Skip to content

Privacy Policy

What is Privacy Policy?

A public-facing document that describes an organization's practices regarding the collection, use, disclosure, and management of personal data.

Privacy and Data Protection

Each of these is named in at least one of the same controls as privacy policy. The number is how many controls name both.

What the standards actually require on privacy policy

Requirements naming privacy policy across 6 standards, quoted from the control text.

The privacy policy clearly and completely describes the operator's personal-information practices: types of PI collected, how it is collected (active/passive), how it is used, disclosures to third parties (incl.

ESRB-PC-06 · Online Privacy Notice (privacy policy)
CCPA/CPRA3 controls

Businesses must include in their online privacy policy or California-specific description: a description of consumer rights, methods for submitting requests, categories of PI collected/sold/shared/disclosed in the preceding 12 months, categories of sources, bu...

§1798.130(a)(3) · Privacy Policy Content Requirements

An operator that collects personally identifiable information about Delaware residents through a commercial internet service must make its privacy policy conspicuously available (e.g., via a link containing the word privacy on the homepage or first significant...

DE-DOPPA-1205C-POST · Conspicuous posting of a privacy policy

Schedule 1 DPP5 Openness Principle requires a data user to take all practicable steps to ensure that a person can ascertain the data user policies and practices in relation to personal data, the kinds of personal data held, and the main purposes for which pers...

HK-PDPO-DPP5-Openness-Privacy-Policy-Statement · HK PDPO DPP5 Openness Principle + Privacy Policy Statement (PPS) + Transparency
COPPA1 control

In addition to direct notice, the operator must post a prominent, clearly labelled link to an online notice of its information practices regarding children on the home or landing page and at each area where personal information is collected.

COPPA-312.4d · Online Notice of Information Practices (Privacy Policy)

Keep approved policies for classifying, protecting and handling data across its whole lifecycle in line with applicable law, standards and assessed risk, and review them at least annually.

CCM-DSP-01 · Security and Privacy Policy and Procedures

Questions people ask about privacy policy

What is Privacy Policy?
A public-facing document that describes an organization's practices regarding the collection, use, disclosure, and management of personal data.
Why is Privacy Policy important for compliance?
Privacy Policy is a key concept in Privacy and Data Protection. Understanding privacy policy helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Privacy Policy?
Privacy Policy appears in the requirement text of ESRB Privacy Certified, CCPA/CPRA, Delaware Online Privacy and Protection Act (proposed), Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486), COPPA. Across these standards we have identified 14 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Privacy Policy?
Explore our compliance framework pages to see how privacy policy applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Privacy Policy applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.