Personal data protection policy template for Word (free download)

Personal data protection policy template for Word (free download)
A personal data protection policy is the document in which a company explains, in its own words, what information it collects about people, what it uses that information for, who may look at it, how long it keeps it and how someone can ask to have it corrected or removed. It answers one very plain question: once a person hands over a piece of information, what happens to it afterwards?
The template you can download on this page is a Word file with the full structure of that policy: a document control table, purpose, scope, definitions, principles, purposes of processing, rights of the data subject, the channel for exercising them, security measures, processors and third parties, validity period and signatures. It arrives as an organised draft that you adapt to your own operation, not a text to sign without reading.
It is used at two moments in particular. The first is when a company starts putting its information in order: résumés, contracts, contact details of customers and suppliers, access logs, price and staff lists. The second is when somebody asks what happens to their data and there is no written answer. In both cases the sensible move is to have the policy approved before it is needed, rather than drafting it in a rush while a deadline runs.
It is written for small and mid-sized companies, warehouses, distributors and inventory departments where employee, customer and supplier data circulate without anyone having defined common rules. It also serves anyone who must account for that information during an internal audit or for a customer that requires such a document before signing.
⬇ Download personal data protection policy (.docx)What the policy covers and what it does not
The policy covers the ground rules: what information is collected, for what purpose, who may access it, how it is protected, how long it is kept and how a request to correct or remove data is handled. It is a framework document, so it does not go into the operating detail of each area.
It does not cover daily operations, which belong in separate documents: how permissions are assigned by role in the system, how backups are made, what is checked when somebody leaves the company and what is done when there is an incident. Nor does it replace the notice given to each person when their data is collected for a specific purpose, or the agreements with third parties that process information on the company's behalf.
And it does not replace your adviser. The policy sets commitments the company must be able to keep; if it promises more than the company does, the document becomes a liability instead of a defence. Write it with whoever knows the obligations that apply to your business, and review it whenever the operation changes.
What it is useful for
- It puts in writing what information is collected and why, so nobody has to answer from memory when a customer or an employee asks.
- It defines who may see each piece of data and from which role, which reduces informal access to customer lists, prices, suppliers and payroll.
- It sets a single channel for someone to ask to know, update, correct or remove their information, with an identified owner and a defined response time.
- It fixes retention and deletion rules, so the company does not keep information forever out of habit or out of fear of deleting it.
- It works as evidence in internal audits, customer reviews and supplier onboarding processes that ask for documented proof.
- It gives a common framework to new staff: the policy is handed over and explained, instead of improvised depending on who is on shift.
What the template includes
These are the real sections of the file, in the order they appear. The right-hand column summarises what goes in each one.
| Section | What goes in it |
|---|---|
| Document control | Code [PD-___], version, approval date and owner. This is what tells you which version is currently in force. |
| 1. Purpose | Why the policy exists and what it aims to protect, in a few lines. |
| 2. Scope | Which sites, areas, processes and information systems it applies to, and who is covered. |
| 3. Definitions | Data subject, personal data, sensitive data, processing and processor, explained in plain language. |
| 4. Principles | Purpose, necessity, accuracy, security, confidentiality and transparency, each with one sentence of practical application. |
| 5. Purposes | The concrete uses for which the company processes information: payroll, recruitment, invoicing, dispatches, marketing, security. |
| 6. Rights of the data subject | To know, to update and rectify, to ask for proof of consent, to request deletion, to withdraw consent and to file complaints. |
| 7. How to exercise those rights | The editable fields for contact channel, response time and the role of the person responsible. |
| 8. Security measures | The measures the company commits to maintaining on access, backups, devices, files and staff. |
| 9. Processors and third parties | Who processes data on the company's behalf and whether information is transferred outside the country. |
| 10. Validity | When it takes effect, how often it is reviewed and how changes are communicated to the teams. |
| Signatures and notice | Two approval signatures and the notice that the model is general and is not legal advice. |
How to fill it in, step by step
- Replace the company name in the header and footer, adjust the [PD-___] code to the numbering your company uses and delete the instruction notes left in the file.
- Write the purpose in two or three lines: what is protected and why. If it does not fit in three lines, the purpose is badly stated.
- Define the scope with real names: sites, areas, processes and information systems included. Whatever is not named stays out of the policy.
- Go through the list of purposes and remove the ones that do not apply. If the company does not run marketing with customer data, that purpose should not be written down.
- Adapt the principles with examples from your own operation: what necessity means when someone asks for one document too many, and what purpose means when someone wants to reuse a database for something else.
- Define the contact channel and the owner: a visible email address or form, with the role of the person who answers, not the name of someone who may leave next month.
- Write the retention and response times using values the company can actually meet; if in doubt, leave the field editable and check with your adviser.
- Mark on the security list which measures already exist and which are pending with a date, and describe how access is granted and withdrawn.
- Sign, version and communicate: register the approved version, publish it where staff can find it and keep a record of who received it.
The rights of the data subject, without jargon
The rights section is the one that generates the most questions. This table summarises what each right means in the daily life of a warehouse or an office:
| Right | What it means in practice |
|---|---|
| To know | A person may ask what data the company holds about them, why and since when. The answer uses the real information, not a vague summary. |
| To update and rectify | If a record is out of date or wrong, it is corrected and the correction is logged. |
| To ask for proof of consent | The company must be able to show how, when and for what the use of that information was authorised. |
| To request deletion | When the information is no longer needed or the relationship has ended, it is deleted, except for what the company must keep for its own operational reasons. |
| To withdraw consent | A person may withdraw permission for one specific purpose, such as advertising messages, without that affecting the basic commercial relationship. |
| To file complaints | There is a channel to raise a complaint and a written answer within a time the company defines and meets. |
Common mistakes before you approve it
- Copying another company's policy and leaving the other company's name in it: it happens more often than you would think and it undermines the whole document.
- Listing purposes the company does not actually carry out. Every purpose written down becomes a commitment you later have to explain.
- Promising security measures that do not exist, such as encrypted databases or daily backups nobody ever configured.
- Naming a contact channel that nobody really checks, or appointing an owner who rotates every few months.
- Leaving no trace of consent: the policy describes the right, but there is no evidence of how permission was actually given.
- Leaving the document unsigned, unversioned and undated, so nobody knows whether it is the current one or an old draft.
When it is worth moving to a system
The policy says what should happen with data; the system is what makes it happen without relying on memory. While the operation is small, with a handful of databases and few users, a Word policy and an orderly folder can be enough. Trouble starts as users, sites and transactions multiply: permissions get copied too widely, lists get exported without control and nobody can say with certainty who looked at what.
At that point you want permissions by role, a change history and records showing who made each movement and when. A tool such as Kardex Tauro helps precisely there: it leaves a trace of movements and users instead of relying on loose spreadsheets. It does not replace the policy, but it makes the policy verifiable, which is the difference between a document that gets filed and one that gets followed.
This model is general guidance, not legal advice
The template is a model for internal use, written to help put information in order and to leave rules in writing. It is not legal advice and does not replace review by a professional: the commitments the company takes on must match its real operation and what it can actually deliver.
Before approving and publishing it, review it with your adviser, adapt the editable fields to your case and check the timeframes, contact channels and security measures with the people who handle that information every day. A policy the company cannot keep is worse than having no policy at all.
⬇ Download personal data protection policy (.docx)