Legal and compliance
What is Privacy policy?
A published document stating what personal data a site collects, why, on what lawful basis, who it is shared with, how long it is kept, and how someone exercises their rights over it. Under UK and EU GDPR it is mandatory whenever any personal data is processed, including a contact form.
Also called: privacy notice · data protection notice
What it must actually contain
- Who you are and how to contact you — a real address, not only a form
- Every category of data collected, including analytics and server logs
- The purpose and lawful basis for each category, stated separately
- Every third party that receives the data, named rather than described
- Retention periods, and what happens at the end of them
- How to access, correct, delete or object, and how to complain to a regulator
Why a template alone is a liability
Templates describe a generic business. If yours claims advertising cookies you do not set, or omits the chat widget installed last year, it is inaccurate — and an inaccurate policy is a worse legal position than a short, honest one. The document has to match what the site does, which means auditing the site before writing it.
What it unlocks commercially
Google Ads, Merchant Center, most payment processors and most B2B procurement checks all require a published privacy policy alongside contact details and terms. Beyond compliance, it is a precondition for selling at all through those channels.
Where this is covered in depth
A definition can only go so far. Who actually owns your website — a checklist you can verify today covers this properly — 3 minutes, free, no email required.
Who wrote this
Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan. These definitions come from client work rather than from a content brief — where an entry describes a mistake, it is usually one found on a real site. More about how I work.