What Every Privacy Policy Needs

A privacy policy is the public promise your website makes about how it handles people’s data. Done well, it is short, honest and genuinely readable. Done badly, it is a wall of copied boilerplate that satisfies nobody — not your visitors and not a regulator. Here is what actually needs to be in one.

The short version

Cover seven things clearly: what data you collect, why, your legal basis, who you share it with, how long you keep it, what rights people have, and how to contact you. Write it in plain language and keep it current. This is general information, not legal advice.

1. What data you collect

List the categories of personal data you gather and how. Split it into data people give you directly (name, email, order details) and data collected automatically (IP address, device information, cookies). Be specific enough that a reader recognises exactly what you hold. If you don’t collect something, don’t list it — padding the policy with irrelevant clauses only confuses people.

2. Why you collect it (purpose)

For each type of data, say what you use it for: fulfilling orders, answering support requests, sending a newsletter, measuring site traffic. Tie the data to a purpose so people can see there is a real reason behind every field you ask for.

3. Your legal basis

Under the GDPR you must state the lawful basis for each use — consent, contract, legal obligation, legitimate interests, and so on. A newsletter typically relies on consent; processing an order relies on contract. Naming the basis is a legal requirement, not an optional extra.

SectionAnswers the question
Data collectedWhat do you have about me?
PurposeWhy do you have it?
Legal basisWhat allows you to hold it?
SharingWho else sees it?
RetentionHow long do you keep it?
RightsWhat can I ask you to do?
ContactWho do I talk to?

4. Who you share it with

Name the categories of third parties that receive data on your behalf — hosting, payment processors, email tools, analytics providers. You don’t have to list every vendor, but the reader should understand the types of recipients. If data leaves the EU or EEA, explain the safeguards you rely on for that transfer.

5. How long you keep it (retention)

State how long you retain each type of data, or the criteria you use to decide. “We keep order records for the period required by tax law, then delete them” is far better than silence. Indefinite retention with no justification is a red flag.

6. People’s rights

Explain the rights individuals have — access, correction, deletion, restriction, portability, and objecting to certain processing — and how to exercise them. Include the right to withdraw consent where you rely on it, and the right to complain to a supervisory authority.

7. How to contact you

Give a real contact route for privacy questions and requests: an email address at minimum, and a data protection contact if you have one. This is where a data subject request will land, so make sure someone actually monitors it.

Tip. Date your policy and note when it was last updated. When you change what you collect or add a new tool, revisit the policy the same day — an outdated privacy policy is a common and avoidable compliance gap.

Writing style matters

Regulators expect policies to be concise, transparent and intelligible. Prefer short sentences and real words over legalese. Pair the policy with correct cookie consent so the two are consistent, and see our compliance overview for how privacy fits the bigger picture.

This guide is general information, not legal advice. Use a template as a starting point, but tailor it to what your site actually does and consult a professional for specifics.

Frequently asked questions

Can I just copy another site’s privacy policy?

No. A policy must describe your actual data practices. Copying one that lists tools or data you don’t use is inaccurate and can be worse than having none.

Do I need a privacy policy for a simple contact form?

If the form collects personal data such as a name and email, then yes — you should explain what you do with it, even for a single field.

How often should I update it?

Whenever your data practices change — a new analytics tool, a new payment processor, a new purpose — and review it periodically even if nothing obvious has changed.

Related guides

Check your site against this guide

Run a free ScanOpsPro scan and see how your site handles the fundamentals.

Run a free scan