Home / What is a privacy policy?
What is a privacy policy?
A privacy policy is a public statement of what personal information your website or app collects, why, who you share it with, how long you keep it and what rights people have over it. For most sites it is a legal requirement, not a formality.
Why the law asks for one
Privacy laws are built on transparency: people can only make choices about their data if they know what happens to it. So nearly every modern privacy law makes the notice itself an obligation.
- California (CalOPPA) requires any commercial website or online service that collects personally identifiable information from California residents to conspicuously post a privacy policy (Bus. & Prof. Code § 22575). No size threshold, and it applies wherever you are based.
- EU and UK (GDPR) Articles 13 and 14 list the information you must give people when you collect their personal data, and Article 12 says it must be concise, transparent and in clear and plain language.
- California (CCPA/CPRA) requires larger businesses to post a detailed privacy policy covering consumers' rights (Cal. Code Regs. tit. 11, § 7011).
- Canada (PIPEDA) Principle 8, openness, requires organisations to make their personal information policies readily available.
Outside the statutes, platforms enforce it too: Apple and Google require a privacy policy URL to publish apps, and Google Analytics' terms require you to disclose your use of it.
Which privacy laws apply to you?
Flip the statements that are true for your site. The verdicts use each law's own scope rules and thresholds.
- CalOPPA: Likely
You run a commercial site or app and collect personal information from Californians. CalOPPA has no size threshold.
- CCPA: Unlikely
Needs a for-profit business with Californian consumers AND one threshold: revenue above $26,625,000, 100,000+ consumers' data bought/sold/shared, or 50%+ of revenue from selling/sharing it.
- GDPR: Unlikely
Applies if you are established in the EU or offer goods/services to, or monitor, people there.
- PIPEDA: Unlikely
Applies to personal information collected in the course of commercial activity in Canada.
A rough screen based on the statutes' own thresholds, not a legal opinion. Other laws may apply too (for example UK GDPR, COPPA, other US state privacy laws, Brazil's LGPD).
Rules click faster when you can flip the inputs and watch the answer change; ahaboo applies the same idea in a narrated explainer on why the Moon has phases.
What goes in a privacy policy
The core sections overlap across laws; each law adds its own. Toggle laws to compare.
With GDPR + CalOPPA, your policy needs 18 of 19 sections.
GDPR: Art. 13(1)(a)CCPA: 11 CCR § 7011(e)PIPEDA: Sch. 1, Principle 4.8 (openness)
Common mistakes
- Copying another site's policy. It describes their tools and practices, not yours, and it is their copyrighted text.
- Leaving out third-party tools. Analytics, ad pixels, embedded videos, chat widgets and payment providers all collect data through your site.
- Promising what you don't do. Under CalOPPA and the FTC Act, failing to follow your own policy can itself be the violation.
- Never updating it. A policy that doesn't mention the tool you added last year is inaccurate.
Frequently asked questions
Is a privacy policy legally required?
For most websites and apps, yes. CalOPPA requires one from any commercial site or online service that collects personally identifiable information from California residents. GDPR Articles 13 and 14 require the same information to be given to people in the EU and UK. The CCPA, PIPEDA and many other national laws have similar rules, and app stores, ad networks and analytics providers require a policy in their terms.
Do I need a privacy policy if I don't collect any data?
Almost every site collects something: server logs record IP addresses, and analytics, embedded videos, fonts and contact forms all process personal information. If you truly collect nothing, a short policy saying so is still useful and is required by Apple for every app.
What is the difference between a privacy policy and terms and conditions?
A privacy policy is a notice: it tells people what you do with their personal information, and many laws require it. Terms and conditions are a contract setting the rules for using your service; they are usually optional but protect you.
Where should I put my privacy policy?
On its own page, linked from every page footer with a link containing the word "privacy", and at every point where you collect data, such as sign-up forms and checkout. Apps should link it in the store listing and inside the app.
How often should I update it?
Whenever your practices change (a new analytics tool, a new payment provider, a new feature that collects data). Businesses covered by the CCPA must review and update it at least every 12 months.