Website Spec
← Privacy
Required

Privacy policy

A privacy policy tells visitors what personal data you collect, why, on what legal basis, who you share it with, how long you keep it, and what rights they have.

What it is

A privacy policy is the public document that explains how your website handles personal data. Under the GDPR it satisfies the transparency obligations of Articles 13 and 14 — the right of the data subject to be informed about processing. Similar laws exist in the UK (UK GDPR), California (CCPA/CPRA), Brazil (LGPD), and most other jurisdictions.

It is not a disclaimer. It is a binding statement of practice.

Why it matters

If you collect any personal data — names, email addresses, IP addresses, cookies tied to a user, form submissions — you owe the visitor an accurate description of what happens to it. Regulators treat a missing, vague, or out-of-date policy as a transparency failure on its own, even before they look at what you actually do with the data.

A clear policy also reduces support load. Most "what do you do with my data?" questions disappear when there is a page to point at.

How to implement

A privacy policy should disclose, at minimum:

Link to the policy from the footer of every page. Do not put it behind a login.

Common mistakes

Sources