Privacy Policy
A short, plain-language disclosure at the point of collection, with a clear path to the full legal policy for those who want it.
Background
A privacy policy that is too short omits substance a cautious customer needs; one that’s exhaustively legal reads as unreadable and erodes rather than builds trust. Presenting the same policy at several depths — a short summary down to the full legal document, each linking to the next — resolves this directly, letting each audience stop reading once they’ve gotten what they came for instead of forcing one length on everyone.
Presenting the same policy at several depths — a short summary down to the full legal document, each linking to the next — resolves this directly, letting each audience stop reading once they’ve gotten what they came for instead of forcing one length on everyone.
Problem
Most customers are concerned about their privacy online — surveys have repeatedly found this especially pronounced among Internet novices, parents, older adults, and women — and a site needs a concrete way to tell them what’s collected, why, how it’s used, and under what conditions it’s disclosed to others.
Solution
Communicate Fair Information Practices to customers through a privacy policy that is available everywhere and prominent where it matters most.
Place it on every page
Typically linked from the footer as part of the Page Template, and made especially conspicuous on the homepage, sign-in/account-creation pages, and checkout — the pages where the most sensitive disclosure actually happens. A conspicuous link on every page is now near-universal practice, not just good manners: CalOPPA (California Online Privacy Protection Act) was the first law to actually require it. That same prominence makes it a target: scammers copy a real privacy-policy page’s look and content to lend a fake site borrowed legitimacy, one of the impersonation techniques covered in Preventing Phishing Scams.
Address fair information practices directly
What’s collected, how it’s collected (e.g. cookies for a persistent session), how it’s used, who it’s shared with, and what security precautions protect it.
Consider a multilayered policy
A 2005 EU Article 29 Working Party proposal that’s held up well as UX guidance independent of its regulatory origin: a short policy (a few sentences, terse enough to print on a card), a condensed policy (a half-page summary of the important points), and a complete policy (the full multi-page legal document), each linking down to the next level of detail. This lets most customers get their answer from the short or condensed layer without wading through the complete text.
Each tier answers what a reader actually came for, then hands off to the next tier only for those who want more.
Handle children’s privacy as a special case
COPPA requires sites that collect information from children to give parents notice, get verifiable parental consent before collecting, let parents review/delete/refuse further collection, collect no more than the activity actually needs, and keep the data secure. A site whose audience is children must assume most visitors are children and build to that standard; a general-audience site can typically just ask a visitor’s age and take the answer at face value.
Treat health data as its own special case
A site that touches protected health information — a patient portal, telehealth interface, or appointment-booking form — needs a Notice of Privacy Practices as its healthcare-specific counterpart to the general privacy policy, plus a named contact for complaints: see HIPAA (Health Insurance Portability and Accountability Act) for the minimum-necessary disclosure rule and the patient access/request rights this notice has to name.
Surface region-specific rights where the law requires it
GDPR and CCPA/CPRA each grant residents of their jurisdiction specific rights (access, deletion, correction, opt-out of sale/sharing) that a policy has to name concretely and link to a working request path for — a generic “contact us for privacy questions” line doesn’t satisfy either law once a visitor is covered by one.
State special exceptions for valid legal process
E.g. how the site responds to a subpoena or court order — so customers aren’t surprised by disclosures that fall outside the policy’s normal promises.
Meet the legal floor required of U.S. federal government sites
Not just best practice: a 1999 Office of Management and Budget (OMB) memorandum requires every federal agency site to post a privacy policy on all major entry points and on any page collecting substantial personal information, disclosing what’s collected, why, and how it’s used.
a 1999 Office of Management and Budget (OMB) memorandum requires every federal agency site to post a privacy policy on all major entry points and on any page collecting substantial personal information, disclosing what’s collected, why, and how it’s used.
Frame data collection around tangible value, not just disclosure
Early Web sites lost customers by asking for information with no visible payoff. State the reason a field exists at the point of collection — a postal code for shipping-cost estimates, an email address for order status or personalized recommendations — so the request reads as an exchange rather than an intrusion. People do tolerate real privacy trade-offs (credit card purchase histories, mobile-phone location data) when the convenience they get back is high enough to justify it.
Early Web sites lost customers by asking for information with no visible payoff.
Related Concepts
Patterns
- About Us Pages
- Homepage Portal
- Quick-Flow Checkout
- Page Template
- Site Footer
- Privacy Preferences
- Preventing Phishing Scams
- Sign-In and Account Creation
- Customer Sessions
- Email Communications
Principles
Standards
- Fair Information Practices
- CalOPPA (California Online Privacy Protection Act)
- COPPA (Children's Online Privacy Protection Act)
- GDPR (General Data Protection Regulation)
- CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act)
- HIPAA (Health Insurance Portability and Accountability Act)
Sources
The Design of Sites: Pattern Group E — Building Trust and Credibility (E4 Privacy Policy) The footer/key-page placement guidance, the multilayered short/condensed/complete policy structure, COPPA’s special child-privacy provisions, and the federal-site legal-floor requirement all come directly from this pattern.