Governance & Operations
What is Privacy Policy?
A privacy policy is the public document in which an organization discloses what personal data it collects, why, how it is used and shared, how long it is kept, and what rights individuals have — a legal requirement under GDPR, the CCPA, and dozens of other laws.
The privacy policy is where transparency obligations converge. GDPR Articles 13 and 14 prescribe the notice content in detail: the controller's identity and contacts, the purposes and legal basis of each processing operation, legitimate interests where relied on, recipients, international transfers and their safeguards, retention periods, the full catalog of data subject rights, withdrawal of consent, complaint rights, and the existence of automated decision-making. California layers on its own list: categories collected, sold, or shared in the last 12 months, the purposes, consumer rights, and how to exercise them — with an annual update requirement.
It is also a liability document. The FTC's core privacy authority polices deception, and the fastest route to a deceptive-practices case is a policy that says 'we never share your data' while the site syncs audiences to ad platforms. Class actions quote policies back at their authors; regulators diff them against scan results. The cardinal rule is that the policy must describe what actually happens — which means it depends on knowing your data flows, and it must change when they do.
Format matters legally: notices must be concise, transparent, intelligible, and in clear and plain language. Layered policies — a readable summary above the detailed disclosures — are the accepted pattern. Boilerplate copied from another site fails in both directions: it discloses processing you do not do and misses processing you do.
Adjacent documents orbit it: cookie policies detailing trackers, CCPA-specific notices at collection, and — for stores — regionally tailored disclosures that track where you actually sell.
Why it matters for eCommerce
Your policy must accurately cover the whole stack — commerce platform, email, analytics, pixels, fulfillment — and it changes every time marketing adds a tool. Generic templates are the standing hazard: they promise practices your tag manager contradicts. Generating the policy from your actual data flows and tracker inventory, and regenerating on change, keeps the promise and the practice aligned.
Frequently asked questions
- Is a privacy policy legally required?
- Yes, for essentially any site or app handling personal data: GDPR mandates detailed notices, California has required posted policies since CalOPPA in 2004 with the CCPA adding specifics, and platform rules (Apple, Google, payment providers) require one contractually even where no statute reaches you.
- How often should a privacy policy be updated?
- Whenever practices change — new tools, new data uses, new sharing — and at least annually, which California requires explicitly. Material changes to how existing data is used may also require fresh notice or consent, not just a silent edit.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Generate a privacy policy with PieEye