A privacy policy should describe what an organization actually does with personal information. Drafting from a generic template before mapping forms, analytics, vendors, accounts, logs, and retention often produces a policy that is polished but inaccurate. Start with the data flow, then obtain jurisdiction-specific legal review where needed.
This is an operational checklist, not legal advice. Privacy obligations vary by location, audience, industry, business size, contract, and data type. A qualified professional should review the final disclosures and consent mechanisms that apply to the organization.
1. Inventory every collection point
Walk through the site as a new visitor, customer, account holder, staff member, and administrator. Record information collected directly and information produced automatically.
- Contact, quote, booking, application, newsletter, survey, review, and support forms
- Account registration, authentication, profile, order, payment, and document workflows
- Cookies, local storage, analytics, advertising, embedded media, chat, and session tools
- Server logs, security events, device data, IP addresses, and fraud signals
- Uploads, free-text fields, call transcripts, photos, signatures, and location information
- Information received from integrations, referral partners, public sources, or data providers
2. Build a data-practice table
| Data category | Source | Purpose | Recipient/system | Retention trigger |
|---|---|---|---|---|
| Contact request | Website form | Respond to the request | Form provider and service team | Request resolved plus approved period |
| Account record | User registration | Provide and secure the account | Application and identity provider | Account closure plus required period |
| Usage event | Analytics tool | Understand site use | Analytics provider | Configured event/user retention |
| Security log | Server or application | Detect and investigate misuse | Host and security team | Log period tied to investigation need |
If the team cannot name a purpose and owner, pause the collection. The FTC's guide to protecting personal information recommends taking stock, keeping only what the business needs, protecting it, disposing of it properly, and planning for incidents.
3. Explain collection in plain language
Group data in terms a reader can recognize. Explain whether it is provided, collected automatically, or received elsewhere. Avoid saying the site collects only "non-personal" information if identifiers, device data, precise location, account events, or combined datasets can relate to a person or household under applicable rules.
4. State specific purposes
Purposes should be concrete enough to govern behavior: fulfill a request, operate an account, process a transaction, prevent abuse, meet a legal obligation, improve a feature, or send a chosen communication. Phrases such as "for any business purpose" provide little meaningful notice.
Match choices to reality. If marketing is optional, make the operational flow work without it. If data is used to train or evaluate an automated system, disclose and review that practice specifically rather than hiding it inside a general improvement clause.
5. Identify sharing and service providers
List categories of recipients and explain why information moves to them. Review hosting, analytics, email, CRM, payments, scheduling, support, fraud, advertising, document, call, and backup providers. A statement that the business "does not share" data can be misleading if service providers routinely process it.
- Document the vendor, data categories, purpose, location, contract owner, and deletion path.
- Distinguish operational providers from advertising or unrelated third-party uses.
- Explain business transfers, legal requests, safety, and fraud disclosures accurately.
- Confirm that embedded tools do not collect more than the policy describes.
6. Address cookies and similar technologies
Inventory technologies before writing a cookie section or deploying a consent banner. Categorize purpose, provider, duration, and whether a choice is required. Make the consent interface and policy agree. A banner that claims to reject optional tracking while loading it first is not an accurate control.
7. Publish a retention approach the business can follow
A policy can describe retention criteria rather than an exact number for every record, but the internal schedule needs enough detail to operate. Use the data retention policy guide to define triggers, periods, holds, backup behavior, deletion methods, and owners.
8. Explain choices, rights, and contact routes
Describe applicable ways to unsubscribe, change account information, manage cookies, request access or deletion, appeal a decision, or contact the privacy team. Do not promise a right or response time the organization cannot administer. Verify identity proportionately and avoid collecting excessive new information to process a request.
9. Cover security without making guarantees
Describe reasonable safeguards at an appropriate level without publishing exploitable detail. Avoid absolute claims such as "completely secure." Link policy commitments to the small-business security baseline and, for WordPress sites, the WordPress-specific checklist.
10. Review audience and special contexts
Assess children and teens, employees and applicants, health or financial information, precise location, biometrics, regulated services, international transfers, and users in multiple jurisdictions. These contexts can require different notices, consent, contracts, or operational controls. Do not infer that a generic website policy covers them.
11. Make changes traceable
- Display an effective or last-reviewed date that reflects a real review.
- Keep prior versions and a change log.
- Define which material changes require additional notice or consent.
- Trigger review when a form, vendor, cookie, purpose, audience, acquisition, or law changes.
- Give one owner authority to block launches that the policy and controls do not cover.
Pre-publication test
- Can every statement be tied to a system, contract, configuration, or procedure?
- Do the forms and just-in-time notices match the policy?
- Do cookie choices work before and after consent?
- Can staff complete the rights and deletion processes described?
- Would a direct reader understand what happens without needing legal vocabulary?