Need a data compliant Privacy Policy?

    One of the main requirements of data privacy laws is notifying users about the data you collect, by what means and for what purposes. Your Privacy Policy page is a common location to display that information. It also needs to be kept up to date as your website, the cookies and other tracking technologies you use, and the legal landscape change.

    The Cookiebot CMP can help. It detects, reports, and manages cookies with three powerful and automatic core functions. It helps enable you to accurately report your cookie usage and keep that information up to date.

    • Monitoring: stay up to date on the cookies and tracking technologies your website uses, enabling user notification and consent
    • Control: When required, prevent cookies from being used unless user consent has been obtained
    • Consent: Obtain and store informed, granular consent from users
    Cookie checker

    Frequently asked questions

    We cannot provide legal advice, and recommend consulting qualified legal counsel regarding your specific business and data processing situation.

    However, if your website collects the personal data of customers or visitors that reside in a country or region protected by data privacy regulations, especially if that data is shared or sold, then you most likely do need one. Small blogs can need a Privacy Policy page as much as a huge company's website or ecommerce operation does.

    If your website is hosted by a third-party company, or if you use plugins, social media or analytics tools, etc., then you are setting cookies and collecting user data that is potentially personal data.

    Personal data is information from or about people that can identify them. On websites it could include anything from name, email address, or credit card number, which a user could provide, to information that cookies collect, like IP address and browsing activities.

    Depending on what regulation(s) you need to comply with, the Privacy Policy will contain some variances in information. It should be in clear language that is understandable to the average person. Most commonly required in a privacy notice or policy are the specific details about what data you collect, by what means, and for what purposes. It is also common to provide information about users'/consumers' rights and how they can exercise them (and contact you to do so).

    Having a clear and comprehensive Privacy Policy is also an excellent way to build trust with users and show respect for their rights and consent choices.

    We cannot provide legal advice, and recommend consulting qualified legal counsel regarding your specific business and data processing situation. You should also review the Privacy Policy requirements of whichever privacy regulations are relevant to you. (E.g. for the GDPR.) However, there are a number of types of information that are commonly required in a Privacy Policy.

    A Privacy Policy should be:

    • presented in a format that is transparent, concise, understandable, and easily accessible
    • written in clear, plain language (especially if children's data is processed and privacy information must include them)
    • delivered in a timely manner (note that under some regulations, users must be informed before providing or declining consent, and both of these things must happen before data is collected)
    • provided free of charge

    As noted, your Privacy Policy's contents will be specific to your organization's regulatory responsibilities and data processing, however, the requirements laid out by the GDPR are comprehensive and a good guideline.

    • identity and contact details of the organization, its representative, and its Data Protection Officer (if the organization has a such an Officer)
    • purpose for the organization to process an individual’s personal data and its legal basis
    • legitimate interests of the organization (or third party, where applicable)
    • any recipient or categories of recipients of an individual’s data
    • details regarding any transfer of personal data to a third country and the safeguards taken
    • retention period or criteria used to determine the retention period of the data
    • existence of data subject’s' rights
    • information about the right to withdraw consent at any time (where relevant)
    • information about the right to lodge a complaint with a supervisory authority
    • whether the provision of personal data is part of a statutory or contractual requirement or obligation and the possible consequences of failing to provide the personal data
    • existence of any automated decision-making system, including profiling, and information about how this system has been set up, the significance, and the consequences

    As a Privacy Policy typically needs to communicate information about the categories of personal data the website collects, for what purposes, and for whom it's shared, it is necessary to know and be able to communicate all of the technologies, like cookies, that are collecting personal data on your website.

    Companies should keep track of this information, but if it changes often, or if the website uses third-party hosting or tools or services, it may not have full visibility into what those tools do or when they change. Changes or additions to this information also need to be updated in the Privacy Policy in a timely manner.

    Cookiebot CMP deep scans your website, finding and reporting on all the cookies and other tracking technologies in use. This enables you to notify users about them accurately. Regular scanning enables you to maintain the accuracy of this information. The Cookiebot CMP also enables you to block the use of cookies and trackers until you receive user consent for them, thus enabling privacy compliance with some regulations.

    Try it and scan your website for free.

    Show more

    Learn how easy it is to get your website privacy-compliant

    If you want to get your website compliant with the GDPR or other regulations, Cookiebot CMP is easy to set up, user-friendly to customize and uses powerful scanning technology to help you achieve and maintain privacy compliance for cookie use, and populate and maintain your Privacy Policy. Best of all, you can get started for free. Here's how.

    Trackpad icon - Cookiebot
    Icon shield
    Pepco
    rural-king
    orbico
    credit-exchange
    canon
    bauhaus
    Cookiebot bg shield