Do you need to update your website’s terms and conditions to comply with the GDPR?

No – the GDPR doesn’t directly regulate your terms and conditions, but you should make a few adjustments once you’ve updated your privacy policy. The GDPR concerns privacy law: privacy policies are central to it, but your terms and conditions aren’t. What you do need to check is that the two documents are separate, that they refer to each other correctly, and that any terms about minors match the GDPR’s rules.

The main aim of the EU’s General Data Protection Regulation (GDPR) is to strengthen internet users’ rights and improve the security of their personal data, change how businesses handle personal data, and require new ways of informing users. Privacy policies are the foundation for making sure both your site and your users know their privacy rights – and that you’re working to protect them.

What are terms and conditions?

Terms and conditions are a set of rules and disclaimers that visitors must follow when they use your website. Their main purpose is to protect you and your business by requiring users to follow certain rules if they want to use the services you offer.

They can also be called terms of use, terms of service, general terms or similar – the terms are interchangeable and a matter of preference.

What should a GDPR-compliant agreement include?

Terms and conditions are an optional legal agreement setting out rules for correct use of your services and disclaimers to protect you from legal disputes.

They’re your responsibility and in your own interest. They include disclaimers about payments and subscriptions, limitations of liability, and rules of conduct to ensure correct use of the site, a product or a service. The rules give you the right to suspend users who misuse the service, protect you from unfounded legal action, and help you prove payment procedures in a dispute.

Such rules are a good idea, but they aren’t covered by the privacy law the GDPR regulates. Even so, some adjustments should be made:

  • The GDPR requires your privacy policy to be separate from, and independent of, your terms and conditions. The two documents should refer to each other and can link to each other.
  • When you update your privacy policy for GDPR compliance, update any links to it from your terms and conditions.
  • Don’t refer to an old, non-compliant privacy policy in your terms. Check that every reference to the privacy policy in your terms is up to date and consistent in both documents.

The GDPR doesn’t require consent to terms and conditions in the same way as for privacy policies, but it’s still a good idea to get it. For example, the cookie consent banner you use to get consent to data collection and acceptance of your privacy policy can also include a link to your terms.

If you ever need to enforce your terms in court, you’ll then have clear evidence that the user agreed to be bound by them.

If your terms include rules about minors using the site – for example that minors need a guardian’s consent before using the site or creating an account – you may need to change them, since the GDPR has its own rules for collecting and processing minors’ personal data. Adjust the relevant sections of your terms to reflect any policy changes.

Important: this article isn’t a substitute for legal advice. We strongly recommend reviewing your terms and conditions after you’ve updated your privacy policy and become GDPR compliant.

Was this article helpful?

Related Articles