Privacy policy: what it must say and how to keep it true

The information a privacy statement must contain under the GDPR, how to write one that matches your actual website, and how to keep it current.

4 minread 852words last updated

The short answer

A privacy statement exists to tell people, in language they can follow, what happens to their data. The regulation sets out what it must contain: who you are and how to contact you, what personal data you collect, for what purposes, on which legal basis, who else receives it, how long you keep it, whether it goes outside the EU and under what mechanism, what rights people have and how to exercise them, and the right to complain to the supervisory authority. Where you rely on legitimate interest, you say what that interest is. The practical difficulty is not the list but the accuracy: generated statements describe a generic website, mentioning tools you do not use and omitting the ones you do, and an inaccurate statement fails the information obligation it was meant to satisfy. Write it from your record of processing so that every sentence is true of your site, keep it to a page of plain language, date it, and revise it whenever the site or its tools change.

What it must contain

Required informationWhat to write
Identity and contact detailsLegal name, address, email; the data protection officer if you have one
What you collectBy source: contact form, newsletter, account, order, analytics, logs
PurposesWhy each category is collected, in concrete terms
Legal basisPer purpose: contract, legitimate interest with the interest named, consent, legal obligation
RecipientsCategories of providers and partners who receive it: hosting, email, CRM, payment, analytics
TransfersWhether data goes outside the EU, to where and under which safeguard
RetentionHow long, per category, or the criteria used to decide
RightsAccess, rectification, erasure, restriction, portability, objection, withdrawing consent
How to exercise themA specific route: an address, a form, an expected response time
ComplaintsThe right to complain to the supervisory authority, named
Automated decisionsWhether any exist, and meaningful information about the logic, if so
SourceWhere data came from, if not collected from the person directly

Writing one that stays true

  1. Start from your record of processing, not from a template’s text.
  2. Write one section per data source in the order a visitor would meet them.
  3. Name the tools by category, and by name where it helps, especially analytics and chat.
  4. State real retention periods you can demonstrate.
  5. Use plain sentences; if a colleague outside the business cannot follow it, rewrite it.
  6. Add the date and a version note.
  7. Link it from the footer, every form and the cookie banner.
  8. Add a review step to your process for any new tool or form field.
  9. Keep old versions so you can show what was published when.

The two are separate and connected. The banner obtains consent before non-essential cookies; the statement explains what happens to data generally. The banner’s category descriptions must match the statement’s, and both must match what the site actually loads. When the three disagree, and they usually do on inherited sites, fix the site first, then the banner, then the statement, in that order.

What this means for you

A privacy statement must say who you are, what you collect, why, on what basis, who receives it, how long you keep it, where it goes, what rights people have and how to complain, in plain language. Write it from your own record of processing so it is accurate, keep it to a page, date it, link it everywhere it is needed, and update it whenever the site changes. An honest short statement beats a generated long one in every respect that matters. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Can we use a template or a generator?

As a structure, yes; as a finished document, no. Generators produce statements describing tools you may not use and omitting ones you do, and the result usually claims things about cookies and analytics that are untrue for your site. Since the obligation is to inform people accurately, an inaccurate statement is worse than a short honest one. Use a template for the headings and fill it from what your site actually does.

How long should it be?

As long as it takes to cover the required information clearly, which for a typical business website is one page. Length is not a virtue; the regulation requires concise, transparent, intelligible and easily accessible information in clear and plain language. A ten-page statement that nobody reads meets the letter and fails the purpose.

How often must we update it?

Whenever something it describes changes: a new form field, a new tool, a new purpose, a changed provider or retention period. In practice that means checking it whenever the site changes and reviewing it annually regardless. Date it, and keep previous versions, because it is useful to be able to show what you told people at a given time.

Sources

  1. EUR-Lex: Regulation (EU) 2016/679, Articles 12-14 (accessed 2026-09-14)