Privacy Policy

Knowledge Base | Privacy Policy | What should be in a privacy policy?

What should be in a privacy policy?

Your privacy policy should cover the disclosures required by applicable laws and your actual activities. These commonly include:

  • Organization identity and contact details, including a DPO or representative where applicable.

  • Data collected, its sources, and collection methods.

  • Processing purposes, required legal bases, and relevant legitimate interests.

  • Recipients or recipient categories.

  • International transfers and applicable safeguards.

  • Data retention periods or the criteria used to determine them.

  • Applicable rights, request procedures, consent withdrawal, and complaint routes.

  • Relevant automated decisions and their significance and consequences.

  • Mandatory data requirements and the consequences of not providing information.

The ICO’s disclosure checklist provides a UK GDPR reference.

Include additional disclosures where required, such as children’s data practices or California sale/sharing and opt-out information. Show the effective or updated date and keep the content accurate.