VeryAppı
Technical & legal

Writing a Privacy Policy for Your Website

Published on November 22, 2025·7 min read

A privacy policy is the document that explains to a site's visitors what personal data is collected, why, for how long, and how to exercise their rights. It stems directly from the GDPR's information obligations and must precisely reflect the processing actually carried out by the site, not a generic text disconnected from reality.

The real problem: a copied document rather than a written one

The most common practice is to copy another site's privacy policy, sometimes without even changing the company name. Yet this document engages the publisher's liability: it must reflect exactly what the site does in terms of data collection. A policy that mentions processing that doesn't exist, or that omits real processing (an analytics tool, an advertising pixel, a third-party integration), constitutes misleading information and a breach of the GDPR's transparency obligation.

What the document must include

A complete privacy policy answers a precise set of questions for each category of data collected:

ElementWhat must be specified
Identity of the data controllerWho collects the data, with their contact details
Data collectedThe exact nature of the data (name, email, browsing data, etc.)
PurposeWhy this data is collected, for what exact use
Legal basisConsent, legitimate interest, performance of a contract, legal obligation
Retention periodHow long the data is kept, with a precise timeframe or a determining criterion
RecipientsWho receives or processes this data (host, subcontractors, partners)
Transfers outside the EUIf applicable, to which country and on what legal basis
Data subject rightsHow to exercise access, rectification, erasure, objection
ContactHow to reach the data controller or the DPO if one has been appointed
ComplaintsA reminder that a complaint can be lodged with the data protection authority in case of disagreement

Adapting the document to the site's actual processing

Before drafting the privacy policy, it is necessary to map out precisely what the site actually collects. This means reviewing every collection point: contact form, newsletter sign-up, account creation, audience analytics tools, live chat, social media integrations, payment provider. Each of these points must appear in the document with its own purpose and retention period, rather than a vague statement covering "all data on the site."

The privacy policy must state, for each type of data, the legal basis relied upon. This choice isn't arbitrary: it follows from the nature of the processing. A contact form generally relies on legitimate interest or pre-contractual steps, a newsletter on consent, invoicing on the performance of a contract or a statutory accounting obligation. This consistency between the actual processing and the stated legal basis is a point checked as a priority in the event of an audit.

Retention period, a point often overlooked

Contrary to a common assumption, there is no universal retention period applicable to all data. Each category follows its own logic: data belonging to a prospect who didn't convert is generally kept for three years from the last contact, an active customer's data for the duration of the business relationship plus statutory retention obligations (accounting, in particular), and audience measurement cookies for a maximum of thirteen months per the recommendations of the data protection authority. The privacy policy must specify these periods, or failing that, the criteria used to determine them.

What to remember

  • The privacy policy must reflect exactly the data processing actually carried out by the site, not a generic text copied from elsewhere.
  • Each category of data must be linked to a precise purpose, legal basis, and retention period.
  • Data recipients (host, subcontractors, providers) must be mentioned, particularly in the case of transfers outside the European Union.
  • The rights of data subjects must be clearly explained, with a concrete means of exercising them.
  • The document must be updated with every change to the site's data processing.
  • This document is distinct from the legal notice, which meets a different obligation (e-commerce law).

Frequently asked questions

Can we use a generic template found online? A template can serve as a starting point, but it must be adapted to your site's actual processing. A policy copied without adaptation risks mentioning nonexistent processing or omitting real processing.

Does the privacy policy need to be a separate page from the legal notice? There is no strict formal obligation, but it is strongly recommended for clarity, since these two documents meet distinct legal obligations.

Do we need to list every subcontractor and tool used? It is recommended to mention at least the categories of recipients, and ideally their precise identity, particularly when data is transferred outside the European Union.

How often should this page be updated? With every new processing activity or change affecting the purpose, duration, or recipients of the data. An annual review even without an identified change remains good practice.

In summary

A well-written privacy policy is not an exercise in legal style but a faithful mirror of what the site actually does with its visitors' data. This general framework presents the principles derived from the GDPR; for precise drafting tailored to your activity, support from a lawyer or the templates offered by the relevant data protection authority remain the most reliable resources. Sites supported by VeryAppi start from a compliant privacy policy structure, to be adjusted according to each business's specific processing.

Frequently asked questions

Can we use a generic template found online?

A template can serve as a starting point for the structure, but it must be adapted to the actual processing carried out by your site. A privacy policy copied without adaptation risks mentioning processing you don't actually carry out, or omitting processing you genuinely do, which exposes you to a breach in the event of an audit.

Does the privacy policy need to be a separate page from the legal notice?

There is no strict formal obligation to separate them, but it is strongly recommended for clarity and readability. The legal notice and the privacy policy meet distinct legal obligations (e-commerce law for one, GDPR for the other) and are better presented separately.

Do we need to list every subcontractor and tool used?

It is recommended to mention at least the categories of data recipients (host, emailing tool, payment provider) and, ideally, their precise identity when this remains readable. This transparency strengthens compliance and trust, particularly when data is transferred outside the European Union.

How often should this page be updated?

Every time a new data processing activity is introduced (a new tool, a new feature collecting data) or a change affects the purpose, retention period, or recipients of data already collected. A systematic annual review remains good practice even when no change has been identified.

Related articles

← Back to blog