A Privacy Policy and a Terms and Conditions agreement are both legal documents that are useful for any business or website. A Privacy Policy is required by law if you collect and process personal information, while a Terms and Conditions agreement sets the guidelines for using your site and helps limit legal liability. Let’s take a closer look at the differences between, and purpose of, both agreements.

The Key Differences

Privacy PolicyTerms & Conditions
Legally required as soon as you collect any personal dataNot legally required, but helps limit legal liability
Protects your usersProtects your business, limits liability
Outlines your collection, use, and storage of personal dataSets rules and guidelines for your website
Includes: data collection, personal data, non-personal data, sharing your data, retaining and deleting personal data, users’ rights, users’ data protection, international transfer, cookie policy, data securityIncludes: users’ rights and responsibilities, refund policy, governing law, limitations of liability, DMCA notices, indemnity, dispute resolution and arbitration, minimum age requirements, copyright notices, termination

Privacy Policy

A Privacy Policy is required by law if you collect and process personal information on your website. It outlines how and why you collect personal data, what you use it for, how you secure it, and where it is stored.

Personal data is any information that enables the identity of a person: a full name, address, date of birth, license number, or email address are all examples.

There are also a number of international laws a Privacy Policy should comply with. The main ones are GDPR, CalOPPA, COPPA, and CCPA.

GDPR

GDPR General Data Protection Regulation

The General Data Protection Regulation is an EU privacy law that aims to protect the privacy of EU residents. It requires that you inform your users of their data protection rights and that you’re transparent in your collection and use of their personal data.

Given the nature of the internet, regardless of where your website is located, you’ll likely need to cover these laws in your Privacy Policy, since you probably have users or customers from these regions. For more, see our article on GDPR compliance.

CalOPPA

The California Privacy Rights Act requires that your Privacy Policy be conspicuous, so your users and customers have easy access to it, and that it includes the word “privacy.”

CalOPPA also permits California residents to request information about your use of their personal information being disclosed to third parties for direct marketing, and permits users under 18 to request removal of content or information they’ve posted publicly.

COPPA

The Children’s Online Privacy Protection Act requires that websites and online services disclose whether they knowingly collect personal information from children under the age of 13.

If your website doesn’t target children under 13, you need a clause in your Privacy Policy stating this, and you should avoid collecting age-related information on your site.

CCPA

The California Consumer Privacy Act strengthens the rights of California residents by giving them the right to:

  • Know what personal data is being collected about them
  • Know whether their personal data is sold or disclosed, and to whom
  • Say no to the sale of personal data
  • Access their personal data
  • Request that a business delete any personal information collected about them
  • Not be discriminated against for exercising their privacy rights

What should be included in a Privacy Policy?

  • Data Collection: what data is collected and processed
  • Security: how personal information is kept secure
  • Personal Information: the types of personal information your website collects and processes
  • Cookies: an explanation of cookies and your website’s use of them
  • Data Protection Rights: the data subject’s rights
  • Contact Information: contact details for your company, and for your Data Processing Officer and Data Controller if applicable
  • And more

Terms and Conditions Agreement

Terms and Conditions agreement

A Terms and Conditions agreement, also known as a Terms of Service contract, is a set of rules and guidelines your users and customers need to follow when using your website or service. Without one, how will you enforce appropriate use of your site?

What should be covered in your Terms and Conditions agreement?

  • Governing law: what country or state law your company is governed by
  • Users’ rights and responsibilities: the rules governing use of your website
  • Confidentiality clause: a clause outlining that information collected through the relationship via the website is not to be disclosed to third parties unless permitted
  • Security: the forms of security you employ on your website
  • Copyright notice: copyright and other intellectual property rights over the content of the website
  • Refund policy: your company’s policy on refunds, if any
  • Termination clause: the conditions for terminating the agreement between both parties
  • And much more

Although a Terms and Conditions agreement isn’t currently required by law, there are good reasons to have one: it informs your users of their rights and responsibilities, helps protect your content via a copyright clause, and builds trust by clearly setting out what’s required of users and what policies apply to situations like refunds and account termination.

Combined or Separate Agreements?

You may wonder whether you need separate Privacy and Terms and Conditions documents, or whether you can combine them into one. The answer is definitely separate.

First, a combined document would be overwhelmingly long for your users to read through. Second, a Privacy Policy is a legal requirement while a Terms and Conditions agreement is not. Third, it’s much easier for users to find the information they need when the two documents are separate; they can go straight to the Privacy Policy for questions about their data, or the Terms and Conditions for the rules of using your service.

Conclusion

When running an online business or website, it’s both legally required (for your Privacy Policy) and generally safer (for your Terms and Conditions) to have both documents in place. Make sure they’re accessible and clearly labelled so your users can find them easily.

Generate your own Privacy Policy and Terms and Conditions agreement using our free generators.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.