Mandatory, and usually written in language that no one reads.
A privacy statement is the public explanation of what personal data you collect, why, how long you keep it, who you share it with and what rights people have. Under the GDPR this is mandatory and must be in understandable language - a legally sealed text does not meet that purpose.
IN COMMON LANGUAGE
What belongs in it
Who you are and how you can be reached, what data you process and why, on what basis, how long you keep it, with which parties you share, and how someone can request their data or have it deleted.
Also add where someone can complain. This is mandatory and is often forgotten.
WHY IT MATTERS
Where things go wrong
A copied statement that doesn't match what your site actually does is worse than none: you're recording that you're doing something you're not doing, or vice versa.
Therefore, check which services your site actually uses and update the statement if anything changes.
- In understandable language — illegible does not suffice.
- Matches reality — no copied text.
- Mention retention periods — and also live up to them.
- Appoint processors — with whom you share.
- State right to complaint — obligatory and often forgotten.
FREQUENTLY ASKED QUESTIONS
More about a privacy statement
Can I use an example?
As a basis, yes, but check it line by line to see what your site actually does. An incorrect statement is a risk instead of a protection.
How often should I update it?
As soon as something changes in what you process or which parties you work with. If you add analytics or a chat function, that is part of it.
Do you write to him?
We ensure that the technology is correct and say which processors belong based on what your site uses. We leave the legal text to a lawyer.
CONTINUE READING
Of course, continue reading about this subject.
Does your statement make sense to you? site?
We inventory what your site actually processes and with which parties.