GDPR Templates

These GDPR templates provide practical starting points for documenting how an organisation handles personal data. The collection includes common records and agreements used for transparency, data-subject rights, controller and processor relationships, security incidents, retention, processing inventories, and data-protection impact assessments.

Choose documents by mapping real processing first: whose data you hold, why you use it, your lawful basis, where it comes from, who receives it, where it is stored or transferred, how long it is retained, and which technical and organisational measures protect it. Medical-device companies should clearly separate clinical-investigation, vigilance, customer, employee, website, and device-generated data flows; they may involve different roles and legal bases.

Templates are not proof of GDPR compliance and are not legal advice. Adapt them to the facts, applicable EU and national law, and agreements with customers, sites, investigators, cloud providers, and other processors. A privacy notice must describe actual processing, and a signed data-processing agreement cannot repair an unlawful or insecure workflow. Have qualified counsel or a data-protection professional review high-risk processing, international transfers, research, and DPIA conclusions.

View on GitHub

Load GDPR Templates into Formwork.

Formwork includes these templates already, organized as a live QMS pack with AI assistance and connected records.

Start from the whole pack instead of downloading files one by one.

Got questions? Reach out any time, we’re happy to help.