchanges | Key points, specific concerns, business particularities |
3. Additional research on the site (if accessible):
Note: Some sites only display a "Request a quote" form without access to the platform. In that case, rely primarily on the documents provided.
The objective is to understand the business AND identify technical elements:
- Understand what the company actually does
- Read the existing privacy policy (if present)
- Read the existing T&Cs/Legal notices
- Identify the typical user journey (if visible)
- Identify data collection forms (registration, contact, order...)
- Spot cookies/trackers via the banner
- List features (account, newsletter, chat, payment...)
4. Summary before drafting:
CLIENT: [Name]
BUSINESS: [Description in 2-3 sentences]
PLATFORM TYPE: [SaaS, e-commerce, mobile app, etc.]
USER JOURNEY: [Key steps]
DATA COLLECTED: [List by collection point]
COOKIES IDENTIFIED: [Types of cookies spotted]
FORMS: [List of collection points]
KEY LAWYER POINTS: [What must absolutely be included]
SPECIFICITIES: [What makes this case particular]Once the summary is ready → Proceed to Draft 1
核心目标:真正了解客户的业务内容、平台用户旅程。
1. 向律师索要可用信息:
"To draft a perfectly tailored policy, please provide:
- Information you have about the client and their business
- Existing documents (T&Cs, sales conditions, order forms, contracts...)
- Exchanges or key points raised by the client
- The site/application URL (if accessible)
- Points that must absolutely be included according to you
You may anonymize this information if necessary for confidentiality reasons.
The more information you provide, the better adapted the policy will be to the actual case. Otherwise, we will conduct our own research but it will be limited to publicly accessible information."2. 分析提供的文档:
| 文档 | 提取内容 |
|---|---|
| 条款/销售条件 | 平台运营方式、提供的服务、各方义务 |
| 订单表单 | 收集的数据、服务内容、潜在处理商 |
| 与客户的沟通记录 | 核心要点、客户特别关注的问题、业务特殊性 |
3. 对网站进行额外分析(若可访问):
注意:部分网站仅显示“请求报价”表单,无法访问平台核心内容。这种情况下,优先依赖提供的文档。
目标是理解业务并识别技术要素:
- 了解公司实际业务内容
- 阅读现有隐私政策(若存在)
- 阅读现有条款/法律声明
- 识别典型用户旅程(若可见)
- 识别数据收集表单(注册、联系、订单等)
- 通过弹窗识别Cookie/追踪器
- 列出功能模块(账户、新闻通讯、聊天、支付等)
4. 撰写前的总结:
CLIENT: [Name]
BUSINESS: [Description in 2-3 sentences]
PLATFORM TYPE: [SaaS, e-commerce, mobile app, etc.]
USER JOURNEY: [Key steps]
DATA COLLECTED: [List by collection point]
COOKIES IDENTIFIED: [Types of cookies spotted]
FORMS: [List of collection points]
KEY LAWYER POINTS: [What must absolutely be included]
SPECIFICITIES: [What makes this case particular]总结完成后 → 开始撰写第一版草稿
Step 3: Draft 1
步骤3:第一版草稿
ABSOLUTE RULE: The template is your validated base.
- START from the template: structure, wording, tone → this is your reference
- ADAPT to the client case: integrate the specific information collected
- DO NOT rewrite everything: keep the template wording, only adapt what needs to be
In summary: Template + client information = Draft 1. Not a complete rewrite.
Complete the template section by section with the collected information:
- Identity of the data controller
- Data collected (by category)
- Purposes and legal bases (table)
- Recipients and processors
- International transfers
- Retention periods (table)
- Data subject rights
- How to exercise rights
- Cookies and trackers
- Data security
- Policy changes
- Contact
Immediate compliance check: Before presenting Draft 1, verify the mandatory disclosures checklist (Art. 13 GDPR):
- Controller identity and contact details
- DPO contact details (if appointed)
- Processing purposes
- Legal basis for each purpose
- Legitimate interests pursued (if applicable)
- Recipients or categories of recipients
- Transfers outside EU and safeguards
- Retention period or criteria for determination
- Data subject rights (access, rectification, erasure, restriction, portability, objection)
- Right to withdraw consent (if applicable)
- Right to lodge a complaint with the CNIL
- Whether data provision is mandatory/optional
- Existence of automated decision-making (if applicable)
If Draft 1 is compliant → Proceed to Step 3.
绝对规则:模板为已验证的核心依据。
- 从模板出发:结构、措辞、语气均以模板为参考
- 适配客户场景:整合收集到的客户特定信息
- 不得全盘重写:保留模板措辞,仅调整必要内容
总结:模板 + 客户信息 = 第一版草稿,而非完全重写。
逐节用收集到的信息填充模板:
- 数据控制方身份
- 收集的数据(按类别划分)
- 处理目的与合法依据(表格)
- 接收方与处理商
- 国际数据传输
- 数据保留期限(表格)
- 数据主体权利
- 权利行使方式
- Cookie与追踪器
- 数据安全
- 政策变更
- 联系方式
即时合规检查:提交第一版草稿前,验证GDPR第13条强制披露清单是否完整:
- 控制方身份与联系方式
- DPO联系方式(若已任命)
- 处理目的
- 每项目的对应的合法依据
- 追求的合法利益(若适用)
- 接收方或接收方类别
- 欧盟外数据传输及保障措施
- 保留期限或期限判定标准
- 数据主体权利(访问、更正、删除、限制处理、数据可携、反对)
- 撤回同意的权利(若适用)
- 向CNIL投诉的权利
- 数据提供是否为强制性/可选
- 自动化决策的存在(若适用)
若第一版草稿合规 → 进入步骤3。
Step 4: Deliver Draft 1 + Benchmark + Improvement Suggestions
步骤4:提交第一版草稿 + 基准对比 + 改进建议
1. Deliver Draft 1 with explanation:
Here is Draft 1 of the privacy policy.
**What I took into account:**
- [Summary of key elements integrated]
- [Client specificities considered]
- [Particular points mentioned by the lawyer]
**Compliance:** The document meets Art. 13 GDPR requirements.2. Present the benchmark (systematic):
Research 3-5 privacy policies from companies in the same sector, then present:
**Benchmark conducted:**
I analyzed the privacy policies of:
- [Company 1] - [what we noted]
- [Company 2] - [what we noted]
- [Company 3] - [what we noted]
**Identified possible improvements:**
- [Improvement 1]: [explanation]
- [Improvement 2]: [explanation]
- [Improvement 3]: [explanation]
Would you like to incorporate these elements into the provided Draft?3. If the lawyer approves improvements → Produce Draft 2.
1. 提交第一版草稿并说明:
Here is Draft 1 of the privacy policy.
**What I took into account:**
- [Summary of key elements integrated]
- [Client specificities considered]
- [Particular points mentioned by the lawyer]
**Compliance:** The document meets Art. 13 GDPR requirements.2. 展示基准对比(强制要求):
调研3-5家同行业公司的隐私政策,然后说明:
**Benchmark conducted:**
I analyzed the privacy policies of:
- [Company 1] - [what we noted]
- [Company 2] - [what we noted]
- [Company 3] - [what we noted]
**Identified possible improvements:**
- [Improvement 1]: [explanation]
- [Improvement 2]: [explanation]
- [Improvement 3]: [explanation]
Would you like to incorporate these elements into the provided Draft?3. 若律师认可改进建议 → 生成第二版草稿。
Step 5: Final Verification
步骤5:最终验证
Final review before definitive delivery:
- All Art. 13 GDPR disclosures present
- Client information correctly integrated
- Clear and accessible language
- No internal references (template, sources) in final document
- Update date present
正式交付前的最终审核:
- GDPR第13条所有披露内容齐全
- 客户信息整合正确
- 语言清晰易懂
- 最终文档中无内部参考(模板、来源)
- 包含更新日期
Standard Policy Structure
标准政策结构
PRIVACY POLICY
[Company Name]
Last updated: [DATE]
TABLE OF CONTENTS (if long document)
1. WHO ARE WE?
- Controller identity
- DPO contact details
2. WHAT DATA DO WE COLLECT?
- Identification data
- Browsing data
- Transaction data
- Etc.
3. WHY DO WE COLLECT YOUR DATA?
- Purposes / legal bases table
4. WITH WHOM DO WE SHARE YOUR DATA?
- Internal services
- Processors
- Partners (if consent)
- Authorities (legal obligations)
5. IS YOUR DATA TRANSFERRED OUTSIDE THE EU?
- Countries concerned
- Safeguards
6. HOW LONG DO WE KEEP YOUR DATA?
- Retention periods table by data type
7. WHAT ARE YOUR RIGHTS?
- List of rights with simple explanation
- How to exercise them
8. COOKIES AND TRACKERS
- Types of cookies used
- Preference management
9. SECURITY
- Measures in place (without sensitive technical details)
10. CHANGES TO THIS POLICY
- Notification procedure
11. CONTACT US
- Email
- Postal address
- Link to formPRIVACY POLICY
[Company Name]
Last updated: [DATE]
TABLE OF CONTENTS (if long document)
1. WHO ARE WE?
- Controller identity
- DPO contact details
2. WHAT DATA DO WE COLLECT?
- Identification data
- Browsing data
- Transaction data
- Etc.
3. WHY DO WE COLLECT YOUR DATA?
- Purposes / legal bases table
4. WITH WHOM DO WE SHARE YOUR DATA?
- Internal services
- Processors
- Partners (if consent)
- Authorities (legal obligations)
5. IS YOUR DATA TRANSFERRED OUTSIDE THE EU?
- Countries concerned
- Safeguards
6. HOW LONG DO WE KEEP YOUR DATA?
- Retention periods table by data type
7. WHAT ARE YOUR RIGHTS?
- List of rights with simple explanation
- How to exercise them
8. COOKIES AND TRACKERS
- Types of cookies used
- Preference management
9. SECURITY
- Measures in place (without sensitive technical details)
10. CHANGES TO THIS POLICY
- Notification procedure
11. CONTACT US
- Email
- Postal address
- Link to formDrafting Best Practices
撰写最佳实践
Writing Style
写作风格
| Do | Avoid |
|---|---|
| Use "you" / "your data" | Use "the user" / "the data subject" |
| Short and simple sentences | Excessive legal jargon |
| Concrete examples | Vague wording ("various data") |
| Tables for clarity | Dense paragraphs |
| Clear and explicit headings | Multiple cross-references without explanation |
| 建议做法 | 避免做法 |
|---|---|
| 使用“您”/“您的数据” | 使用“用户”/“数据主体” |
| 短句、简单句 | 过度使用法律术语 |
| 具体示例 | 模糊表述(如“各类数据”) |
| 用表格提升清晰度 | 密集段落 |
| 清晰明确的标题 | 大量交叉引用但无说明 |
Accessibility
易访问性
- Clear language: understandable by a non-lawyer user
- Visible structure: table of contents, numbered headings
- Layered information: summary + details if needed
- Update date: visible at top of document
- 语言清晰:非法律从业者也能理解
- 结构清晰:目录、编号标题
- 分层信息:摘要 + 详细内容(若需)
- 更新日期:显示在文档顶部
Common Mistakes to Avoid
需避免的常见错误
| Mistake | Consequence | Solution |
|---|---|---|
| Copy-paste from generic template | Non-compliance, inconsistency | Adapt to each case |
| Incorrect legal bases | Unlawful processing | Analyze each purpose |
| Missing retention periods | Non-compliance Art. 13 | Systematic table |
| Forgetting transfers outside EU | Potential fine | Check processors |
| Rights mentioned without procedures | Rights unexercisable | Dedicated email address |
| Cookie wall | Prohibited by CNIL | Refusing as easy as accepting |
| 错误 | 后果 | 解决方案 |
|---|---|---|
| 直接复制通用模板 | 不合规、内容不一致 | 针对每个场景调整模板 |
| 合法依据错误 | 处理行为违法 | 针对每项目的进行分析 |
| 遗漏保留期限 | 违反第13条要求 | 统一使用保留期限表格 |
| 忽略欧盟外数据传输 | 可能面临罚款 | 核查所有处理商 |
| 仅提及权利但未说明行使流程 | 权利无法实际行使 | 提供专用联系邮箱 |
| Cookie墙 | 被CNIL禁止 | 拒绝Cookie需与接受同样便捷 |
CNIL Reference Sanctions
CNIL参考处罚案例
| Company | Amount | Main Reason |
|---|---|---|
| €150M | Cookies: refusing more difficult than accepting | |
| €60M | Cookies: no "reject all" button | |
| Carrefour | €3M | Insufficient information, excessive retention |
| Amazon | €35M | Cookies placed without consent |
These sanctions illustrate the importance of a compliant policy and rigorous cookie management.
| 公司 | 罚款金额 | 主要原因 |
|---|---|---|
| 1500万欧元 | Cookie:拒绝操作比接受更复杂 | |
| 600万欧元 | Cookie:无“全部拒绝”按钮 | |
| Carrefour | 30万欧元 | 信息披露不足、保留期限过长 |
| Amazon | 350万欧元 | 未经同意设置Cookie |
这些处罚案例表明,合规的隐私政策与严谨的Cookie管理至关重要。
Frequently Asked Questions
常见问题
1. Must the policy be in French?
1. 政策必须用法语撰写吗?
Yes, if the site targets French users. It can be bilingual if the site is international.
是的,若网站面向法国用户。若为国际网站,可提供双语版本。
2. Is a separate policy needed for the mobile app?
2. 移动应用需要单独的隐私政策吗?
Not necessarily, but the policy must cover app-specific aspects (permissions, data collected by the device).
不一定,但政策必须覆盖应用特有的内容(权限、设备收集的数据)。
3. How to handle updates?
3. 如何处理政策更新?
- Date each version
- Inform users of substantial changes
- Keep previous versions
- 为每个版本标注日期
- 向用户通知重大变更
- 保留历史版本
4. Is a DPO mandatory?
4. 必须任命DPO吗?
Not systematically. Mandatory if:
- Public authority
- Large-scale processing of sensitive data
- Regular and systematic large-scale monitoring
并非强制。仅在以下情况需要:
- 公共机构
- 大规模处理敏感数据
- 定期、系统性地大规模监控
Using This Guide
本指南使用流程
- Step 1 - Choose the template: Default, or lawyer's internal template
- Step 2 - Understand the business: Collect lawyer docs + site research
- Step 3 - Draft Draft 1: Complete template + compliance check
- Step 4 - Deliver + Benchmark: Present Draft 1 + systematic benchmark + improvement suggestions
- Step 5 - Finalize: Integrate approved improvements + final verification
TEMPLATE REMINDER: Never draft from scratch. Always start from the template and adapt it.SOURCES REMINDER: The CNIL and GDPR references in this guide are for the drafter. They should not appear in the final document, except for mandatory legal disclosures (right to lodge a complaint with CNIL, etc.).
- 步骤1 - 选择模板:默认模板或律师提供的内部模板
- 步骤2 - 理解业务:收集律师提供的文档 + 网站调研
- 步骤3 - 撰写第一版草稿:填充模板 + 合规检查
- 步骤4 - 提交 + 基准对比:提交第一版草稿 + 系统性基准对比 + 改进建议
- 步骤5 - 最终定稿:整合获批的改进内容 + 最终验证
模板提醒:禁止从零开始撰写,必须从模板出发进行调整。来源提醒:本指南中的CNIL与GDPR参考内容仅供撰写者使用,最终文档中不得包含这些内部参考,仅需保留强制法律披露内容(如向CNIL投诉的权利等)。",