Data protection policy vs privacy policy: what each one covers
In short
A data protection policy is the internal document telling a company's own people what personal data they may collect, how long they may keep it, and what to do if something goes wrong. A public privacy policy is a different document, aimed at a website visitor. GDPR binds a company of any size on the core obligations, with only a narrow records-of-processing exemption under 250 employees. Ripe Leads' internal policy, IAP-1, is named here by clause.
On this page
- A data protection policy is not the same document as a privacy policy
- What GDPR actually requires of a company this size
- What belongs in an internal data protection policy
- What to check when someone hands you theirs
- What Ripe Leads' IAP-1 actually commits to
- How the policy stays current
- What this document does not prove
A data protection policy is not the same document as a privacy policy
A data protection policy is the internal document that tells a company's own director, employees and partners what personal data they may collect, how long they may keep it, and what to do if something goes wrong. A privacy policy is the public-facing document a website shows a visitor, explaining what happens to that visitor's own data. The two serve different readers and often sit at different addresses on the same website.
Ripe Leads publishes both, and they are not the same document. A public privacy policy tells a website visitor what data the company collects about them and why. The document this page is about, IAP-1, is the internal governance policy: the rules the company's own people follow when they handle a client's, a candidate's, or a partner's data, whether or not that person ever visits the website.
A procurement or compliance reader running vendor due diligence usually wants the internal one, because it is the document that shows whether a company actually has a process, rather than a page telling a visitor about their own rights.
"Information security policy" and "GDPR policy" are usually the same kind of document as IAP-1 under a different name: an internal statement of how data and systems are protected, not a public notice aimed at a customer.
What GDPR actually requires of a company this size
The General Data Protection Regulation binds a company of any size the moment it processes personal data, through core obligations that do not scale down for a small headcount: Article 5's principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation and accountability; Article 6's requirement to have a lawful basis for every processing activity; and Articles 13 and 14's duty to tell people what is done with their data.
Article 32 requires risk-based technical and organisational security measures, again regardless of size. Articles 33 and 34 set the breach rules: the supervisory authority must be told without undue delay, and where feasible within 72 hours, unless the breach is unlikely to risk anyone's rights; affected people must be told directly only where the breach is likely to cause them a high risk.
Article 30's records-of-processing duty carries a partial exemption for organisations under 250 employees, but the exemption does not apply where the processing is likely to risk people's rights, is not occasional, or involves special category or criminal-offence data. Most small companies process employee or customer data on an ongoing, non-occasional basis, which makes this exemption narrower in practice than the headline number suggests.
One neighbouring rule gets conflated with GDPR often enough to be worth separating out. Cookie consent and the confidentiality of electronic communications sit under the ePrivacy Directive, 2002/58/EC, as amended, not under GDPR itself, and the proposed ePrivacy Regulation that was meant to replace it was withdrawn. National laws implementing the 2002/58/EC Directive continue to govern cookie consent, so a data protection policy and a cookie banner answer to two different instruments and should not be written as though one covers the other.
What belongs in an internal data protection policy
A working policy states, in plain terms, what categories of personal data the company actually holds, not a generic list copied from a template. Business contact details, candidate data, correspondence and contract documents are typical categories for a small B2B company; special category data such as health or religious belief usually should not appear at all, and a policy that explicitly says so is easier to trust than one that stays silent on the point.
It should state a retention period for each category, in months or years, and what happens at the end of that period, deletion or anonymisation, rather than the phrase "as long as necessary."
It should name a response deadline for a data subject request and for an opt-out, and a route for reporting a suspected breach internally, since the 72-hour clock in Article 33 starts running the moment the company becomes aware, not the moment it finishes investigating.
It should also name its processors: the email provider, the CRM, the cloud storage, the accounting service, and state whether each has signed GDPR-compliant processing terms and, broadly, where the data actually sits.
What to check when someone hands you theirs
Check for a retention period stated in months, not a promise to delete data "when no longer needed." A specific number is a policy someone can actually be held to.
Check the breach notification clause for a stated deadline, ideally referencing the 72-hour figure GDPR sets for the supervisory authority, and check that it separately addresses when an affected person gets told directly, since that is a different, higher, threshold.
Check whether the policy names its data processors by category, or only says data is "processed securely" without saying which services actually hold it. A policy naming its email provider, CRM and cloud storage, and stating that each has signed Article 28 terms, is showing its work in a way a vague reference to "appropriate safeguards" does not.
Check the words "certified" or "verified." An information security policy is not the same as an ISO/IEC 27001 certificate, which is a specific, voluntary, independently audited standard. A policy that borrows the language of certification without naming a certificate number or an auditor is worth a direct follow-up question.
What Ripe Leads' IAP-1 actually commits to
Ripe Leads is the trading name of UAB "Kofi Tech." Its data protection policy, document code IAP-1, applies to the director, employees and partners working with the company's or its clients' data, and is written to the General Data Protection Regulation.
IAP-1 names its data categories directly: business contacts of client and prospect representatives (name, role, company, business email, phone), partner and candidate data needed for a contract or payment, and correspondence and contract documents. It states plainly that the company "processes no special category data."
Retention is stated by category: business contacts for 24 months from the last contact, absent a live contract, and candidate data for 6 months from the end of a selection process unless a longer period is agreed; contract and accounting records run for their statutory period, and each category is deleted or anonymised once its period ends. A data subject request is answered within 30 calendar days, and an opt-out is executed within 5 working days and added to a suppression list.
On security, IAP-1 commits to encrypted disks and screen locks, a password manager with a unique password per service, two-factor authentication wherever a service supports it, and a rule that secrets are never stored in source code or documents. Access follows least privilege and is revoked within 5 working days of a cooperation ending. A breach is reported to the director at once, who assesses the risk and notifies Lithuania's State Data Protection Inspectorate within 72 hours where a breach is likely, informing the affected person directly in a high-risk case. The full text sits at the IAP-1 document on the sustainability page, alongside the twelve other policies it cross-references.
How the policy stays current
IAP-1 sets its own review point: the director reviews the policy annually and approves any change by order. Training on it runs through EIP-1's module M3, which every partner completes within their first 30 days of signing a contract, covering GDPR basics for collecting contacts, opt-out handling, and honest claims.
The processor list behind IAP-1, the email, CRM, cloud storage and accounting services the company actually uses, is reviewed annually alongside the wider supplier review, and the policy states a preference for EU or EEA-based processors, with an adequacy decision or standard contractual clauses required for any transfer outside that area.
The document is published at kofitech.eu in plain HTML, alongside all thirteen documents in the same set, so a customer running due diligence can read the actual commitments rather than a summary of them.
What this document does not prove
IAP-1, and the other twelve documents in the same set, are self-authored and approved internally by UAB "Kofi Tech." They are not audited, certified or verified by any third party, and no sustainability label, badge or score is claimed anywhere in connection with them. From 27 September 2026, the Empowering Consumers Directive, (EU) 2024/825, bans a self-awarded sustainability label outright, one more reason these pages carry no badge.
A written commitment to encrypt disks and use two-factor authentication is not the same as an independent security audit confirming those controls are actually in place. A reader who needs that level of assurance should ask for it directly, because IAP-1 does not claim it.
Frequently asked
What is the difference between a data protection policy and a privacy policy?
Does GDPR apply to a small company with only a few employees?
What should a GDPR compliance statement actually include?
Does Ripe Leads have a data protection policy?
Is Ripe Leads' data protection policy independently certified?
Want the accounts behind these numbers?
Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.
Book a strategy call