Privacy Policy

A Privacy Policy is a legal statement that specifies what the business owner does with the personal data collected from users, along with how the data is processed and for what purposes.

In 1968, Council of Europe did studies on the threat of the Internet expansion as they were concerned with the effects of technology on human rights. This lead to the development of policies that were to be developed to protect personal data.

This marks the start of what we know now as a “Privacy Policy.” While the name “Privacy Policy” refers to the legal agreement, the concept of privacy and protecting user data is closely related.

This agreement can also be known under these names:

  • Privacy Statement
  • Privacy Notice
  • Privacy Information
  • Privacy Page

A Privacy Policy can be used for both your website and mobile app if it’s adapted to include the platforms your business operates on.

The requirements for Privacy Policies may differ from one country to another depending on the legislation. However, most privacy laws identify the following critical points that a business must comply with when dealing with personal data:

  • Notice – Data collectors must clearly disclose what they are doing with the personal information from users before collecting it.
  • Choice – The companies collecting the data must respect the choices of users on what information they choose to provide.
  • Access – Users should be able to view, update or request the removal of personal data collected by the company.
  • Security – Companies are entirely responsible for the accuracy and security (keeping it properly away from unauthorized eyes and hands) of the collected personal information.

Who needs a Privacy Policy

Any entity (company or individual) that collects or uses personal information from users will need a Privacy Policy.

A Privacy Policy is required regardless of the type of platform your business operates on or what kind of industry you are in:

The basics of a Privacy Policy

Flag of EU

In the EU, the GDPR requires companies dealing with EU citizens to have a Privacy Policy.

This law became enforceable in early 2018 and has affected businesses around the world. Not only does it require a Privacy Policy, but it has requirements for what must go into a Privacy Policy and how it must be written and displayed.

As a general rule, if you’re compliant with Privacy Policy requirements of the GDPR, you’ll by default end up complying with most other privacy laws around the world. That’s because the GDPR is so robust and comes with stringent requirements.

US Flag

In the US, privacy legislation may vary from one state to another. Certain federal laws govern users’ data in some circumstances, such as in these examples:

  • The Gramm-Leach-Bliley Act – This act obliges organizations to offer clear and accurate statements about their information collecting practices and it also limits usage and sharing of financial data.
  • COPPA – This act is especially for businesses that collect information about children under 13 years of age.
  • Health Insurance Portability and Accountability Act – This act applies to online health services as well.
  • California Online Privacy Protection Act (CalOPPA) – California’s privacy law affects anyone collecting personal information from residents of California.
  • SOPIPA – This act applies if you collect personal data from students.
  • Content Eraser law – This law applies if you collect data from minors (under the age of 18).

Canada Flag

In Canada, there’s the Personal Information Protection and Electronic Documents Act (PIPEDA)generated by federal privacy laws.

This law established acceptable standards to limit and organize personal data gathering, usage, and disclosure by commercial institutions. This means that organizations may gather, use and disclose that percent of information for purposes that a reasonable person would consider fit in the circumstance.

The Privacy Commissioner of Canada stands for receiving and peacefully taking care of complaints against organizations. Its purpose is to solve privacy matters through compliance, not through enforcement. It reaches complaints, spreads the importance of awareness of and conducts studies about privacy issues.

Australia Flag

In Australia, the Privacy Act requires Australian companies to have a Privacy Policy.

Before you draft this agreement for your business, consider the basic requirements for most online businesses that deal with personal data from users (this includes SaaS apps or Facebook apps as well):

  • That the privacy of your users is protected.
  • That you take full responsibility to protect the privacy of your users.
  • That you comply with active privacy laws.

What to include in your Privacy Policy

Download our Privacy Policy template by clicking here. It’s free.

Users need to know exactly what kinds of personal data you collect from them.

Your Privacy Policy must also disclose why you collect this kind of data. Some examples include:

  • To help develop new services or improve your existing services
  • To send users emails about special offers, new services or other information they may be interested in
  • To personalize their sessions on your website in order to better fit their interests, such as offering them relevant, individually tailored content

If you already have a Privacy Policy for your website and you’re now launching a mobile app, you need to first consider what new types of personal data you’ll be collecting through the mobile app.Then, update your agreement to include the new changes: what you collect from the website and from the mobile app.

You should always inform users about any updates or changes to your Privacy Policy.

Disclose if any third parties are involved in collecting personal information in your name, i.e. you use MailChimp to collect email addresses to send weekly updates to your members.

Here are a few examples of common sections of a Privacy Policy:

  • The Information Collection and Use section is the most important section of the entire agreement where you need to inform users what kind of personal information you collect and how you are using that information.

    Here’s how Asana, a project management tool, informs users that the tool collects personal information:

    Asana Privacy Policy: Information We Collect section intro

    The policy goes on to inform users about what kinds of information they may provide and how (by becoming a member, by connecting through Facebook, Twitter etc.):