The Dutch Data Protection Authority has released two new GDPR compliance templates designed specifically for small and mid-sized businesses, giving companies a simpler starting point for documenting their data practices and explaining them to customers.
The Autoriteit Persoonsgegevens, commonly known as the AP, announced the resources on September 3, 2026. The regulator published templates for two of the more basic, but frequently mishandled, pieces of GDPR compliance: a record of processing activities and a privacy notice.
The move follows complaints from Dutch businesses that GDPR compliance can create substantial administrative work, particularly for smaller organizations without dedicated privacy teams.
According to the AP, businesses specifically asked for ready-made documents that could serve as a foundation rather than requiring every company to build its compliance documentation from scratch.
The regulator developed the templates following discussions that included the Dutch Ministry of Economic Affairs and MKB-Nederland, which represents small and medium-sized businesses in the Netherlands.
What makes the release useful is that these are not simply blank forms.
The AP included example information for businesses operating across 10 industries: education, hospitality, retail, information technology, logistics, manufacturing, professional services, real estate, healthcare and construction.
Businesses can remove the examples that do not apply to them and fill in the details that reflect how they actually handle personal data.
A GDPR Record of Processing Activities Made for Smaller Companies
One of the two new resources is a template for maintaining a record of processing activities, often referred to as a ROPA.
A ROPA is essentially an internal map of how an organization processes personal information.
Depending on the organization, that might include customer names and addresses, employee information, payment data, marketing lists, account information, website data or copies of identification documents.
For many organizations subject to the GDPR, maintaining these records is an important compliance requirement.
But the value of a ROPA goes beyond checking a regulatory box.
A properly maintained processing register can answer basic questions that become surprisingly difficult when a company has never formally documented its data practices:
What personal information are we collecting?
Why are we collecting it?
Where does it come from?
Who receives it?
How long do we keep it?
What systems and vendors have access to it?
Those questions become especially important when something goes wrong.
If a company suffers a data breach, for example, an accurate processing inventory can help determine which categories of information were affected, where the information was stored and which individuals may need to be notified.
Without that documentation, privacy and security teams may first have to reconstruct their own data environment before they can fully investigate the incident.
The AP also points out that the information contained in a processing register can be reused elsewhere in a privacy program.
A company can draw from it when preparing its privacy notice, negotiating data processing agreements with vendors or responding to individuals exercising GDPR rights.
That makes the processing register less of a standalone compliance document and more of a foundation for other privacy obligations.
The European Union May Eventually Reduce the ROPA Requirement
The timing of the new template is interesting because the European Commission has also proposed reducing some of the GDPR recordkeeping burden on businesses.
Under proposals being considered at the European level, some organizations may eventually be required to maintain detailed processing registers only where their activities present a high risk to individuals.
The Dutch AP has previously expressed support for reducing unnecessary regulatory burdens, provided that doing so does not weaken protections for individuals.
For now, however, businesses should not assume that the requirement has disappeared.
The AP’s own decision to publish a new processing-register template reinforces a practical point: organizations still need to understand and document how personal information moves through their businesses.
Even if European lawmakers ultimately narrow the formal Article 30 documentation requirement, knowing where personal information resides remains fundamental to privacy compliance.
A company cannot reliably honor a deletion request, investigate a data breach or accurately describe its data practices if it does not know what data it possesses in the first place.
A New Privacy Notice Template
The AP’s second resource is a template for creating a GDPR privacy notice.
Privacy notices are familiar to almost every business with a website, but they remain one of the most common areas where compliance documents drift away from reality.
Under the GDPR, organizations must provide individuals with clear information about how their personal information is handled.
That generally includes information such as the categories of personal data being processed, the purposes of the processing, the organization’s legal basis, recipients of the data, retention periods, international transfers and the rights available to individuals.
The Dutch regulator’s template is intended to make that process easier for smaller organizations.
But the AP also makes an important point that companies sometimes miss: publishing a privacy policy in the footer of a website is not always enough.
Privacy information should be provided at the point where personal data is collected when appropriate.
If someone completes a contact form, for example, the organization should explain how the information entered into that form will be used and provide a clear link to additional information in the privacy notice.
The same principle can apply to account registration, newsletter subscriptions, job applications and other data-collection points.
Privacy disclosures work best when they are connected to the actual collection of the data rather than hidden several clicks away.
Templates Solve One Problem, but They Can Create Another
Regulator-created templates are useful, particularly for smaller companies trying to establish a privacy program without hiring a large compliance team.
But businesses should resist the temptation to treat them as fill-in-the-blank legal protection.
A privacy notice is only useful if it accurately describes what the organization does.
That sounds obvious, but privacy policies frequently contain language copied from templates, law firms or other businesses that no longer matches the underlying technology.
A company may say that it does not share information for advertising while its website sends identifiers to advertising platforms.
It may describe a limited set of cookies while dozens of additional technologies load through a tag manager.
It may identify several categories of service providers but omit analytics, session replay, chat, video, payment or marketing vendors that actually receive user information.
This is where documentation and technical privacy compliance have to meet.
A regulator can provide an excellent privacy notice template. It cannot automatically determine which JavaScript tags are firing on a company’s website, what information is being transmitted to third parties or whether the business has changed its technology stack since the policy was last updated.
That work still belongs to the organization.
Privacy Documentation Should Follow the Data
The AP’s release is a useful reminder of how privacy compliance should be approached.
Start with the data.
Identify what information the organization collects. Map the systems where it is stored. Determine why it is processed. Identify the vendors receiving it. Document retention periods. Determine the applicable legal basis. Then build the privacy notice and other compliance documentation around those facts.
Doing it in the opposite direction creates problems.
Writing a privacy policy first and then assuming the business behaves according to the document can produce a significant gap between policy and practice.
That gap is increasingly easy for regulators, plaintiffs’ attorneys and privacy researchers to identify because website data flows can be tested directly.
Cookie scanners, browser developer tools, network analysis and automated privacy testing can reveal what happens on a website regardless of what its privacy notice claims.
For businesses operating internationally, the problem becomes more complicated because GDPR disclosures are only part of the picture. A website may also need to account for U.S. state privacy laws, cookie consent requirements, Global Privacy Control signals, advertising opt-outs and sector-specific obligations.
The document therefore cannot remain static while the technology changes around it.
A Practical Step From the Dutch Regulator
Privacy regulators are often associated with investigations and fines. This release takes a different approach.
The Dutch AP is attempting to reduce the practical friction involved in complying with the GDPR by giving smaller businesses a regulator-created starting point.
Companies operating in the Netherlands, or those simply looking for a structured GDPR reference, can download both documents directly from the regulator:
Both were released as editable Word documents.
For smaller businesses that have never formally documented their processing activities, the templates provide a sensible place to begin.
The more important task comes afterward.
Companies still need to verify that the documents match what is actually happening across their websites, applications, vendors and internal systems. A privacy notice written from a template can explain a company’s data practices.
It cannot discover them.