What a privacy policy must say

Learn the essential components of a privacy policy. This guide covers legal requirements, data collection disclosures, and user rights in the US, EU, and India.

6 min readUpdated September 2026

The short answer

A privacy policy is a legal document that explains how a company collects, uses, and protects personal data. To be legally compliant under laws like the GDPR or CCPA, it must clearly state what information is gathered, the purpose of processing, and how long data is stored. It also needs to outline user rights, such as the ability to access or delete information, and provide contact details for the data controller to ensure transparency and trust.

Have the contract in front of you? upload it for a free contract review with Lawly AI and see the exact wording in your own document.

Identity and Data Collection

The policy must begin by clearly identifying the entity responsible for the data. This means providing the legal name of the company and contact information for the data protection officer or a relevant department. Transparency about who is handling the data is a foundational requirement under modern privacy frameworks.

You must explicitly list the types of information being collected. This includes personal identifiers like names and emails, technical data like IP addresses, and sensitive information such as financial or health data. If you use cookies or tracking pixels, these must be disclosed here or in a separate linked policy.

  • Full legal name and contact address
  • Types of personal data collected
  • Methods used for data collection
  • Use of cookies and tracking technologies
  • Disclosure of third-party tracking tools

Purpose and Legal Basis

It is not enough to say you collect data; you must explain why. Jurisdictions like the EU and UK require a specific 'legal basis' for processing, such as fulfilling a contract, legal obligation, or legitimate interest. In India and the US, clear disclosure of the intended use prevents claims of deceptive trade practices.

Common purposes include processing orders, improving website performance, or sending marketing communications. If you plan to sell data or share it with advertisers, this must be stated in unambiguous terms to avoid regulatory penalties and lawsuits.

  • Specific business purposes for processing
  • Legal basis for each processing activity
  • Intent to use data for marketing or profiling
  • Circumstances for sharing data with third parties
  • Handling of data during a business sale or merger

Storage and Data Transfers

Data retention periods must be defined. You should only store personal information for as long as it is necessary to achieve the stated purpose. Once that period ends, the data should be securely deleted or anonymized to protect the user's privacy.

International data transfers are a major compliance hurdle. If a company in the EU sends data to servers in the US or India, they must disclose the safeguards in place to ensure the data remains protected. This often involves standard contractual clauses or adequacy decisions by regulatory bodies.

  • Duration of data retention
  • Criteria for determining storage periods
  • Security measures to prevent data breaches
  • Details on international data transfers
  • Safeguards for cross-border processing

Individual User Rights

Modern laws grant users significant control over their information. Your policy must detail how users can exercise these rights. In many jurisdictions, users have the right to access, rectify, or delete their data, as well as the right to object to certain types of processing like automated decision-making.

The policy should provide a simple process for these requests, such as a dedicated email address or an online form. Failing to provide a clear mechanism for users to exercise their rights can lead to significant fines from data protection authorities.

  • Right to access and portability
  • Right to correction or deletion
  • Right to withdraw consent at any time
  • Right to lodge a complaint with authorities
  • Opt-out mechanisms for marketing

Jurisdiction Specific Clauses

Different regions have specific requirements. For example, the CCPA in California requires a 'Do Not Sell My Personal Information' link. The GDPR in Europe demands a high level of detail regarding the rights of data subjects and the role of the lead supervisory authority.

In India, the Digital Personal Data Protection Act emphasizes the role of 'Consent Managers' and requires notices to be available in multiple languages if applicable. Always ensure your policy is tailored to the physical location of your users, not just your company's headquarters.

  • CCPA specific disclosures for California users
  • GDPR compliance for European data subjects
  • DPDP Act requirements for Indian residents
  • COPPA compliance for children's data
  • Specific notices for financial or health data

Sample clause language

Illustrative wording, written for this guide — not copied from any real contract.

Overly Broad Collection
We collect any and all data we deem necessary for our business operations. By using this site, you agree that we may share your data with any of our partners or third parties for any reason, including marketing, at our sole discretion.

This is legally risky because it lacks specificity regarding data types, purposes, and third-party identities, which violates transparency requirements.

Transparent Disclosure
We collect your email address and name solely to process your subscription. We do not sell your data to third parties. You may request the deletion of your account at any time by contacting our support team at privacy@example.com.

This is balanced and compliant as it defines a specific purpose, limits sharing, and provides a clear path for users to exercise their rights.

Red flags to look for

  • Vague language like 'may use data for internal purposes' without definition
  • Hidden or difficult-to-find links to the privacy policy
  • Claims that the company owns user data outright
  • Lack of a clear date for the last update or version control
  • No method provided for users to delete their personal information
  • Pre-ticked boxes for marketing consent
  • Failure to mention third-party cookies or analytics tools

Not sure whether your contract has these problems? Lawly AI reads the whole document, quotes the risky wording back to you, and scores the overall risk in about a minute.

What to ask for

  • Specify the exact categories of data the service provider will access
  • Include a requirement for immediate notification in case of a data breach
  • Demand that data be stored only in jurisdictions with adequate protections
  • Limit the provider's ability to use aggregated data for their own marketing
  • Ensure the provider bears the cost of data deletion upon contract end

Check this in your own contract

Upload a PDF, Word file, or photo of your agreement and Lawly AI will pull out the clauses that matter, quote the exact wording, flag the deadlines, and explain the risk in plain English. Your first five documents are free.

Frequently asked questions

Is a privacy policy required by law?

Yes, in most jurisdictions including the US, EU, and India, if you collect personal data, you are legally mandated to have a privacy policy.

What happens if I don't have one?

You can face significant fines, lawsuits from users, and may be banned from using platforms like Google Play or the Apple App Store.

Do I need a separate cookie policy?

While you can include it in your privacy policy, many companies use a separate cookie policy to provide more technical detail on tracking technologies.

How often should I update my policy?

You should update it whenever your data practices change or when new privacy laws are enacted in the regions where your users live.

Related guides

This guide is general educational information about how these clauses usually work. It is not legal advice, and contract law differs by jurisdiction. For a decision that matters, speak to a qualified lawyer.