How to Write a Privacy Policy People Will Actually Read

Yes, really. It is possible. Here is how.

Privacy policies have a reputation problem. They are often the ‘fine print’ documents that everyone clicks 'I agree' on without reading, written in legalese designed to confuse rather than inform, and they typically serve the company's legal interests far more than the user's understanding. That does not have to be the case. And if you care about ethical marketing, it really should not be.

Why it matters

A privacy policy is, at its heart, a promise to your customers about how you will treat their data. Its something that under UK GDPR, you are legally required to provide on your website with specific information in a way that is concise, transparent, and written in plain language. 'Plain language' is not just good practice. It is a legal requirement.

When we build websites for our clients we often come across existing privacy policies that have been bodged together from various examples found via Google Search. And it shows… they’re legally meaningless and not worth the time it spends to cobble one together.

What most privacy policies get wrong

• Written for lawyers, not people. Lengthy sentences, passive voice, and language that requires a law degree to parse.

• They cover everything, so nothing stands out. A 5,000-word document buries the things people actually care about.

Impossible to find. Buried in the footer, labelled in small grey text, and requiring three clicks to reach.

Never updated. A privacy policy written in 2019 and untouched since is almost certainly out of date.

How to write one people will actually read

• Start with what matters most to your users. What data do you collect? Why? Who do you share it with? Front and centre.

Use plain English. 'We share your name and email address with Mailchimp, the platform we use to send our newsletter' is infinitely more useful than impenetrable legal language.

• Use clear structure. Short sections with clear headings. Summaries at the top of each section.

Be specific about what you do and do not do. 'We will never sell your data to third parties' is a powerful statement if it is true.

• Include a 'last updated' date. So people know the information is current.

• Tell people how to exercise their rights. Who do they contact? How? What can they ask for?

Our take

A clear, honest privacy policy is a marketing asset, not just a compliance burden. It tells your customers that you take their trust seriously enough to explain yourself in plain terms. That is a meaningful signal. It’s always best to get a properly drafted privacy statement and so we’re offering 20% off with our affiliate partners at K&K Legal Services via the link below:

Get 20% off your legal contracts and policies with our partners at K&K Legal Services Use code IPSA at the checkout.

Next
Next

Why Building a Smaller, More Engaged Email List Is Better for Everyone