privacytemplate

Templates / Policies

WordGDPR

Information Security Policy (GDPR)

A Word information-security policy that you align with your controls and GDPR security duties. Name your tools and owners. It does not implement those controls.

€34.95

No VAT is charged because PrivacyTemplate uses the Dutch Small Businesses Scheme (KOR).

  • Instant download
  • 30-day refund
  • Not legal advice
Preview this template
File name
Information-Security-Policy-GDPR-2rbnpu.docx
Format
Word
Opens with
Microsoft Word or another editor that opens .docx
Jurisdiction / regulations named
GDPR
Last catalog update
7 Sept 2026
What you must still do
Put the file on your letterhead, name your tools and roles, and have qualified counsel review it for your processing. These materials are not legal advice and do not certify compliance.
Who it's for
Privacy, HR, and IT teams who need a starting policy they can tailor to their organization.

More in Policies · Also see Forms

Information Security Policy (GDPR)

Preview

Sample pages

English. Word file (Information-Security-Policy-GDPR-2rbnpu.docx). Excerpts below are copied from this upload.

Placeholders in this file

  • BUSINESS NAME

Excerpt 1

Information Security Policy

[BUSINESS NAME] [BUSINESS NAME] is committed to the highest standards of information security and treats confidentiality and data security extremely seriously. In relation to personal information, under General Data Protection Regulation, [BUSINESS NAME] must: use technical or organisational measures to ensure personal information is kept secure, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage; implement appropriate technical and organisational measures to demonstrate that it has considered and integrated data compliance measures into [BUSINESS NAME]’s data processing activities; and

Excerpt 2

be able to demonstrate that it has used or implemented such measures.

This purpose of this policy is to: protect against potential breaches of confidentiality; ensure all our information assets and IT facilities are protected against damage, loss or misuse; support [BUSINESS NAME]’s Data protection policy in ensuring all staff are aware of and comply with GDPR and [BUSINESS NAME]’s procedures applying to the processing of personal information; and increase awareness and understanding in [BUSINESS NAME] of the requirements of information security and the responsibility of staff to protect the confidentiality and integrity of the information that they themselves handle.

Excerpt 3

For the purposes of this Policy:

business information means business-related information other than personal information regarding customers, clients, suppliers and other business contacts of [BUSINESS NAME]; confidential information means trade secrets or other confidential information (either belonging to [BUSINESS NAME] or to third parties) that is processed by [BUSINESS NAME]; personal information

Excerpt 4

(sometimes known as personal data) means information relating to an individual who can be

(sometimes known as personal data) means information relating to an individual who can be identified (directly or indirectly) from that information; pseudonymised means the process by which personal information is processed in such a way that it cannot be used to identify an individual without the use of additional information, which is kept separately and subject to technical and organisational measures to ensure that the personal information cannot be attributed to an identifiable individual; sensitive personal information (sometimes known as ‘special categories of personal data’ or ‘sensitive personal data’) means personal information about an individual’s race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership (or non-membership), genetic information, biometric information (where used to identify an individual) and information concerning an individual’s health, sex life or sexual orientation.

Text copied from the uploaded file. It is not the complete download.

Overview

A longer Word information-security policy aimed at GDPR-era organizations. It covers access, assets, incidents, and supplier expectations so privacy and IT are not two separate stories. Use it as a baseline, then attach your real technical standards.

License

For one organization's internal use. You may customize the files. You may not resell or redistribute them as products. They are starting documents or training clips, not legal advice, not a certification, and not a guarantee of compliance — have qualified counsel review them for your situation.

What's inside

  • Microsoft Word information-security policy
  • Access control, assets, and acceptable use
  • Incident reporting and supplier security
  • Chapter structure you can trim or extend
  • Map controls to what you actually run

Related templates

Privacy Notice (GDPR)
Word
Privacy Notice (GDPR)

A Word privacy notice you can adapt for a website or service. It lists typical GDPR notice topics so you can fill in your own processing. Counsel should confirm lawful bases, recipients, and retention before you publish it.

€29.95

See template
Data Protection Policy
Word
Data Protection Policy

A Word data-protection policy covering roles, principles, and handling of personal data. Map it to your DPO or privacy lead. It is not a substitute for a DPIA or a processing contract.

€34.95

See template

Information Security Policy (GDPR)

€34.95