What this document is actually for
The European regulation imposes an information duty: the person whose data you process must know what you do with it, before entrusting it to you. The privacy policy is the usual form of that information.
So it is not a contract, nor a liability waiver. Writing « by using this website you accept our policy » authorises you to do nothing more. What the document must do is describe reality. A perfect document describing a practice different from yours is a false document.
A reassuring corollary for a small business: if you collect almost nothing, your policy can be short. A brochure website with a simple contact form does not need eight pages.
The eight sections, and how to fill them
- Who is responsible. The company name, address and a contact. For a small business, the same entity as in the legal notice.
- What data, and through what means. List the actual fields of your forms. « Name, email address, message » is a complete answer for many websites.
- Why. One purpose per use: answering a request, sending a newsletter, issuing an invoice. A vague purpose such as « improving our services » is not one.
- On what basis. Consent for a newsletter, performance of a contract for an order, legitimate interest for answering an inbound request, legal obligation for an invoice.
- For how long. A figure, not « as long as necessary ». Three years after the last contact for a commercial enquiry is common practice.
- Who else has access. The section most often wrong, see below.
- Transfers outside the European Union, if any, and on what legal basis they rest.
- The person's rights and how to exercise them: access, rectification, erasure, objection, and the option of lodging a complaint with the supervisory authority.
The two mistakes that make the document false
1. Copying a template without adapting it. The symptom is easy to spot: your policy mentions processing you do not carry out, or a retention period nobody in your business applies. The text becomes an inaccurate statement, which is more awkward than having no text.
2. Forgetting the real recipients. This is the most widespread mistake, and it is unintentional. People hear « recipient » and picture selling a database. But a recipient is also any tool that sees the data pass: the host, the email sending service, the audience measurement tool, the font loaded from a third-party server, the form service, the booking widget.
Each of those calls transmits at minimum the visitor's IP address, and sometimes more. Many are based outside the European Union, which triggers the transfers section. That is precisely why self-hosting your fonts, a purely technical move, also simplifies the legal document.
Taking inventory of what your website calls
Before writing the recipients section, you need to know what your pages actually call. Two methods.
By hand: open your website, press F12, Network tab, then reload. The domain column gives you the list of everything the visitor's browser contacted. Look at the names that are not yours.
Automatically: our free audit takes that reading and returns two figures, the number of third-party domains called and the number of services based outside the European Union, with their names.
That inventory serves twice: to write an accurate policy, and to decide what must go behind consent. The second point is covered in the article on cookies and trackers.
The contact form case, the most common one
Nine small-business websites out of ten have a single data processing activity: a contact form. Here is what an honest policy looks like in that case, in a few lines, to show that eight pages are not needed.
The data is the form fields, and nothing else: name, email address, possibly phone, and the message. The purpose is to answer the enquiry. The basis is legitimate interest, since the person wrote to you on their own initiative: it is not consent, so there is no tick box to add. The duration is yours to choose and to write down, for example three years after the last exchange for a commercial enquiry, or the length of the contract if it goes ahead.
The recipients are your website host and your email provider, and they must be named. If the form goes through a third-party service, it joins the list, and if that service is based outside the European Union, the transfers section is triggered.
Two points often missed on this otherwise simple case:
- A newsletter tick box is not the same thing as a contact form. Signing up to a newsletter is a separate processing activity, with its own basis, consent, and its own way to withdraw. The box must be unticked by default and separate from sending the message.
- Messages end up in a mailbox, which keeps them indefinitely unless someone clears it out. The duration you state must match a real practice, or your document becomes false again.
What our audit measures
The privacy and trackers category holds 6 checks: presence of analytics trackers, cookies set on landing, consent collection when trackers are loaded, resources loaded from other domains with their list, transfers to services based outside the European Union with their list, and server location. The legal compliance category, with its 2 checks, separately verifies that the legal pages exist and are reachable in one click.
What the audit does not do: it does not read your privacy policy and does not verify that it correctly describes the processing it detected. It gives you the raw material, that is, the real list of services your pages call; comparing that with your document remains human work.