Website privacy policy: when it's required, what it must contain and the risks of not having one
If you have a site, a blog or an online shop, you've probably asked yourself at least once whether you really need a privacy policy. The short answer is nearly always the same: yes. A website privacy policy is required in the overwhelming majority of cases, and it takes far less than you think to trigger the obligation. A simple contact form, Google Analytics, a newsletter or a third-party cookie is enough to make the notice a legal requirement, not an optional extra.
In this guide we look clearly at when you need a privacy policy, what it must contain, why copying one from another site is a terrible idea, and what fines you risk without one.
Note: this article is informational. It is not legal advice. For complex situations or specific doubts, consult a professional.
Why a privacy policy is required (and nearly always)
The legal foundation is the GDPR (EU Regulation 2016/679), together with the national data protection law of your country. Both impose a simple principle: anyone collecting or processing personal data must inform the people concerned transparently, before the processing begins.
Articles 13 and 14 of the GDPR are explicit: the notice is an obligation of the controller, not a favour to the user. And here's the point many people miss: the concept of "personal data" is extremely broad. We're not just talking about name, surname and email. An IP address is personal data. A cookie identifier is. A combination of browsing data that makes a person identifiable is.
That's why, in practice, a privacy policy is required practically always: it's nearly impossible to have a modern site that doesn't collect at least one piece of personal data, even indirectly.
Even if you think you don't collect data, you probably do
Many makers and small business owners believe they're "exempt" because they have no order form or members' area. They're wrong. Here are the most common cases that make a privacy policy mandatory without you noticing:
- Google Analytics or any statistics tool: it collects IPs and browsing data.
- Contact forms: name and email are personal data to all intents and purposes.
- Newsletter / email signup: collecting and storing data for marketing purposes.
- Third-party cookies: the Meta pixel, ad tags, YouTube or map embeds.
- E-commerce: billing, shipping and payment data (here the obligation is absolute).
- Blog comments, social login, chat: each of them processes personal data.
- Fonts or libraries loaded from external servers (e.g. Google Fonts via CDN): they transmit the user's IP to a third party.
If your site falls into even one of these categories — and it almost certainly does — then the answer to when you need a privacy policy is: now.
What a privacy policy must contain
Having a document called "Privacy Policy" isn't enough. It must contain a set of specific information, otherwise it's considered incomplete and therefore non-compliant. Here's what a privacy policy must contain under Articles 13-14 of the GDPR:
| Mandatory element | What it must state |
|---|---|
| Controller | Name/company name, address, contact details (email, registered address) |
| DPO contact details | If one has been appointed (mandatory in some cases) |
| Types of data collected | Identity data, browsing data, payment data, etc. |
| Purposes of processing | Why you collect the data (contact, shipping, marketing…) |
| Legal basis | Consent, contract, legal obligation, legitimate interest |
| Recipients of the data | Who it's disclosed to (suppliers, couriers, platforms) |
| Transfers outside the EU | Whether data leaves the European Economic Area |
| Retention period | How long you keep the data |
| Data subject rights | Access, rectification, erasure, objection, portability |
| Right to complain | The option of contacting the supervisory authority |
| How to exercise rights | How the user can contact you to enforce their rights |
The language matters as much as the content
The GDPR doesn't only ask for the right information, but for it to be expressed in a concise, transparent, intelligible and easily accessible form, using clear and plain language. A privacy policy in impenetrable legalese, or hidden behind a link nobody can find, can be considered non-compliant even if, on paper, it contains everything.
Why copying a privacy policy from another site is dangerous
It's the most common and riskiest shortcut. Copying a competitor's notice looks free and fast, but it exposes you to serious problems:
- The data doesn't match. Their document describes their processing, suppliers and tools. If you use Mailchimp and they use Brevo, if you sell and they don't, the copied notice makes false statements about your actual processing.
- Wrong controller. You end up with another company's name and contact details — a mistake that invalidates the whole document.
- Copyright infringement. A legal text is still a work of authorship.
- You miss the updates. Regulations change; a static copy ages badly.
A privacy policy must reflect exactly what your site does with data. That's why it should be built from the tools actually installed on your site, not pasted from elsewhere. Tools like Appurai scan the site to detect which trackers, cookies and third-party services are actually active, so the notice starts from what's really there rather than from a generic template. If you want to dig into automatic templates, we cover them in detail in the guide to privacy policy generators.
Fines: what you risk without a privacy policy (or with a wrong one)
This is where many underestimate the situation. Fines for a missing or non-compliant privacy policy aren't theoretical. The GDPR provides for two tiers of administrative fines:
- Up to 10 million euros or 2% of worldwide annual turnover for breaches of obligations such as the information notice.
- Up to 20 million euros or 4% of turnover for the most serious breaches (e.g. basic principles and data subject rights).
For a small site or a maker, record-breaking figures aren't the typical scenario — but the fines remain real and proportionate, and the supervisory authority can intervene in several ways:
- Warnings and orders to become compliant within a deadline.
- Financial penalties running into thousands of euros even for small operators.
- Restriction or ban on processing, which in practice can mean having to switch off features of your site.
On top of that comes the most insidious risk: a report from a user or a competitor. All it takes is one unhappy customer or an attentive competitor filing a complaint to trigger an investigation. And a missing privacy policy is the first thing anyone notices, because it's public and visible to everyone.
How to get a compliant privacy policy
Now that it's clear a website privacy policy is required, two main routes remain for getting a valid one:
1. A legal adviser or DPO
The most solid route, especially for structured organisations, e-commerce with complex processing, sensitive data or profiling. A professional drafts a bespoke notice and supports you with the related obligations. It costs more, but it's irreplaceable in delicate cases. If you run an online shop, also read the dedicated guide to GDPR for e-commerce, where the obligations multiply.
2. Automatic generation based on your site
For blogs, brochure sites, portfolios and small businesses, a document generated from what your site actually does covers most needs quickly and cheaply. The difference between a good tool and a poor one lies right here: it must start from a real scan of the site, not a generic questionnaire.
With Appurai the free version scans the site and shows you the problems (missing or default privacy policy, non-compliant cookie banner, trackers firing before consent); the paid plan generates personalised legal documents from the scan. In both cases, the value lies in verifying that what's written matches what the site really does.
Verification: the step almost everyone skips
Even the best privacy policy ages. You install a new plugin, change email marketing provider, add an advertising pixel: from that moment the notice may no longer be up to date. Compliance isn't a one-off event but a process. A periodic check tells you whether the document still reflects reality: you'll find a complete path in the guide on how to make a website GDPR compliant.
Frequently asked questions
Is a privacy policy required even for a simple personal blog?
If the blog uses Google Analytics, shows ads, has a contact form, allows comments or loads external resources (fonts, embedded video), then yes. It's very rare for a modern blog not to collect any personal data at all.
Is writing "We don't collect data" enough?
No. If that statement is false — and it nearly always is, because even an IP is data — you're still non-compliant, and on top of that you're giving misleading information to the user and to the authority.
Are a privacy policy and a cookie policy the same thing?
No, they're two distinct documents even though they're connected. The privacy policy covers all processing of personal data; the cookie policy specifically covers cookies and tracking technologies. Many sites need both, plus the cookie banner.
My site is small, the authority will never check me. True?
The bigger risk isn't a random inspection, but a report from a user or a competitor. A complaint can come from anyone who visits your site, and the privacy policy is the first public, verifiable thing. The size of your business doesn't exempt you from the obligation.
How often should a privacy policy be updated?
Every time something changes in your processing: a new analytics tool, a new supplier, a new marketing purpose, a new external service. Absent any changes, it's still good practice to review it at least once a year and after every significant regulatory update.
In summary
A website privacy policy is required in almost every real-world case: a form, an analytics tool or a cookie is enough to trigger the obligation under the GDPR and national law. It must contain specific elements — controller, data, purposes, legal basis, retention, rights — and be clear. Copying one from someone else is risky, the fines are real, and compliance has to be maintained over time.
The useful first step is understanding what your site really does with data. A free scan shows you within minutes whether your privacy policy is missing, default or out of step with reality — and from there you can decide how to get compliant.