Is there an ideal and foolproof Privacy Policy?
This is one of the most difficult questions to answer nowadays. Especially considering all the jurisprudence already established in Europe with the GDPR, the extensive history of cases, and the numerous tips we see in the market. Not to mention the judicial decisions that are already emerging in Brazil with the LGPD.
I'll answer you promptly: No. And I'll help you understand why.
I believe it is possible to develop a line of reasoning that can assist each one of us entrepreneurs, DPOs, lawyers, third-party consultants, etc. Ultimately, everyone can have a clear understanding of how the game works to avoid being caught off guard.
Below is the logic behind a privacy policy and some principles to help you understand the game. Perhaps even assist you in adapting your company and addressing any doubts that may arise along the way.
What makes a privacy policy better or worse?
To be as straightforward as possible: Does it accurately reflect the reality of data usage and flow within the company?
Here is the key to understanding any privacy policy: It must truthfully reflect the motivations and data flow in the company's routines.
Therefore, before we evaluate the quality of a privacy policy, it is essential to understand why it exists and its purpose. Is it becoming clearer?
In a simple and direct manner, I would highlight that a company's privacy policy is:
A public declaration of the objectives, interests, and responsibilities that companies have regarding the use and application of data, especially personal data, for the execution of their business model.
In other words, the guidelines provided in the privacy policy give us a real understanding of how that business operates regarding data usage and the actual commercial and/or legal purposes for which the data is used.
What do I need to know and map out to create my Privacy Policy?
In essence, it is not possible to structure a privacy policy without understanding the foundations of the business. Don't worry, I'm not complicating things for the sake of it, but rather showing you that without this knowledge, even a lawyer charging thousands of dollars per hour won't be able to assist you.
By the way, a good piece of information for you is that the privacy policy does not necessarily need to be written by a lawyer or in "legalese." According to the LGPD, before anything else, it must be clear, educational, and easily readable for the data subject.
So, whether it's you, your lawyer, or anyone who understands the processes, purposes, or legislation of your market, it's all good. Prioritize readability, clarity, and the ability for any visitor or customer accessing your platforms to understand and interpret the information.
However, it is worth noting that we recommend at least seeking advice from a lawyer. There are certain criteria and potential complexities in the market that they can assist you with more adeptly. For example, the healthcare industry has specific legislation that already treats patient data differently, and therefore, it may sometimes supersede LGPD requirements.
We are in Brazil, my friend, so, as usual, everything depends on the specific circumstances.
Anyway, let's go through the essential points you need to know to create any privacy policy. Points such as:
3.### Relevant laws governing the activities of players in the market;
4.### Product and/or service portfolio;
5.### Revenue streams and distribution channels;
6.### Basic understanding of the company's organizational structure;
(Headquarters and branches, size, number of departments involved, decision-making hierarchy, etc.)
7.### Supply chain;
8.### Sales and after-sales service;
9.### Communication channels;
...
Without this initial detailed understanding, the privacy policy will be incomplete and consequently flawed.
For example, what good does it do if I state that I use data on Facebook, collect addresses, emails, and CPF (Brazilian individual taxpayer registry number) for signing up for my plan and for email marketing, with data disposal in case of opt-out, if there is a legislation in my market that requires me to store this data beyond the data subject's requests?
I believe it is clear now how much information we need to consider. However, this should not discourage you! In fact, it is precisely the knowledge of these processes, or in other words, the understanding of the entire operation, that will give you greater confidence to determine whether the privacy policy is "good" or not. Again, it must reflect the reality and day-to-day operations of the company.
One of the tools/processes that can help you confidently structure the privacy policy is Data Mapping. If you don't have one yet or haven't considered implementing it, I'll summarize it for you in the link below.
Data Mapping: The Life Jacket for LGPD
At the beginning of everything are the legal bases of the LGPD, that is, the legal grounds (legitimate reasons) why companies not only can, but must access customer data in order to do their jobs well.
In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.
Surely you've already seen the predictions of fines and sanctions, processes. But, what does it mean to your company?
In this article, we will answer all your questions regarding fines under the LGPD (Brazil's General Data Protection Law).
Tired of the ads from that site you visited following you around? Is your computer running slow when accessing a particular website? Want to delete all cookies from a specific service or site?
Want to understand why there are cookie banners on every website you visit today? This article is for you!
While both regulations share the goal of safeguarding individuals' rights regarding the processing of their personal data, there are some important differences between them. It is crucial to understand these distinctions and their implications, particularly in the context of internet cookies.
In the end, our goal has never been to predict doom for companies or to be part of the LGPD's Apocalypse Cavalry. But, since we've been in the market for some time, these kinds of issues always catch our attention when we start data mapping and having conversations with colleagues.
Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
Every day, millions of users generate data on the web, which is used by companies around the globe to improve their offerings. Therefore, in 2018, a law was created to regulate the use of personal data by companies, and this directly impacts digital marketing. We're talking about LGPD.
Ignoring Terms of Use and their significance within a website, particularly now with LGPD, is a common mistake that both consumers and website owners frequently commit.
Brazilian LGPD - General Data Protection Law brought with it several acronyms and specific terms. Many of them are imported from other countries and regulations. One of them is ROPA (Record Of Processing Activities), adapted in Brazil to Registros das Atividades de Tratamento. An essential document for any DPO, Data Processor.
All the important information about the General Data Protection Law - LGPD: what it is, why it exists, how it works, when it came into force, who it applies to, potential fines, steps for compliance, and its legal principles.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
On October 18, 2022, the National Data Protection Authority (ANPD) released the "Guidance on Cookies and Personal Data Protection." Highly anticipated by professionals in the field, this document is of utmost importance as it examines various applicable legal scenarios and establishes the requirements to be observed in the case of cookie usage.
Understanding the General Data Protection Regulation (GDPR) and its impact on cookies is essential. So, let's break it down, step by step.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Iowa ICDPA explained: the longest response deadline of all US state privacy laws (90 days), 90-day cure period, opt-out for sensitive data, limited deletion scope, no right to correct, and how it compares to UCPA, VCDPA, and OCPA.
Brings a new era of consumer rights—and at the heart of it is the Data Subject Access Request (DSAR). This article is your go-to guide for understanding what a DSAR is, how to handle it properly, and why your business needs a streamlined process to stay compliant and build trust with Texas consumers.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Discover what the New Hampshire Privacy Act (NHDPA) means for your business. Learn about compliance steps, consumer rights, penalties, and how to simplify it all with AdOpt, a Google-certified CMP.
Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
AdOpt CMP: Google-certified consent platform with prior blocking, granular choices, encrypted logs, and GTM/Consent Mode
What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!
Learn what your TIPA Privacy Policy must include to comply with the Tennessee Information Protection Act from consumer rights and targeted advertising disclosures to the NIST affirmative defense, appeal mechanisms, and how to keep your notice aligned with your operational program.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
What the Virginia VCDPA requires from your Privacy Policy: the 5 mandatory content categories, sensitive data obligations, targeted advertising disclosure, and the appeal process explained.
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
How to handle DSARs under the Colorado CPA: 5 consumer rights, portability limited to twice per year, Universal Opt-Out Mechanism, 24-month record retention, and District Attorney enforcement.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
12 Sep 2023
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications