Do I need a privacy policy if I don’t collect personal data?
The short answer is yes. You still need a privacy policy even if you don’t collect data, because it’s the policy itself that states your app or website doesn’t collect personal information.

A privacy policy informs your users what data you collect (or don’t collect), how it will be stored and used, and what rights they have over it. Even though it’s a legal requirement, it also demonstrates to your users that you handle data transparently, and are worthy of their trust.
Third parties such as Google, Facebook, or Mailchimp gather user data. So if you use any third-party services, you should have a privacy policy that communicates what data those third parties collect and how it’s used. If you don’t collect personal data and don’t use third-party tools, you still need a privacy policy that explains that position clearly to your users.
The General Data Protection Regulation (GDPR) is the primary privacy law regulating how entities manage user data. In this article, we’ll cover:
- What is GDPR?
- What are the privacy requirements in the EU, Australia, and Canada?
- Do I need a privacy policy to use Google Analytics?
- What needs to go into my privacy policy to be GDPR compliant?
What Is GDPR?
The General Data Protection Regulation outlines the requirements for collecting data from residents of the European Union. It safeguards the rights of EU citizens over the use and control of their data, regardless of whether the entity collecting it is inside or outside the EU.
Alongside the GDPR, the Organisation for Economic Co-operation and Development (OECD) provides guidelines for protecting privacy and cross-border flows of personal data. The 2013 OECD guidelines guide its 37 member countries on data protection law, covering issues like private data storage, abuse, and unauthorised disclosure, while also supporting the free flow of data for sectors like banking and insurance.
The GDPR and OECD guidelines are complementary and broadly similar: the main difference is that OECD guidelines steer member countries’ own laws, while the GDPR applies more directly to website and app owners. The GDPR protects EU residents specifically, while OECD guidelines are cross-cutting, given the organisation’s members span multiple continents.
What Are the Privacy Requirements in Australia, Canada, and the United States?
Australia’s Privacy Act outlines the legal framework for data privacy, requiring entities operating in Australia to have a privacy policy and limiting data collection to what’s relevant to the business. Users have the right to know why their data is collected, who handles it, and who has access to it, and entities are responsible for ensuring the data isn’t lost or misused.
In Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) protects Canadians against institutions misusing collected data, requiring website and app owners to get user agreement for data collection, use, and disclosure, and to use the data only for the purpose stated. Canada’s Privacy Commissioner handles complaints about institutions that misuse personal data.
Do I Need a Privacy Policy to Use Google Analytics, AdWords, or AdSense?
Yes. Google requires a privacy notice to access free tools like Analytics, AdWords, and AdSense. Analytics gives you insight into who your users are, what parts of your site they find useful, where they come from, and your traffic sources; but using it, or monetising your content through AdSense, requires disclosing this in your privacy policy, since Google needs to monitor and monetise the behaviour of the people using your platform.
What Needs to Go Into My Privacy Policy to Be GDPR Compliant?
Even if you don’t intend to collect data, your privacy policy must include:
- The scope of your privacy policy
- An explanation that you don’t collect data
- Whether you share data with third parties
Scope of the Privacy Policy
Larger companies typically define the scope of their privacy policy clearly, for example, stating which groups of people it covers (site visitors, event attendees, business partners, and so on). Your own policy should do the same: state plainly who it applies to and what it covers.

Explain That You Do Not Collect User Data
If your platform genuinely doesn’t collect or store any user data or messages, your privacy notice should explain exactly how and why that’s the case.

Indicate If You Share Data With Third Parties
Even if you don’t collect data directly, you may still use a third-party analytics tool that does. Your privacy notice should indicate what data that third party collects and how it’s used.

Conclusion
You can opt for an elaborate privacy policy or a short one, depending on your business. You might even have a summary version alongside a more detailed notice. Either way, having a privacy notice is essential to comply with the legal requirements of the country your business operates in, and the countries your target audience is located in.
Our free privacy policy generator will provide you with a customisable, lawyer-drafted privacy policy to cover your business’s requirements.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.