What Every Privacy Policy Needs
A privacy policy is the public promise your website makes about how it handles people’s data. Done well, it is short, honest and genuinely readable. Done badly, it is a wall of copied boilerplate that satisfies nobody — not your visitors and not a regulator. Here is what actually needs to be in one.
The short version
Cover seven things clearly: what data you collect, why, your legal basis, who you share it with, how long you keep it, what rights people have, and how to contact you. Write it in plain language and keep it current. This is general information, not legal advice.
1. What data you collect
List the categories of personal data you gather and how. Split it into data people give you directly (name, email, order details) and data collected automatically (IP address, device information, cookies). Be specific enough that a reader recognises exactly what you hold. If you don’t collect something, don’t list it — padding the policy with irrelevant clauses only confuses people.
2. Why you collect it (purpose)
For each type of data, say what you use it for: fulfilling orders, answering support requests, sending a newsletter, measuring site traffic. Tie the data to a purpose so people can see there is a real reason behind every field you ask for.
3. Your legal basis
Under the GDPR you must state the lawful basis for each use — consent, contract, legal obligation, legitimate interests, and so on. A newsletter typically relies on consent; processing an order relies on contract. Naming the basis is a legal requirement, not an optional extra.
| Section | Answers the question |
|---|---|
| Data collected | What do you have about me? |
| Purpose | Why do you have it? |
| Legal basis | What allows you to hold it? |
| Sharing | Who else sees it? |
| Retention | How long do you keep it? |
| Rights | What can I ask you to do? |
| Contact | Who do I talk to? |
4. Who you share it with
Name the categories of third parties that receive data on your behalf — hosting, payment processors, email tools, analytics providers. You don’t have to list every vendor, but the reader should understand the types of recipients. If data leaves the EU or EEA, explain the safeguards you rely on for that transfer.
5. How long you keep it (retention)
State how long you retain each type of data, or the criteria you use to decide. “We keep order records for the period required by tax law, then delete them” is far better than silence. Indefinite retention with no justification is a red flag.
6. People’s rights
Explain the rights individuals have — access, correction, deletion, restriction, portability, and objecting to certain processing — and how to exercise them. Include the right to withdraw consent where you rely on it, and the right to complain to a supervisory authority.
7. How to contact you
Give a real contact route for privacy questions and requests: an email address at minimum, and a data protection contact if you have one. This is where a data subject request will land, so make sure someone actually monitors it.
Writing style matters
Regulators expect policies to be concise, transparent and intelligible. Prefer short sentences and real words over legalese. Pair the policy with correct cookie consent so the two are consistent, and see our compliance overview for how privacy fits the bigger picture.
This guide is general information, not legal advice. Use a template as a starting point, but tailor it to what your site actually does and consult a professional for specifics.
Frequently asked questions
Can I just copy another site’s privacy policy?
No. A policy must describe your actual data practices. Copying one that lists tools or data you don’t use is inaccurate and can be worse than having none.
Do I need a privacy policy for a simple contact form?
If the form collects personal data such as a name and email, then yes — you should explain what you do with it, even for a single field.
How often should I update it?
Whenever your data practices change — a new analytics tool, a new payment processor, a new purpose — and review it periodically even if nothing obvious has changed.
Related guides
GDPR Website Checklist for Small Businesses
A practical, jargon-free checklist to bring a small website in line with GDPR, from cookies to data requests.
Read →Privacy & ComplianceThe NIS2 Directive Explained for Website Owners
What the EU NIS2 directive is, who it applies to, and the baseline security it expects.
Read →Privacy & ComplianceCookie Consent Done Right
How consent banners are supposed to work under EU law and how to avoid the most common compliance mistakes.
Read →Check your site against this guide
Run a free ScanOpsPro scan and see how your site handles the fundamentals.
Run a free scan