If it seems like everyone is updating their privacy policies, it’s because they are. Companies update their policies to stay compliant with data protection laws, and to inform users of their rights and how their data is collected, stored, and used. Among the most significant recent changes are GDPR and CCPA, both increasing the need for transparency around personal data and user rights.

What Is a Privacy Policy?

A privacy policy is a legal document explaining how a website or company handles personal data: any information that can be used, alone or with other information, to identify an individual, including name, address, date of birth, phone number, employer, ID numbers, medical history, and marital status.

A privacy policy should include:

  • The name of the website or company
  • The types of personal data collected
  • How that data is collected and stored
  • The reason for collecting it
  • How the company will use it
  • How users can access or correct their data
  • How users can lodge a complaint
  • Users’ rights
  • Your use of cookies

International Privacy Laws

Internation Privacy Data protection

Which laws apply to you depends on where your users are located, not your business. The main ones to consider are GDPR, CCPA, CalOPPA, COPPA, PIPEDA, and the Australian Privacy Act 1988. Here’s a brief look at each: see our dedicated articles for more detail on each one.

GDPR

gdpr gdpr general data protection regulation concept with big text and team people discussion - vector illustration

The General Data Protection Regulation is an EU privacy law protecting the personal data of EU residents. To be GDPR compliant, your privacy policy needs to include your company’s contact details (and your data protection officer’s, if you have one), a list of user data protection rights, the right to withdraw consent at any time, the right to lodge a complaint with a supervisory authority, details of any automated decision-making system, what personal data is collected and why, how long it’s retained, and who it’s shared with.

CCPA

CCPA privacy policy Pharmaceutical policy on clipboard and researchers, tiny people. Pharmaceutical policy, pharmaceutical lobby, drugs production control concept. Bright vibrant violet vector isolated illustration

The California Consumer Privacy Act protects the rights and personal data of California residents. Businesses collecting their data need to include the right to know, the right to delete, the right to opt out, and the right to non-discrimination, along with the categories of personal information collected.

CalOPPA

CalOPPA Corporate compliance. Corporate culture and policies. Representation of the business laws, regulations and standards. Ethical practices of the company. Vector isolated concept creative illustration

The California Online Privacy Protection Act made posting a privacy policy online mandatory. To comply, your policy should be in an easy-to-read format, disclose the personal data you collect, link to third parties’ privacy policies where you share data with them, inform users of their rights and choices, provide contact details, explain how you respond to Do Not Track signals, clearly label your stance on tracking, and list any third parties collecting information on your site.

COPPA

Children's Online Privacy Protection Rule

The Children’s Online Privacy Protection Rule primarily protects the personal information of children under 13. If your site isn’t directed at this age group, say so in your privacy policy. If it is (or is directed at children 3 and under), you must post a clear privacy policy outlining what personal information is collected, why, and how you maintain its confidentiality, security, and integrity.

PIPEDA

Canada

Canada’s Personal Information Protection and Electronic Documents Act applies to private sector businesses. A compliant privacy policy needs to disclose what personal data you collect, why, how it’s used, any risks or consequences of collecting it, which third parties (if any) it’s shared with, and be easy to understand and readily available.

Australian Privacy Act 1988

Australian privacy act

This law protects the privacy of Australian residents and their personal data. A compliant privacy policy needs your business name and contact details, what personal data you collect and how, why you collect it, how you use it, whether you share it with third parties (in Australia or overseas), and how users can access their data or lodge a complaint.

Conclusion

privacy policy protect data

Keeping your privacy policy updated in line with international privacy laws is an important part of running an online business. Generate your comprehensive, lawyer-drafted, up-to-date privacy policy, compliant with all major privacy laws, using our free generator.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.