The owner of a small studio added a Leave a request form to the site and installed a visit counter. A month later a client asked: where does my phone number go? The site had no answer. It had no privacy policy either: it seemed like paperwork for big corporations.
Does a website need a privacy policy
Yes, if the site collects any personal data: a name and phone in a form, a delivery address, an email for newsletters, visit data and cookies (small files that let a site recognise a visitor). The requirement exists in the EU, most US states, Kazakhstan, Russia and Belarus. A privacy policy is a page where the site explains what data it collects, why and what it does with it. You can check yours for free in the Awe Check privacy policy checker.
What a policy must contain
The exact list depends on the country, but its core is visible in Article 13 of the European GDPR. It lists what the controller (the one who collects data) must tell people at the moment of collection. In plain words:
- Who you are: the company or sole trader name and contacts, so a person knows whom to ask.
- Why you need the data and on what basis you process it: to fulfil an order, answer a request, send a newsletter.
- Who gets it: delivery, payment service, analytics service.
- Whether you send it abroad and how you protect it.
- How long you keep it or by what rule you decide when to delete it.
- The person's rights: to access, correct, delete, restrict processing, object and take their data with them.
- That they can withdraw consent at any time and complain to a supervisory authority.
Beginners skip the last three items most often. Yet they are what tells a person their data will not vanish into nowhere.
Where to place the policy
The policy lives on its own page and opens from every page of the site, usually from the footer. A second link is needed next to every form where people leave data. If there is a consent checkbox, it must not be ticked in advance: the person ticks it. A link on the home page alone does not count, because the form may sit on another page.
A policy and a cookie banner: what is the difference
The two are often confused. A policy is a document explaining everything about data in general: who collects it, why, how long it is kept. A cookie banner is a window where a person gives or refuses consent to specific cookies before they start working. A banner without a policy leaves a person without explanations, and a policy without a banner does not ask permission. A good site keeps both together: the banner links to the policy, and the policy describes the same cookies the banner asks about.
An example: an online shop with an order form
A shop collects a name, phone and delivery address, runs a visit counter and sends order emails through a mail service. Its policy must show the seller details, the purpose to fulfil the order and deliver the goods, the list of recipients (delivery service, payment service, mailing service, analytics service), the retention period and contacts for a deletion request. The order form links to the policy and asks for consent that the person ticks themselves. If any one of these links is missing, the shop stays exposed to a buyer complaint.
How to check that the policy works
Having a file is not enough, it has to be connected. Checking takes four steps:
- Open the privacy policy checker and paste the site address.
- The service finds the policy page and shows its address.
- It checks whether there is a link on every page and next to forms, and whether the text answers the main questions.
- It also shows whether cookies are described and contacts are given.
No policy yet? Build one with the free generator for your country and then check the site again.
5 mistakes seen most often
- A policy copied from another site. It carries someone else's details and services you do not use. A reviewer sees it in a minute.
- A link on the home page but not on the page with the form. People leave data where nothing is explained.
- A consent box ticked in advance. The Court of Justice of the European Union in the Planet49 case (C-673/17) held that storing cookies needs the active consent of the user, meaning an action by the person.
- Not a word about cookies while counters and ads are running.
- A policy that is never updated. A new service was connected but the document does not mention it. Add every new analytics or newsletter service to the list of recipients.
What a missing policy risks
The size of a fine depends on the country and business size: Kazakhstan, Russia and Belarus have their own articles in administrative codes, and in the EU fines are set by the GDPR. We gathered the amounts per country in our guide to website fines, so they are not repeated here and do not go stale when the law changes.
Today, open any page of your site with a form and check whether there is a link to the policy next to it. If not, that is the first thing to fix.
Sources
- GDPR, Article 13 - information the controller must give a person when collecting data.
- Court of Justice of the EU, Planet49 (C-673/17), press release - storing cookies requires the user's active consent.






