GDPR translation from €0.12/word GDPR translation: data protection in every language your customers speak.
GDPR translations for privacy policies, data processing agreements and consent forms, handled by legal specialist translators who align your texts to the terminology of the relevant EU member state. Confidential to ISO 27001, in over 220 languages. Request a free quote.
Data protection and legal teams at leading companies trust tolingo
- What it is: The specialist translation of GDPR data protection documents, by legal specialist translators.
- Who it's for: Companies with a multilingual web presence, international business or a group structure, plus data protection, legal and HR departments.
- What it costs: As a legal specialist translation from €0.12/word, fixed price after we've seen the documents.
- The difference: We check against the target country's data protection terminology, not only against the source text. Confidential to ISO 27001.
When you need a GDPR translation
It depends on whom you address, and where
A GDPR translation renders data protection documents into other languages so they meet the GDPR's requirements in the target country. Whether you need one depends less on how much text you have and more on which languages you use to address people. The GDPR requires, in Article 12, that data subjects be informed in a "concise, transparent, intelligible and easily accessible form" and in "clear and plain language".
If you appear in only one language in one market, you usually don't need to do more on the language front. No translation need arises here.
If you offer content in several languages, your privacy policy should be available and easy to understand in those languages. A precise legal website translation is enough, as long as it follows the EU wording of the language in question.
Where there is a link to countries outside the EU, a country-specific legal rewrite may be needed. Relying on European languages alone is risky here.
The GDPR provides, in Article 83, for fines of up to €20 million or 4% of worldwide annual turnover, whichever is higher. We describe the legal framework and do not replace legal advice. Whether and to what extent you need to have documents translated is something to clarify with your data protection officer if in doubt. You will find the text of the GDPR at EUR-Lex.
Which documents we translate
From the privacy policy to the data processing agreement
Data protection is more than the notice on your website. These are the documents companies ask about most:
The notice on your website and in apps, easy to understand in your users' language. Part of every website translation aimed at an international audience.
The DPA (or AVV) with service providers and customers, often in the other party's contract language. A legal translation where the terminology has to be exact.
Consent texts for newsletters, tracking or data sharing, where consent only counts if the data subject truly understands the text.
Cookie banners and policies that must say the same thing in every language version as in the original, so your consent management holds up.
The record of processing activities and the data protection impact assessment (DPIA) for groups and public bodies with reporting duties across borders.
Data protection policies, works agreements and privacy notices for employees and applicants, matched to the language of your sites.
What matters in GDPR translations
Precision, localisation, clarity, consistency
Data protection terms are legally defined, and a shifted term shifts the meaning. So we work along four lines:
Terms like controller, processor and consent follow the official terminology of the member state, secured through terminology management.
The GDPR applies EU-wide but is supplemented nationally, for example by the BDSG in Germany. We take the target country's country-specific requirements into account.
Article 12 calls for clear, plain language. We carry over the legal substance without turning the text into something the data subject cannot read.
Privacy policy, DPA and consent form have to fit together. Translation memory keeps terms identical and makes updates cheap when the law changes.
Machine translation often misses the legal subtleties and national specifics of data protection law, especially with fixed legal terms that carry a defined meaning. We rely on qualified specialist translators with a legal background. On request, AI supports the process, followed by post-editing to ISO 18587, so precision and readability come together.
What a GDPR translation costs
A clear per-word price, with a worked example
We bill GDPR translations as legal specialist translation at a per-word rate. We give you the binding fixed price as soon as we've seen the volume, languages and document type.
| Service | From | Suitable for |
|---|---|---|
| Legal specialist translation (ISO 17100) | €0.12/word | Privacy policies, DPAs, consent forms, policies |
| With four-eyes revision (on request) | on request | Publication-ready or especially sensitive data protection texts |
| Express (24 hrs) | +30 to 50% | Time-critical updates, launches, response deadlines |
| Recurring / many languages | framework rates | Ongoing upkeep of translated data protection texts |
A worked example: a privacy policy of around 1,500 words in five languages starts from approx. €900 as legal specialist translation. These are guide figures and depend on the language pair, complexity and whether you want four-eyes revision. For recurring needs we agree framework rates. More on the prices page.
GDPR translation in context
What sits alongside it and what goes further
Depending on what you have translated and why, a neighbouring service may fit better or complement the GDPR translation:
Is it the whole site, including the privacy policy and legal notice? Website translation brings content and mandatory texts into every language version.
Does it go beyond data protection, into contracts, proceedings or law-firm needs? tolingo legal bundles legal translation for legal departments.
Does an authority require official recognition of a document? Then certified translation by sworn translators is the right route.
How tolingo itself handles your data: data processing agreements, EU servers, deletion policies and a certified information security management system.
Common questions about GDPR translation
Cost, documents, speed, security
What does a GDPR translation cost?
We bill GDPR translations as legal specialist translation at a per-word rate, from €0.12/word. The fixed price depends on volume, language pair and complexity. A privacy policy of around 1,500 words in five languages starts from approx. €900. We give you the binding price once we've looked at your files.
Which documents need translating for GDPR compliance?
Often these are privacy policies, consent forms, information on data processing, cookie policies, data processing agreements, data protection impact assessments and internal data protection policies. Which of these apply in your case, and into which languages, we clarify with you up front.
How quickly do I get a GDPR translation?
We translate standard privacy policies within a few working days. More extensive documentation needs correspondingly more time for legal and linguistic quality. For time-critical projects, such as a launch or a running response deadline, there is the express service in 24 hours.
Why isn't machine translation enough for GDPR documents?
Machine translation often misses the legal subtleties and country-specific details of data protection law, especially with legal terms that carry a fixed meaning. We rely on specialist translators with a legal background, AI-assisted where useful with post-editing to ISO 18587 for precision and readability.
Do you take country-specific data protection laws into account?
Yes. The GDPR applies EU-wide but is implemented differently in each member state and supplemented by national laws, such as the BDSG in Germany. Our legal specialist translators are native speakers and familiar with local data protection rules, so the translation fits the GDPR and national specifics.
How secure are my data protection documents with you?
tolingo is certified to ISO 27001. We have data processing agreements with every translator, processing runs encrypted on EU servers, and there are documented deletion policies. On request, we sign an NDA before the first file.
How do you assure translation quality?
Your documents are handled by legal specialist translators who are native speakers of the target language and familiar with data protection law. On request, the translation goes through four-eyes revision by a second specialist. Our processes are certified to ISO 9001 and ISO 17100.
Do I need certification for GDPR documents?
Usually not. Privacy policies, DPAs and consent forms are business documents with no need for official certification. If an authority does require official recognition, the route is certified translation by sworn translators.
Translations
Looking for the right specialist translation?
GDPR, legal, technical and financial translations sit side by side. The overview shows which specialist translation fits your document.
Bring your data protection into every language your customers speak.
Send us your data protection documents and the target languages. We'll name a fixed price and delivery date and assign the right legal specialist translator.
Reply in ~10 minutes (within business hours) · ISO 27001 · NDA on requestGlossary: terms around GDPR translation
- Data processing agreement (DPA)
- The contract under Article 28 GDPR between a controller and a service provider that processes personal data on the controller's behalf. In international business, often needed in the other party's language, where the terminology has to be exact.
- Controller and processor
- Two central GDPR roles. The controller decides on the purposes and means of processing; the processor acts on the controller's behalf. The terms are defined in the regulation, and each official language version has its own fixed equivalents, so a free translation would be wrong.
- Article 12 GDPR
- The provision on transparent information. It requires that data subjects be informed in a concise, intelligible and easily accessible form and in clear, plain language. That is why data protection texts should be available in your users' language.
- Data protection impact assessment (DPIA)
- A risk analysis under Article 35 GDPR for processing likely to result in a high risk. In groups with cross-border processes, it is often needed in several languages.
