Does your privacy notice describe what you really do?
A privacy notice is only worth anything if it's true. A polished template that names processors you don't use, or omits the analytics you actually run, is theater — and under the EU GDPR it's also a compliance risk, because the law expects the document to match reality. The goal is an honest, plain-language account of what your site genuinely does with people's data.
Make it match reality
Walk your own site and write down what actually happens, then make the notice reflect that. There's no single fixed checklist, but it usually covers:
- Who you are — the data controller's identity and contact details.
- What you really collect — the specific form fields, analytics identifiers, cookies, and log data your site uses, not a generic list.
- Why, and on what legal basis — consent, contract, or legitimate interest.
- Who you share it with — your hosting, email, and analytics providers, plus the easily-forgotten ones: CDNs, CAPTCHA and anti-spam services, payment providers, and embedded third parties like maps, fonts, or video. Name them or give categories of recipient. Some act as your processors, but others may be independent or joint controllers, so don't label them all "processors".
- How long you keep each type of data — real retention periods, or the criteria you use to decide when an exact period can't be stated, rather than a bare "as long as necessary".
- How users exercise their rights — access, correction, deletion, objection — and the route to do it.
- International transfers, if any data leaves the EU/EEA.
If you add or drop a tool, update the notice. A policy that drifts out of sync with your stack is back to being fiction.
Cookies and consent
Under ePrivacy and national cookie rules, prior consent is generally required before non-essential storage or access — advertising, analytics, or personalization trackers, and similar technologies such as localStorage or fingerprinting — while strictly necessary cookies (session, security) generally don't need it. What actually applies depends on the technology and the applicable national law, so check it; and note that the GDPR separately governs any personal data you then process. Where consent is required, your banner must actually enforce the choice, not just describe it.
Takeaway: A privacy notice must describe what you truly do — real data, real processors, real retention, real rights — in plain language, with non-essential cookies gated behind genuine consent.
What to do
- Audit what your site really collects and shares — every form, script, cookie, and processor — before writing a word.
- Adapt a reputable template to those actual findings, in plain language, covering the points above.
- State real retention periods (or your criteria for deciding) and the actual recipients you share data with; don't leave placeholders in.
- Where consent is required, deploy a real banner that blocks non-essential scripts until the user accepts, making it as easy to reject as to accept.
- Make it easily accessible — a footer link on every page, and wherever you collect personal data (forms, signups) — and date it.
- Revisit it whenever your data flows change so the notice never lies.
Frequently asked questions
- Can I just copy another site's privacy policy?
- No. A generic template detached from your real data flows is theater and can be worse than nothing. It must reflect what you actually collect, who you share it with, and how long you keep it. Adapt a template, don't paste it.
- What should a privacy notice cover?
- There's no single fixed checklist, but it typically covers who you are, what data you collect and why, the legal basis, the recipients (or categories of recipient) you share it with, how long you keep it (or the criteria for deciding), how users exercise their rights, and any transfers outside the EU/EEA — all matching what your site really does.
- Do all cookies and similar technologies need consent?
- It depends. Strictly necessary cookies for session and security generally don't need consent, while prior consent is generally required for non-essential storage or access — advertising, analytics, or personalization trackers, and equivalents like localStorage or fingerprinting — unless an exemption applies. Check the actual technology and the applicable national law.
Was this helpful?
Questions about your own site? Get in touch — we read every message.
Source: “Does your privacy notice describe what you really do?” — https://www.siteadvice.be/tips/publish-a-privacy-policy/ · © 2026 EUREGIO.NET AG. All rights reserved.