Privacy Notice
A privacy notice is a public statement that explains what personal data you collect, why you collect it, how you use and store it, and the rights individuals have over that data.
Key takeaways
- Structure covers controller, data categories, purposes, legal bases, recipients, retention and rights.
- Layer it: a just-in-time line at the form, the full document behind a link.
- Notices drift because tool changes happen outside the team that maintains them.
- Publishing a purpose informs about processing; it does not authorise it.
- The form-level sentence should describe this submission, not the whole policy.
In depth
A privacy notice is a structured document rather than a block of prose. It identifies the organisation acting as controller, then works through each category of data, the purpose it serves, the legal basis relied on, who receives it, how long it is kept, whether it leaves the jurisdiction, and how a person exercises their rights. Most implementations are layered: a short just-in-time line next to the form covering the immediate collection, and a full document behind a link carrying every purpose the organisation pursues.
The quality of a notice depends on whether it tracks the systems that actually handle the data. Every new tool added to the stack changes the recipient list, and every automation that copies records between systems changes retention. Notices drift because those changes happen in engineering and marketing while the document sits with legal. Length trades against use: an exhaustive notice nobody finishes satisfies the checklist and not the reader, while a short one that omits recipients or retention fails the substantive requirement.
In practice the notice is anchored where data is collected. A form links to it beside the submit control, and the just-in-time text says what happens to this particular submission. On a scorecard funnel that means stating that answers are stored with the contact record, used to produce and personalise the result, and retained for a defined period. That sentence is doing the work: it turns an abstract policy into a description the respondent can check against what they just did.
A notice informs, it does not authorise. Publishing a purpose in the document does not create permission to pursue it, and adding a paragraph cannot retrofit a legal basis onto processing that had none. It also does not travel with data you send elsewhere: a partner who receives contacts operates under their own notice. And a notice that describes systems accurately today becomes misleading the moment a tool is swapped without the document being revisited.
Example in practice
How to measure it
Coverage is the first measure: compare the list of systems that hold personal data against the recipients named in the notice, and count the gaps. A second is staleness, tracked as the time between the last change to the data stack and the last revision of the document. Both are internal audits rather than analytics, and both catch problems long before a complaint does.
On the visitor side, watch the volume of questions the notice should have answered. Support tickets asking who receives the data, access or deletion requests that arrive with confusion attached, and unsubscribes citing surprise all indicate the notice is not reaching people. Click rate on the link is a weak signal on its own, but a rise after moving the summary next to the form suggests the placement is working.
Common mistakes
The usual failure is a document that no longer matches the stack. A new analytics tool, a support desk, an enrichment provider and a scheduling app all touch contact data, and none of them appear in the recipient list because nobody told the person maintaining the notice. Attach a review step to tool procurement, keep a simple inventory of what processes personal data, and reconcile it against the notice on a fixed schedule.
The second is treating the link as a formality. A notice that opens as a wall of unbroken text on a phone is technically available and practically unread, which shows up later as support questions the document already answers. Give it headings a reader can scan, put retention and rights near the top rather than at the end, and add a short summary of what happens to this form's data next to the field itself.
Frequently asked questions
What is the difference between a privacy notice and a privacy policy?
A notice is written outward, telling the people whose data you hold what happens to it. A policy is often used for the internal document that tells staff how to handle data. In everyday use the terms overlap and many organisations label the public page a policy, but the outward-facing content is what the transparency requirement addresses.
Where should a privacy notice be linked on a lead form?
Next to the submit control, where the decision is made, rather than only in the site footer. Pair the link with one plain sentence describing what happens to this particular submission. That sentence is what most people read, so it carries the practical transparency while the linked document carries the completeness.
How often should a privacy notice be updated?
Whenever the underlying processing changes, which in practice means whenever a tool that touches personal data is added, removed or reconfigured. A calendar review once or twice a year catches whatever slipped through. Keep a dated change log so it is clear which version was in force when a particular record was collected.
Does a privacy notice need to list every tool by name?
Naming categories of recipients is generally acceptable, but specific names are more useful and easier to defend when someone asks. A middle path names the significant processors, such as the email platform and the CRM, and describes the rest by category. Whichever you choose, the list has to reflect what is actually in use.
What should the notice say about quiz or scorecard answers?
That the answers are stored with the contact record, what they are used for such as producing a result and shaping follow-up, whether they influence routing to sales, and how long they are kept. Respondents often assume answers vanish once the score appears, so stating retention explicitly prevents the most common misunderstanding.
Is a privacy notice enough on its own for compliance?
No. It satisfies the duty to inform, but it does not create a legal basis, does not replace consent where consent is required, and does not cover cookie storage, which is handled separately. Think of it as the document that explains a lawful arrangement, not as the thing that makes the arrangement lawful.