Corporate Website Marketing logo — B2B website marketing referenceCorporate Website MarketingB2B website marketing since 2003
Template

Privacy Policy Sample for a Website: Do This Instead

A copied policy describes practices you do not have and omits the trackers you do run. Here is what to inventory, and what each section must answer.

Why a borrowed policy is worse than a short accurate one

A privacy policy is a set of factual representations about your business. Copying one does not save work — it manufactures statements about data practices nobody at your company has checked. The failure runs in both directions, and both are worse than a plain two-page policy that happens to be true.

In one direction it describes things you do not do: a data protection officer you have not appointed, a children's data process for a product no child uses, rights procedures nobody is staffed to answer. In the other direction — the expensive one — it omits the trackers you actually run. The recurring finding in privacy enforcement is not that a policy was too short. It is that described controls did not work, that opt-out signals were ignored, and that data kept flowing to advertising vendors the policy never named. A policy omitting trackers present on the site is a misrepresentation, reachable under FTC Act section 5 and state unfair-practices statutes.

Take the inventory before you write a word

You cannot describe practices you have not enumerated. Before drafting, list everything on the site that collects, stores, or transmits information about a visitor:

  • Every tag and pixel in the tag manager container, including paused ones, anything hard-coded outside it, and any legacy analytics property still firing
  • Every advertising platform with a conversion tag, remarketing tag, or audience integration
  • Every form, and where each submission lands — CRM, marketing automation, an inbox, a spreadsheet
  • Chat widgets, session replay and heatmap tools, testing tools, the consent tool itself, and embedded video, maps, fonts, or social buttons loading from someone else's server
  • Cookies and identifiers actually set, with purpose and lifetime, read from the browser rather than a vendor's page
  • Every recipient: vendors, subprocessors, and advertising partners, what contract terms exist with each, and how long each keeps the data

Read the network requests in developer tools while walking the site, including a form submission and a consent rejection. That exercise routinely surfaces tags nobody remembered adding.

Work out which rules actually reach you

Scope determines content, and it is not intuitive for a business-to-business site. Twenty US states have comprehensive consumer privacy statutes in force as of mid-2026, with Indiana, Kentucky, and Rhode Island the most recent, all effective 1 January 2026. Thresholds differ by state; Texas and Nebraska have no numeric volume threshold at all, reaching any non-small-business in the state that processes or sells personal data.

The trap specific to B2B is California. The CCPA's exemptions for business-to-business contact data and for HR data expired on 1 January 2023 and were not renewed. Business contact data of California residents sits fully inside the CCPA — badge scans, gated-asset forms, and the prospecting database included.

If EU or UK visitors reach the site, GDPR and UK GDPR transparency requirements apply. Note which instrument governs cookies: consent to store or access information on a device is required by ePrivacy Article 5(3), and PECR regulation 6 in the UK, not by the GDPR — and legitimate interests is not available for non-essential cookies.

The structure a defensible policy has, and what each part must answer

Work through these in order, answering the third column from your inventory, not another company's policy.

SectionWhat belongs in itQuestion it must answer
Who we areLegal entity, address, privacy contact, DPO if one existsWho is the controller, and can a person reach them?
What we collectCategories of information and the source of eachDoes this match the forms, tags, and logs you inventoried?
Why we collect itSpecific purposes per category; lawful basis for EU and UK visitorsIs each purpose specific, not just improving our services?
Cookies and trackingTechnologies deployed, purpose, lifetime, how to refuseWould a developer agree with this list?
Who receives itNamed recipients or narrow categories, and the purpose of eachAre ad and analytics vendors identified, not hidden behind partners?
Sale, sharing, targeted advertisingWhether data is sold or shared, to which categories, how to opt out, and how signals such as Global Privacy Control are processedIf the answer is none, is that stated expressly? Does the signal stop the flow, for the account as well as the device?
RetentionThe period per category, or the criteria for setting itCan anyone confirm deletion happens?
Rights and requestsRights available, submission methods, verification processIs there a working mechanism behind every right?
Transfers, children, changesThird-country transfers and the mechanism relied on; minors; the date last updatedAre these claims true, or inherited from a template?

Illustrative wording, offered as illustration only

The two passages below show what specificity looks like. They are not a template to adopt: the facts they recite are almost certainly false for your site.

A tracking disclosure. We use Google Analytics 4 to measure how the site is used, and advertising tags from Google Ads and LinkedIn to measure campaign performance and build audiences. These tools set cookies in your browser and transmit your IP address, the pages you view, and interaction events to those companies. You can refuse non-essential tags using the control in the footer; refusing stops those tags loading and does not restrict access to the site.

An opt-out signal disclosure. We treat a Global Privacy Control signal from your browser as a valid request to opt out of the sale and sharing of personal information. On receiving it we stop transmitting identifiers to advertising recipients for that browser, and where it arrives while you are signed in we apply the opt-out to your account across devices. We do not require identity verification to opt out.

What makes wording like that usable is that every sentence is checkable: named recipients, a stated consequence, and a mechanism someone can test.

What is usually missing, and why policies quietly go stale

The gaps are consistent:

  • Advertising and analytics recipients described as partners rather than named
  • No retention period and no criteria for setting one
  • No explanation of how opt-out preference signals are processed — the item most often absent altogether
  • No last-updated date and no annual review
  • A right described with no working mechanism behind it, which turns a compliance gap into an affirmative misstatement
  • Identity verification imposed on an opt-out, which under the CCPA is not a verifiable request
  • Missing contract terms with advertising vendors — the adjacent failure that recurs in enforcement

Then there is the maintenance problem, which is structural rather than a drafting error. A marketer adds a remarketing tag on a Tuesday afternoon. It sends data to a recipient the policy does not mention, and by Wednesday the policy is wrong — silently, with nobody notified. The California enforcement record turns on this class of drift: non-functional opt-outs, failure to honour Global Privacy Control including honouring it per-device rather than per-account, verification friction on opt-outs, and missing ad-tech contract terms. Adding a tag should require naming the recipient, the data it sends, and the policy line it changes.

When to bring in a lawyer

Do the inventory yourself. It is technical work, the web team is the only group that can do it accurately, and handing counsel a complete tracker and recipient list is the largest saving available.

Bring in a qualified privacy lawyer to decide which statutes apply, to draft or review the operative language, and specifically before making any representation about selling or sharing data, sensitive data, international transfers, or automated decision-making. Counsel should also review contract terms with advertising and analytics vendors, since missing terms have featured in enforcement as often as policy text.

This page is general information for marketing and web teams. It is not legal advice, it does not create an attorney-client relationship, and a privacy policy should be reviewed by a qualified lawyer before it is published.

Frequently Asked Questions

Can I use a free privacy policy sample for my website?

Use one as a structural reference, not as text to publish. A privacy policy is a set of factual claims about your data practices, and a sample was written about someone else's. Published as-is it asserts practices you do not have and omits the tools you run.

Treat a sample as a checklist of sections, write each section from an inventory of your own tags, forms, vendors, and retention periods, then have counsel review it.

Does a B2B website need a privacy policy?

Yes. The assumption that business contact data sits outside privacy law does not hold in California, where the CCPA's B2B and HR exemptions expired on 1 January 2023 and were not renewed. Business contact information of California residents is fully within the statute — gated-content forms, badge scans, and prospecting databases included.

Twenty states have comprehensive privacy statutes in force as of mid-2026. Whether commercial-context data falls outside another state's definitions should be checked against that state's code rather than presumed.

Do I need a cookie consent banner on my site?

It depends who visits and which rules reach them. For visitors in the EU and UK, consent to store or access non-essential cookies is required by ePrivacy Article 5(3) and, in the UK, PECR regulation 6 — not by the GDPR, and legitimate interests is not available as a basis.

US state statutes generally work through opt-out rights and preference signals rather than prior consent, so what matters there is a mechanism that actually stops the data flow when a signal arrives.

How often should a privacy policy be updated?

On a schedule and on every relevant event. California's regulations require the policy to carry the date it was last updated, and failure to update annually was among the findings in the CalPrivacy order against PlayOn Sports dated 27 February 2026.

The annual review is the floor. A policy becomes inaccurate the moment a tag, form, vendor, or retention period changes, so treat any new tool or recipient as a trigger.