forumNew topic

Transparency and privacy notices under KVKK and RGPD: where do we start from scratch?

HHüsniye A***Veteran
Job title
Graphic Designer
Sector
Packaging
Organization type
40-person manufacturing company
Joined
Feb 2025
Message
137
#1

We provide corporate event and catering services based in Lyon. We have a core team of 4 and an annual revenue of around 260,000 EUR. Our clientele includes local French businesses as well as organizations with ties to Turkey. Over time, through quote forms, email exchanges, and WhatsApp, we've gathered names, phone numbers, company names, and even dietary or allergy requirements from hundreds of corporate reps and attendees.

Last week, an international corporate client asked for our privacy notice, a summary of our data processing inventory, and a transparency compliance report before signing. That's when we realized we have nothing official on our site besides a generic two-paragraph privacy policy copied and pasted off the web in a rush.

Given RGPD in France and our touchpoints with Turkey under KVKK, how should we build this process from the ground up to be fully compliant? What sections are mandatory in a privacy notice, at what touchpoints must we present them to clients, and how do we determine data retention periods?

CCansu P***MemberCommunity member
Joined
Mar 2024
Message
237
Most Helpful#2

Short answer: The duty to inform isn't just sticking a generic privacy policy in your footer; you must clearly tell individuals across every collection channel what data you process, for what purpose, on what legal basis, and for how long. Starting from scratch, boilerplate templates won't protect you legally—you need to begin with a basic data mapping inventory.

Your first step is data mapping. Build a spreadsheet listing what data (name, phone, email, dietary/health info) you collect and through which channel (web form, WhatsApp, contracts). Legally, your privacy notice must include: the data controller's legal identity and address, processing purposes, who data is shared with and why, collection methods, the legal basis for processing, and data subjects' statutory rights.

To meet transparency standards, use a layered notice approach: 1) Place a concise 1-2 sentence notice right below website quote/contact forms with a direct link to the full policy. 2) When quoting via WhatsApp or email, include a brief disclosure sentence and a privacy link in your opening response. 3) Add a standard data protection clause to your commercial service agreements.

You cannot arbitrarily determine retention periods; they must be based on statutory limitation periods. For instance, while accounting and invoicing records must be retained for 10 years under French legislation, data of prospective clients that remained at the proposal stage and did not convert into a contract should be kept for a maximum of 3 years and then deleted or anonymized. As for special category health data such as allergies and dietary restrictions, you must retain them only until the event is concluded and destroy them immediately thereafter.

RRecep S***MemberCommunity member
Joined
May 2025
Message
342
#3

The biggest misconception is confusing the privacy notice with explicit consent. A privacy notice is not a consent-seeking document; it is a notification telling the other party, 'I process your data under these rules.' Therefore, putting an 'I have read and agree' checkbox under the text is legally incorrect; it simply needs to be accessible.

DDoruk G***New memberCommunity member
Joined
Jun 2026
Message
8
#4

You mentioned collecting allergy information, which is a critical point. Under both KVKK and RGPD, health and dietary sensitivities are considered special category personal data. Merely providing a general privacy notice is not sufficient to process this data; you must obtain explicit consent, limit the retention period to the event itself, and keep it encrypted in your database.

TTuğçe C***Expert
Job title
Human Resources Specialist
Sector
Law
Organization type
40-person manufacturing company
Joined
Feb 2023
Message
185
#5

Something you can easily do first thing tomorrow: instead of a checkbox below the quote request form on your website, add a link that reads, 'By submitting this form, you acknowledge that you have reviewed the Personal Data Processing Privacy Notice.' Until you draft the full text, you will at least have initiated the transparency step at the touchpoint.

edit: typed from phone, sorry for typos.

SSerkan Ç***VeteranCommunity member
Joined
May 2023
Message
294
#6

Are you storing data belonging to clients in Turkey on servers in France or is data from clients in France being transferred to Turkey? If there is a cross-border data transfer you are required to explain the recipient countries and legal safeguards under a separate heading in the privacy notice.

SSerdar K***Veteran
Job title
Growth marketing
Joined
May 2023
Message
264
#7

Don't trust online automatic policy generators. Most are translations of 'privacy policies' drafted under American law. Neither the supervisory authority in France nor your corporate client's legal department will accept those templates. You really need to write a simple text tailored specifically to your operation.

GGizem E***Veteran
Job title
Social media manager
Sector
Food wholesale
Organization type
sole proprietorship
Joined
Sep 2024
Message
161
#8

As a legal entity operating in France, your primary obligation is compliance with RGPD and CNIL regulations. Under the law, you must explicitly state a dedicated email address in the privacy notice where data subjects can submit requests to exercise their rights of erasure, rectification, and access.

ÖÖmer B***MemberCommunity member
Joined
Dec 2022
Message
55
#9

When starting from scratch, follow these three steps: 1) Create a one-page inventory table categorizing collected data by purpose, 2) Draft a plain-language, layered privacy notice based on this inventory, 3) Permanently place a link to the notice at the bottom of forms and proposal PDFs.

FFerhat A***Member
Job title
Co-founder
Sector
IT services
Organization type
family business
Joined
Aug 2023
Message
3

Doki · Server maintenance contract · 2024

#10

Don't let it overwhelm you at all. Corporate clients usually just want to see that you take the matter seriously. Once you have a basic notice in place and set sensible retention periods you'll pass their audit with no problem.

KKorhanExpert
Job title
B2B Sales Manager
Joined
Sep 2023
Message
162
#11

I agree with this. Mistakes made on the kvkk transparency privacy notice side are usually reversible but expensive.

FFiliz S***Member
Job title
Software developer
Sector
Printing
Organization type
early-stage startup
Joined
Apr 2026
Message
129
#12

We need to take it step by step. When you try to change everything at once, nothing settles.

BBuseNew member
Job title
Fashion blogger
Organization type
early-stage startup
Joined
Sep 2024
Message
48
#13

you're right. an automated scan report is not the same as a penetration test.

proven by experience.

EElvanNew member
Job title
Dental clinic
Organization type
cooperative
Joined
Sep 2024
Message
40
#14

This thread is archived.

TTaner Ö***ExpertCommunity member
Joined
Mar 2024
Message
16
#15

I agree with this. If permission and scope aren't in writing, don't start that test.

Good luck with that.

LLeyla Y***MemberCommunity member
Joined
Mar 2026
Message
61
#16

Could you elaborate on that? Solutions that work at a small scale collapse when you grow; I learned this late.

When making decisions, write down the worst-case scenario too, not just the best. Hope this helps.

SSelçukMember
Job title
Sports club
Organization type
boutique agency
Joined
Jun 2024
Message
76
#17

quick summary for newcomers: The biggest time-waster for us was not knowwing who had the final say.

if it's your first time, start small; scaling comees later.. then honestly of course, it varies if your situation is different.

KKemal T***Member
Job title
Accounting clerk
Sector
Accounting & advisory
Organization type
8-person team
Joined
Jan 2025
Message
347
#18

This is exactly what we experienced. The harder it is to reverse a decision the slower you should make it.

Proven by experience.

OOrhan T***MemberCommunity member
Joined
Mar 2024
Message
242
#19

I was thinking the same thing. Everything goes well for the first three months; problems arise in the fourth.

Don't hesitate to ask; those who don't ask always pay more. If you post the result here, it will help others too.

GGökhan D***Member
Job title
System administrator
Sector
Retail
Organization type
300-person organization
Joined
Dec 2024
Message
5
#20

i'm curious too.

Reply