The median privacy policy ran 1,522 words in 2019, the most recent year covered by a 2021 Princeton and KU Leuven analysis of more than one million archived policies, nearly double the 876-word median from a decade earlier. Length has kept climbing since, driven in large part by the disclosure requirements the GDPR introduced in 2018. This page breaks the number down by percentile, tracks the trend by year, and covers how long an average policy actually takes to read.

Median privacy policy length grew from 876 words in 2009 to 1,522 in 2019 876 1,522 2009 2019 median policy length,in words: nearly doubledin a decade

How many words are in the average privacy policy?

The median privacy policy contained 1,522 words in the second half of 2019, according to the Princeton and KU Leuven dataset described above, built from 1,071,488 English-language privacy policies collected across more than 130,000 websites. A single average understates how much policies vary in practice: the shortest 5% ran 248 words or fewer, while the longest 5% reached 3,404 words or more, a spread of more than 13-fold between the two ends.

PercentileWord count (2019)
5th percentile248 words
Median (50th)1,522 words
95th percentile3,404 words

A policy sitting at the median is roughly three pages of single-spaced text. One at the 95th percentile runs well past what most readers will scroll through in one sitting, regardless of how the content is organized.

How has privacy policy length changed since 2009?

Length grew gradually for most of the decade the researchers tracked, then accelerated. The median word count moved from 876 words in the first half of 2009 to 1,522 words by the second half of 2019, and the increase became noticeably sharper after 2018, when GDPR's disclosure requirements took effect across the EU and, in practice, in many privacy policies written for a global audience. The pattern held for both popular and less-popular websites in the dataset, not just the largest platforms.

Figure 1: Milestones in privacy policy length research and regulation. Source: FTC (2000), McDonald and Cranor (2008), Degeling et al. (2019), Amos et al. (2021).

Did the GDPR make privacy policies longer?

The evidence points to yes, and from two independent research teams measuring different samples. A GDPR compliance study covering the top 500 websites in each of the 28 EU member states, 6,759 sites in total, found the median privacy policy grew from 2,145 words in 2016 to 3,044 words in 2018, the year GDPR's disclosure rules became enforceable, and tied the jump directly to the new regulation. The Princeton and KU Leuven team's own global sample shows a comparable pattern using a separate methodology: the median for the worldwide top 1,000 websites grew from 2,691 words in 2016 to 3,303 words in 2018, and the top 10,000 grew from 2,122 to 2,651 words over the same span.

Median privacy policy word count, 2016 vs 2018 01,0002,0003,0004,000 wordsTop 1,000 sitesTop 10,000 sites20162018

Figure 2: Median privacy policy word count for the global top 1,000 and top 10,000 websites, 2016 versus 2018. Source: Amos et al., "Privacy Policies over Time" (WWW '21, 2021).

The two studies do not agree on an exact word count, because a top-500-per-country EU sample and a global top-1,000/top-10,000 sample are not the same population of websites. Both agree on the direction and the rough scale of the change: privacy policies got noticeably longer in the year GDPR's specific disclosure requirements, covering legal basis, data transfers, retention periods, and individual rights, became something regulators could actually enforce.

How readable is the average privacy policy?

Word count is only part of the story. The median Flesch-Kincaid grade level required to read a privacy policy climbed from 11.9 in 2009 to 13.2 by 2019, more than a full grade level higher and above a typical first-year college reading level, in the same Princeton and KU Leuven dataset. The researchers also found that more-popular websites carry less-readable policies than smaller, less-trafficked ones, the opposite of what a "policies aimed at the widest audience should be the clearest" assumption would predict.

Median reading grade level required, 2009 vs 2019 20092019Flesch-Kincaid grade level 11.913.2

Figure 3: Median Flesch-Kincaid grade level required to read a privacy policy, 2009 versus 2019. Source: Amos et al., "Privacy Policies over Time" (WWW '21, 2021).

For a point of comparison, a separate 2012 study by Li and colleagues, cited within the Princeton and KU Leuven paper, measured an average Flesch-Kincaid grade level of 13.33 for the privacy policies of the 30 Dow Jones Industrial Average companies, a figure the later researchers described as consistent with their own measurements for the most popular websites.

How long does it take to read a privacy policy?

At the standard reading rate of 250 words per minute, a rate the Carnegie Mellon researchers Aleecia McDonald and Lorrie Faith Cranor used because it reflects a typical reader with a high-school education, a median-length privacy policy takes about 10 minutes to read from start to finish. Their 2008 study measured word counts across the 75 most popular websites of the time and calculated reading time for three length tiers.

Policy length tierWord countTime to read
Short (25th percentile)2,071 words8 minutes
Medium (median)2,514 words10 minutes
Long (75th percentile)3,112 words12 minutes

The same study estimated what this costs at a national scale. If every American internet user read the privacy policy of every website they visited once a year, word for word, McDonald and Cranor put the value of that lost time at roughly $781 billion annually, based on an estimated 244 hours per person per year and Bureau of Labor Statistics wage data from 2008. Their lower-bound estimate was $560 billion; their upper-bound estimate topped $1.1 trillion.

Most site owners are not trying to make a policy harder to read. Length usually creeps in from years of legal additions layered on top of each other rather than any deliberate choice. If your own policy has grown well past the 1,522-word median without getting any clearer for it, generating a plain-language document from scratch is often faster than trying to prune an old one down: you can build a GDPR- and CCPA-ready privacy policy that covers legal basis, data transfers, and retention periods in the fewest words that still meet current disclosure requirements.

Do people actually read privacy policies before agreeing to them?

Rarely, and the pattern has held for years. Only 9% of US adults say they always read a privacy policy before agreeing to it, according to a 2019 Pew Research Center survey of 4,272 US adults conducted in June 2019. Another 13% say they often read one, 38% say they sometimes do, and 36% say they never do.

How often US adults read privacy policies before agreeing 38%36%13%9%Sometimes38%Never36%Often13%Always9%

Figure 4: Self-reported frequency of reading privacy policies before agreeing, among US adults. Source: Pew Research Center, "Americans and Privacy" (2019, n=4,272).

The share who say they never read a policy at all (36%) is close to four times the share who say they always do (9%), a gap that has changed little across the years Pew has asked the question.

How was this data actually measured?

The headline 1,522-word figure comes from a purpose-built research corpus, not a survey or a manual sample. The Princeton and KU Leuven team built a crawler that pulled archived homepage snapshots and linked privacy policy pages from the Internet Archive's Wayback Machine, covering websites that appeared in Alexa's top 100,000 list at any point between 2009 and 2019.

1.07 million English-language privacy policies in the research corpus 1.07M English-language privacy policiesin the underlying research corpus

Figure 5: Scale of the underlying research corpus behind the word count and readability figures on this page. Source: Amos et al., "Privacy Policies over Time" (WWW '21, 2021).

Not every homepage yielded a usable policy. A related finding from the same crawl, covered in more detail in how many websites actually carry a detectable privacy policy link, is that link discoverability itself varies by site popularity, which is part of why the researchers built a classifier to confirm each downloaded document was genuinely a privacy policy before including it in the length and readability figures used throughout this page.

The Bottom Line

The average privacy policy has grown from 876 words in 2009 to 1,522 words in 2019, and gotten harder to read at the same time, climbing more than a full grade level on the Flesch-Kincaid scale. GDPR's 2018 disclosure requirements accelerated a trend that was already underway rather than starting it, and two independent research teams measured a comparable jump using different site samples. None of this length has translated into more people actually reading the document: only 9% of US adults say they always do. For anyone maintaining a privacy policy today, the practical lesson is not to chase brevity for its own sake but to make sure every added disclosure earns its place, since a policy that has quietly grown past 1,522 words without becoming any clearer is the exact pattern this data describes.

Frequently Asked Questions

How many words is the average privacy policy? The median privacy policy contained 1,522 words in the second half of 2019, the most recent measurement in a Princeton and KU Leuven study of more than one million archived policies. That is nearly double the 876-word median measured a decade earlier, in the first half of 2009.

Did the GDPR make privacy policies longer? Yes. A compliance study covering the top 500 websites in each of the 28 EU member states found the median policy grew from 2,145 words in 2016 to 3,044 words in 2018, the year GDPR's disclosure rules took effect. The Princeton and KU Leuven dataset shows the same jump in its own top 1,000 and top 10,000 site samples.

How long does it take to read the average privacy policy? About 10 minutes for a median-length policy of 2,514 words, using the standard 250 words-per-minute reading rate applied in a 2008 Carnegie Mellon study of the 75 most popular websites. Longer policies at the 75th percentile, 3,112 words, take about 12 minutes.

Do most people actually read privacy policies before agreeing to them? No. Only 9% of US adults say they always read a privacy policy before accepting it, and 36% say they never do, according to a 2019 Pew Research Center survey of 4,272 adults.

Where the Numbers Come From

  1. Amos, Acar, Lucherini, Kshirsagar, Narayanan, and Mayer. (2021). "Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset." Proceedings of the Web Conference 2021 (WWW '21). 1,071,488 English-language privacy policies from over 130,000 websites, snapshots spanning 2009 to 2019.
  2. McDonald, Aleecia M. and Cranor, Lorrie Faith. (2008). "The Cost of Reading Privacy Policies." I/S: A Journal of Law and Policy for the Information Society, 2008 Privacy Year in Review issue. Word counts and reading times for the 75 most popular websites, based on October 2005 site-ranking data.
  3. Pew Research Center. (2019). "Americans and Privacy: Concerned, Confused and Feeling Lack of Control Over Their Personal Information." Survey of 4,272 US adults, conducted June 3 to 17, 2019.
  4. Degeling, Utz, Lentzsch, Hosseini, Holz, and Schaub. (2019). "We Value Your Privacy ... Now Take Some Cookies: Measuring the GDPR's Impact on Web Privacy." Network and Distributed System Security Symposium (NDSS 2019). Top 500 websites per EU member state, 6,759 sites total, measured before and after GDPR.

Note: All figures verified as of July 2026. The Amos et al. dataset covers archived snapshots through 2019, the most recent large-scale academic measurement of privacy policy word count and readability publicly available at the time of writing. This page will be refreshed if a comparable large-sample study covering more recent years is published.