Why a borrowed policy is worse than a short accurate one
A privacy policy is a set of factual representations about your business. Copying one does not save work — it manufactures statements about data practices nobody at your company has checked. The failure runs in both directions, and both are worse than a plain two-page policy that happens to be true.
In one direction it describes things you do not do: a data protection officer you have not appointed, a children's data process for a product no child uses, rights procedures nobody is staffed to answer. In the other direction — the expensive one — it omits the trackers you actually run. The recurring finding in privacy enforcement is not that a policy was too short. It is that described controls did not work, that opt-out signals were ignored, and that data kept flowing to advertising vendors the policy never named. A policy omitting trackers present on the site is a misrepresentation, reachable under FTC Act section 5 and state unfair-practices statutes.
Take the inventory before you write a word
You cannot describe practices you have not enumerated. Before drafting, list everything on the site that collects, stores, or transmits information about a visitor:
- Every tag and pixel in the tag manager container, including paused ones, anything hard-coded outside it, and any legacy analytics property still firing
- Every advertising platform with a conversion tag, remarketing tag, or audience integration
- Every form, and where each submission lands — CRM, marketing automation, an inbox, a spreadsheet
- Chat widgets, session replay and heatmap tools, testing tools, the consent tool itself, and embedded video, maps, fonts, or social buttons loading from someone else's server
- Cookies and identifiers actually set, with purpose and lifetime, read from the browser rather than a vendor's page
- Every recipient: vendors, subprocessors, and advertising partners, what contract terms exist with each, and how long each keeps the data
Read the network requests in developer tools while walking the site, including a form submission and a consent rejection. That exercise routinely surfaces tags nobody remembered adding.
Work out which rules actually reach you
Scope determines content, and it is not intuitive for a business-to-business site. Twenty US states have comprehensive consumer privacy statutes in force as of mid-2026, with Indiana, Kentucky, and Rhode Island the most recent, all effective 1 January 2026. Thresholds differ by state; Texas and Nebraska have no numeric volume threshold at all, reaching any non-small-business in the state that processes or sells personal data.
The trap specific to B2B is California. The CCPA's exemptions for business-to-business contact data and for HR data expired on 1 January 2023 and were not renewed. Business contact data of California residents sits fully inside the CCPA — badge scans, gated-asset forms, and the prospecting database included.
If EU or UK visitors reach the site, GDPR and UK GDPR transparency requirements apply. Note which instrument governs cookies: consent to store or access information on a device is required by ePrivacy Article 5(3), and PECR regulation 6 in the UK, not by the GDPR — and legitimate interests is not available for non-essential cookies.
The structure a defensible policy has, and what each part must answer
Work through these in order, answering the third column from your inventory, not another company's policy.
| Section | What belongs in it | Question it must answer |
|---|---|---|
| Who we are | Legal entity, address, privacy contact, DPO if one exists | Who is the controller, and can a person reach them? |
| What we collect | Categories of information and the source of each | Does this match the forms, tags, and logs you inventoried? |
| Why we collect it | Specific purposes per category; lawful basis for EU and UK visitors | Is each purpose specific, not just improving our services? |
| Cookies and tracking | Technologies deployed, purpose, lifetime, how to refuse | Would a developer agree with this list? |
| Who receives it | Named recipients or narrow categories, and the purpose of each | Are ad and analytics vendors identified, not hidden behind partners? |
| Sale, sharing, targeted advertising | Whether data is sold or shared, to which categories, how to opt out, and how signals such as Global Privacy Control are processed | If the answer is none, is that stated expressly? Does the signal stop the flow, for the account as well as the device? |
| Retention | The period per category, or the criteria for setting it | Can anyone confirm deletion happens? |
| Rights and requests | Rights available, submission methods, verification process | Is there a working mechanism behind every right? |
| Transfers, children, changes | Third-country transfers and the mechanism relied on; minors; the date last updated | Are these claims true, or inherited from a template? |
Illustrative wording, offered as illustration only
The two passages below show what specificity looks like. They are not a template to adopt: the facts they recite are almost certainly false for your site.
A tracking disclosure. We use Google Analytics 4 to measure how the site is used, and advertising tags from Google Ads and LinkedIn to measure campaign performance and build audiences. These tools set cookies in your browser and transmit your IP address, the pages you view, and interaction events to those companies. You can refuse non-essential tags using the control in the footer; refusing stops those tags loading and does not restrict access to the site.
An opt-out signal disclosure. We treat a Global Privacy Control signal from your browser as a valid request to opt out of the sale and sharing of personal information. On receiving it we stop transmitting identifiers to advertising recipients for that browser, and where it arrives while you are signed in we apply the opt-out to your account across devices. We do not require identity verification to opt out.
What makes wording like that usable is that every sentence is checkable: named recipients, a stated consequence, and a mechanism someone can test.
What is usually missing, and why policies quietly go stale
The gaps are consistent:
- Advertising and analytics recipients described as partners rather than named
- No retention period and no criteria for setting one
- No explanation of how opt-out preference signals are processed — the item most often absent altogether
- No last-updated date and no annual review
- A right described with no working mechanism behind it, which turns a compliance gap into an affirmative misstatement
- Identity verification imposed on an opt-out, which under the CCPA is not a verifiable request
- Missing contract terms with advertising vendors — the adjacent failure that recurs in enforcement
Then there is the maintenance problem, which is structural rather than a drafting error. A marketer adds a remarketing tag on a Tuesday afternoon. It sends data to a recipient the policy does not mention, and by Wednesday the policy is wrong — silently, with nobody notified. The California enforcement record turns on this class of drift: non-functional opt-outs, failure to honour Global Privacy Control including honouring it per-device rather than per-account, verification friction on opt-outs, and missing ad-tech contract terms. Adding a tag should require naming the recipient, the data it sends, and the policy line it changes.
When to bring in a lawyer
Do the inventory yourself. It is technical work, the web team is the only group that can do it accurately, and handing counsel a complete tracker and recipient list is the largest saving available.
Bring in a qualified privacy lawyer to decide which statutes apply, to draft or review the operative language, and specifically before making any representation about selling or sharing data, sensitive data, international transfers, or automated decision-making. Counsel should also review contract terms with advertising and analytics vendors, since missing terms have featured in enforcement as often as policy text.
This page is general information for marketing and web teams. It is not legal advice, it does not create an attorney-client relationship, and a privacy policy should be reviewed by a qualified lawyer before it is published.
Frequently Asked Questions
Can I use a free privacy policy sample for my website?
Use one as a structural reference, not as text to publish. A privacy policy is a set of factual claims about your data practices, and a sample was written about someone else's. Published as-is it asserts practices you do not have and omits the tools you run.
Treat a sample as a checklist of sections, write each section from an inventory of your own tags, forms, vendors, and retention periods, then have counsel review it.
Does a B2B website need a privacy policy?
Yes. The assumption that business contact data sits outside privacy law does not hold in California, where the CCPA's B2B and HR exemptions expired on 1 January 2023 and were not renewed. Business contact information of California residents is fully within the statute — gated-content forms, badge scans, and prospecting databases included.
Twenty states have comprehensive privacy statutes in force as of mid-2026. Whether commercial-context data falls outside another state's definitions should be checked against that state's code rather than presumed.
Do I need a cookie consent banner on my site?
It depends who visits and which rules reach them. For visitors in the EU and UK, consent to store or access non-essential cookies is required by ePrivacy Article 5(3) and, in the UK, PECR regulation 6 — not by the GDPR, and legitimate interests is not available as a basis.
US state statutes generally work through opt-out rights and preference signals rather than prior consent, so what matters there is a mechanism that actually stops the data flow when a signal arrives.
How often should a privacy policy be updated?
On a schedule and on every relevant event. California's regulations require the policy to carry the date it was last updated, and failure to update annually was among the findings in the CalPrivacy order against PlayOn Sports dated 27 February 2026.
The annual review is the floor. A policy becomes inaccurate the moment a tag, form, vendor, or retention period changes, so treat any new tool or recipient as a trigger.