Skip to content
+370 5 212 1506 info@dat.lt

Privacy policy: is it mandatory and when must it be updated?

24 September 2026 · Good to know

The law does not require a document called a “privacy policy”. It requires something else: you must inform people when you collect their data. Article 13(1) GDPR says the information is given at the time the data are obtained, and Article 12(1) GDPR says it must be concise, transparent, intelligible and easily accessible. If the website collects any data at all — through a form, an account or an analytics tool — a public text is in practice the only way to meet this duty. That text is what we call a privacy policy.

It needs updating not by the calendar, but when what you do with the data changes: a new purpose, a new recipient, a new tool, or a transfer of data outside the European Economic Area (EEA). Our partners at Privacio (in Lithuanian) explain step by step how to write such a text. Here we cover what the law requires, when the text goes out of date and what that means legally.

What the law actually requires

Article 5(1)(a) GDPR requires data to be processed lawfully, fairly and in a transparent manner. Article 5(2) GDPR adds accountability: an organisation must not only follow the principles but also be able to prove that it does. The privacy policy is the first piece of evidence that both the individual and the supervisory authority will see.

Two articles set the content. When you collect data from the person, Article 13 GDPR applies. You must state, among other things, who you are and how to contact you, the purposes and legal basis of the processing, the recipients or categories of recipients (Article 13(1)(e) GDPR) and whether you intend to transfer the data to a third country (Article 13(1)(f) GDPR). You must also state how long you will keep the data or the criteria used to decide this (Article 13(2)(a) GDPR), and that the person has the right to lodge a complaint with a supervisory authority (Article 13(2)(d) GDPR). The full list of mandatory information is in Article 13(1) and (2) GDPR. It also covers the person’s rights, withdrawal of consent where processing is based on consent, and automated decisions where there are any.

When you obtain data from someone other than the person — a partner, a register or a public source — Article 14 GDPR applies. The information must be given within a reasonable period, and at the latest within one month (Article 14(3)(a) GDPR). If you use the data to contact the person or disclose them to someone else, it must be given at the latest at the first contact (Article 14(3)(b) GDPR) or the first disclosure (Article 14(3)(c) GDPR).

The Regulation uses the word “policy” only for internal documents. Article 24(2) GDPR refers to an internal data protection policy that the organisation implements where proportionate. That is a set of internal rules for staff, not a text for website visitors. One document does not replace the other. What employees must be told, and when, is covered in Informing employees about data processing: what to say and when.

Whose policy covers which data

A privacy policy covers only the data for which you are the controller. The controller is whoever determines the purposes and means of the processing (Article 4(7) GDPR). Whoever processes data on someone else’s behalf is a processor (Article 4(8) GDPR).

Does an IT system developer’s privacy policy also do for the companies using the system it built? No. A company that processes its own employees’ or customers’ data in the system decides the purposes itself, so it is the controller and informs its own people. The system’s developer is usually a processor towards it, and the relationship between them must be set out in a contract whose content is laid down in Article 28(3) GDPR. The developer’s privacy policy stays about its own data: its customers’ contact persons, website visitors, invoices.

The same principle applies internally. A website text may not cover employees, job candidates or video surveillance. These people must be informed separately, in a way they can understand.

When the policy must be updated

A new purpose. If you intend to use data you already hold for a different purpose, you must tell people before you start (Article 13(3) GDPR; where the data were not obtained from the person, Article 14(4) GDPR). This is the only case in which the Regulation itself sets the timing of an update. But notice does not make the new purpose lawful. If the new purpose is not based on the person’s consent or on a law that provides for such processing as a necessary and proportionate measure, you must first assess whether it is compatible with the purpose for which the data were collected (Article 6(4) GDPR).

A new tool on the website. One client asked whether a quiz or a virtual assistant needs its own privacy policy. The same question arises for a calculator. Usually not: no separate policy is needed, but the existing policy and cookie notice must be updated: what data the tool collects, for what purpose, on what basis and how long you keep it. At the same time, check that there is a contract with the tool’s provider that meets Article 28(3) GDPR. If the same tool runs on several websites, the policy of each website is updated.

A new recipient or service provider. The policy must name the recipients or categories of recipients (Article 13(1)(e) GDPR). A new accounting, advertising or customer service system can mean a new category of recipient.

Transfers outside the EEA. If a new provider stores or accesses the data from a third country, this must be stated, together with whether there is a Commission adequacy decision and, if not, which safeguards apply (Article 13(1)(f) GDPR).

Changed retention periods. The period in the policy and the period actually applied must match (Article 13(2)(a) GDPR).

The general rule is Article 24(1) GDPR: measures are reviewed and updated where necessary. The Article 29 Working Party Guidelines on transparency (WP260 rev.01), endorsed by the European Data Protection Board, state that people should always be told about a change of processing purpose, a change of controller and a change in how they can exercise their rights. Correcting spelling mistakes is not a material change. Where a change fundamentally alters the processing, for example by widening the recipients or introducing a transfer to a third country, the guidelines say people should be told well in advance and in a clear way — by email or a notice on the website, not together with marketing.

What can go wrong

Someone else’s template. The text describes another company’s processing, not yours. Formally a document exists, but it says nothing about what you actually do.

Lists that do not match reality. The policy names three recipients, while ten providers actually have access to the data. A video surveillance system that is running is not mentioned. We explained why documents are written only after the real processes have been examined in our article on the GDPR document package.

No retention periods. “We keep data for as long as necessary” is neither a period nor a criterion. How to justify a period is covered in our article how long to keep personal data.

Cookies confused with the privacy policy. These are two different duties. Article 73(4) of the Law on Electronic Communications (ERĮ) allows information to be stored on, or accessed from, a person’s device only with their consent, except where this is needed solely to transmit the communication or to provide a service the person has requested. A text in the policy does not create consent. Consent must be obtained by a separate action, before non-essential cookies are switched on. When consent is valid, and when it is not, is covered in Consent under the GDPR: when you need it and when it is invalid. When cookies need consent and how a consent banner is judged is covered in Cookies and consent banners: what the ERĮ and the GDPR require.

The sentence “please check this policy regularly”. The WP260 guidelines regard such a statement as insufficient and unfair under Article 5(1)(a) GDPR.

The consequences are legal, not only reputational. The duty to inform is part of Articles 12–14 GDPR, and for infringements of data subjects’ rights under Articles 12–22, Article 83(5)(b) GDPR provides for an administrative fine of up to 20 million euros or, for an undertaking, up to 4 % of total worldwide annual turnover of the preceding financial year, whichever is higher. Lower caps apply to public authorities and bodies in Lithuania: for such an infringement, up to 1 per cent of their budget and other income, but no more than sixty thousand euros (Article 33(2) of the Law on Legal Protection of Personal Data, ADTAĮ), unless the body carries on an economic or commercial activity, in which case the general GDPR caps apply (Article 33(3) ADTAĮ). The supervisory authority can order processing to be brought into compliance within a set period (Article 58(2)(d) GDPR). A person who has suffered damage because of an infringement has the right to compensation (Article 82(1) GDPR). It can also start more simply: with a complaint or an enquiry in which someone compares what the policy says with what actually happens.

When to call a lawyer

Get in touch before you start new processing, not after. Typical cases:

  • you start using data for a new purpose, such as marketing, profiling or an artificial intelligence tool;
  • you are changing to a provider that processes or accesses data outside the EEA;
  • you are building a system for other companies and are not sure who is the controller and who is the processor;
  • there has been a reorganisation or merger, or the company acting as controller has changed;
  • you have received a complaint or a letter from VDAI quoting your policy.

Frequently asked questions

Does a small company whose website has only a contact form need a privacy policy?

Yes, if the form collects a name, an email address or a phone number. The duty to inform under Article 13 GDPR does not depend on the size of the company or the amount of data. The text can be short, but it must contain all the information in Article 13(1) and (2) GDPR that applies to your form: who collects the data, why, on what basis, who receives it, how long it is kept and what rights the person has.

Must customers be told about an updated privacy policy?

For material changes, yes. The WP260 guidelines say that a change of purpose, of controller or of how rights can be exercised should be announced actively, for example by email or a notice on the website, not just by changing the text. If you intend to use data for a new purpose, Article 13(3) GDPR requires you to tell people before you start.

Can the privacy policy be included in the website terms of use?

Better not. The WP260 guidelines say that information about data processing should be clearly separated from contract terms or terms of use, and that people should not have to search for it among other provisions. A separate, clearly labelled text with a link on every page of the website is the simplest way to meet this requirement.

Are the privacy policy and the cookie notice the same thing?

No. The privacy policy informs. For cookies, Article 73(4) of the Law on Electronic Communications requires both information and the person’s consent, except for cookies needed solely to transmit the communication or to provide a service the person has requested. Information about cookies can be given in the privacy policy, but consent must be obtained separately.

How to start

Send us your privacy policy and tell us which systems and service providers you use. We will compare what the text says with what you do and show where the two differ.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit and compliance documents.

Get a free assessment

Related articles