Privacy notice

A privacy notice people can read,
and regulators can check.

What a privacy notice is, how it differs from a privacy policy, and exactly what it must contain under the GDPR and UK GDPR, the CCPA, Australia's Privacy Act and the UAE PDPL. A practical guide, not legal advice.

GDPR Art. 13 and 14UK GDPRCCPA notice at collectionAPP 1 and APP 5UAE PDPL

Last updated Published by TryTrustableNot legal advice

Short answer

A privacy notice is the information you give people about how you use their personal data: who you are, what you collect, why, who you share it with, how long you keep it and what rights they have. A privacy policy is usually the same public document; some teams use "policy" for the internal rules and "notice" for what the public reads. The law cares about the content and the timing: under the GDPR it must reach people when you collect their data, under the CCPA a notice at collection is needed at or before collection, and in Australia APP 1 and APP 5 split it into a privacy policy and a collection notice.

01

What is a privacy notice?

A privacy notice is the statement that tells people how an organisation collects and uses their personal data. It answers the questions a person would ask before handing data over: who is collecting it, what for, who else gets it, how long it is kept, and what they can do about it. Data protection laws make it mandatory because consent, objection and every other right depend on people knowing what is happening.

It is a public document, but it is also evidence. Regulators read it against what you actually do, and a notice that says one thing while your site's trackers do another is a finding in itself.

02

Privacy policy vs privacy notice: is there a difference?

In everyday use, no: "privacy policy" and "privacy notice" usually mean the same public page. Where a distinction is made, the notice is what you tell the public and the policy is the internal rulebook for staff. The laws use different words: the GDPR says "information", the ICO says "privacy information", the CCPA has both a "notice at collection" and a "privacy policy", and Australia has an "APP privacy policy" plus a collection notice.

Privacy noticePrivacy policy
Who reads itThe people whose data you collect: visitors, customers, users, candidatesCommonly the same public; sometimes staff, when it means internal rules
Where it appearsAt the point of collection: a sign-up form, a banner, an app screen, plus a full pageA page linked from the footer of every page
Legal termGDPR Arts 13 and 14 "information", ICO "privacy information", CCPA "notice at collection", APP 5 "notification"CCPA "privacy policy", APP 1 "APP privacy policy"
FormatOften layered: a short notice linking to the full textThe full text

Most sites publish one document and call it either name. What matters is that every required item is in it, and that the short notice at collection links to it.

03

What a GDPR privacy notice must contain (Articles 13 and 14)

Article 13 applies when you collect data from the person directly: a form, an account, cookies. Article 14 applies when you get it from somewhere else: a partner, a data broker, public sources, a customer's upload. The lists overlap almost entirely.

What to includeArt. 13 (collected from the person)Art. 14 (from another source)
Your identity and contact details, and your representative's if any13(1)(a)14(1)(a)
Contact details of your data protection officer, where you have one13(1)(b)14(1)(b)
Purposes and the lawful basis for each13(1)(c)14(1)(c)
The legitimate interests you rely on, where that is the basis13(1)(d)14(2)(b)
Categories of personal dataNot required14(1)(d)
Recipients or categories of recipients13(1)(e)14(1)(e)
Transfers outside the EEA (or UK) and the safeguard used13(1)(f)14(1)(f)
How long you keep the data, or the criteria13(2)(a)14(2)(a)
Rights: access, rectification, erasure, restriction, objection, portability13(2)(b)14(2)(c)
Right to withdraw consent at any time, where consent is the basis13(2)(c)14(2)(d)
Right to complain to a supervisory authority13(2)(d)14(2)(e)
Whether providing data is a legal or contractual requirement, and what happens if not13(2)(e)Not required
The source of the data, and whether it came from public sourcesNot required14(2)(f)
Automated decision-making, including profiling: the logic and consequences13(2)(f)14(2)(g)

The UK GDPR has the same articles. Timing: Art. 13 at the time of collection; Art. 14 within a reasonable period and at the latest within one month, or at first contact or first disclosure if sooner.

Article 12 adds the form: concise, transparent, intelligible and easily accessible, in clear and plain language, especially for children. A layered approach (a short notice where data is collected, with a link to the full text) is what the ICO and EDPB recommend. If you rely on consent, the notice is part of what makes the consent informed, so the version a person saw matters: keep a record of which notice was live when they agreed.

04

CCPA notice at collection and privacy policy

California's CCPA, as amended by the CPRA, requires two things. The notice at collection is given at or before the point you collect personal information: on a form, in an app, or linked from a cookie banner for online tracking. It lists the categories of personal information (and sensitive personal information) you collect, why, whether you sell or share each, and how long you keep it. If you sell or share, it links to your "Do Not Sell or Share My Personal Information" page.

The privacy policy is the full description of your practices: the categories you collect, the sources, the purposes, the categories of third parties you disclose to, the rights Californians have (to know, delete, correct, opt out of sale or sharing, limit use of sensitive data, and not be discriminated against) and how to use them. It must be updated at least once every 12 months. You must honour Global Privacy Control as an opt-out, and saying so in the policy is good practice.

Virginia, Colorado, Connecticut, Texas and the other state laws ask for a similar privacy notice with their own details, such as how to appeal a refused request. Check whether the CCPA applies to you with the CCPA applicability checker.

05

Australian Privacy Principles: APP 1 privacy policy and APP 5 notice

Australia's Privacy Act 1988 splits the job in two. APP 1 requires a clearly expressed and up to date APP privacy policy. APP 5 requires you to take reasonable steps, at or before collection (or as soon as practicable after), to notify people of certain matters or make sure they are aware of them. In practice that means a short collection notice on each form, linking to the policy.

APP 1.4: your APP privacy policy must sayAPP 5.2: at collection, tell people (or make them aware of)
The kinds of personal information you collect and holdYour identity and contact details
How you collect and hold itThe fact and circumstances of collection, if they may not know
The purposes you collect, hold, use and disclose it forWhether the collection is required or authorised by law
How people can access and correct itThe purposes of collection
How people can complain, and how you will handle itWhat happens if they do not provide it
Whether you are likely to disclose it overseas, and to which countriesYour usual disclosures
From 10 December 2026: decisions made or substantially assisted by computer programs that could significantly affect people, and the information usedThat your privacy policy explains access, correction and complaints, and whether and where you disclose overseas

Source: OAIC APP guidelines, chapters 1 and 5. The privacy policy must be free and in an appropriate form, usually on your website (APP 1.5).

The Privacy and Other Legislation Amendment Act 2024 added the automated decision-making disclosure in APP 1, which starts on 10 December 2026. If your product uses automated decisions about people, add it now. Most businesses with annual turnover of A$3 million or less are exempt from the Act, with exceptions such as health service providers and businesses that trade in personal information.

06

UAE PDPL privacy notice requirements

The UAE's federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies across the UAE except in free zones with their own data protection law, such as the DIFC and ADGM. Article 13 gives people a right to obtain information from the controller about the processing of their data, including the types of data, the purposes, who it is shared with inside and outside the UAE, how long it is kept, the safeguards for cross-border transfers, their rights and how to complain to the UAE Data Office. The simplest way to meet this is to publish it in your privacy notice rather than wait for requests.

Check the official text for the full list, and check whether the PDPL's executive regulations, which fill in much of the detail, are in force for your situation. In the DIFC and ADGM, the free zone laws carry their own GDPR-style information duties.

07

How to write a privacy policy that holds up

  1. Start from what you actually do. List every place you collect personal data: forms, accounts, cookies and pixels, support tools, payments, recruiting. A cookie scan and a record of processing activities are the fastest inputs.
  2. For each purpose, name the data, the basis and the retention. Vague lines like "we may use your data to improve our services" are where regulators find gaps.
  3. Name recipients by category (hosting, email delivery, analytics, payments) and say where they are. Keep a sub-processor list for B2B customers.
  4. Explain rights in the reader's market: GDPR rights for Europe, CCPA rights for California, access and correction for Australia, and give one working route to use them.
  5. Layer it. A short notice at each collection point, linking to the full text.
  6. Keep the cookie detail in a cookie policy, linked from the banner. See our cookie compliance guide.
  7. Version it. Date every change, keep old versions, and review at least yearly (California requires it).

Our free privacy policy generator drafts a policy covering the GDPR, UK GDPR, CCPA and India's DPDP Act, with rights, lawful bases and retention filled in. It does not yet cover the Australian or UAE requirements, so add those sections from the tables above. Have counsel review the result.

08

How TryTrustable helps keep your notice true

A privacy notice is only as good as the practices behind it. TryTrustable connects the two:

  • The consent banner links to your notice, records which notice version each visitor saw in a tamper-evident consent ledger, and carries a privacy-request link.
  • Rights requests land in a queue with deadlines derived from the request type, from the banner or from your own form posting to a public intake endpoint (see data discovery and DSAR).
  • The compliance platform tracks the transparency requirements of the GDPR, UK GDPR, US state privacy laws, the Australian Privacy Act, the UAE PDPL, DIFC and ADGM against shared controls, with evidence.

None of this writes a compliant notice for you; it shows whether what the notice says is what your site and team do.

Questions

The things people ask us

What is the difference between a privacy notice and a privacy policy?

Usually none: both names are used for the public page explaining how you use personal data. When they are distinguished, the notice is public and the policy is the internal rulebook. The CCPA and Australian law use both terms for specific documents.

What must a GDPR privacy notice include?

Your identity and contact details, DPO contact, purposes and lawful basis, legitimate interests, recipients, international transfers, retention, rights, the right to withdraw consent and to complain, whether data is required, and any automated decision-making (Articles 13 and 14).

When must a privacy notice be given?

Under the GDPR, at the time you collect data from the person, or within a month when it comes from another source. Under the CCPA, at or before collection. Under APP 5, at or before collection or as soon as practicable after.

What is a CCPA notice at collection?

A short notice at or before the point of collection listing the categories of personal information collected, the purposes, whether each is sold or shared, and how long it is kept, with a link to the privacy policy.

What does APP 1 require in a privacy policy?

The kinds of personal information you hold, how you collect and hold it, the purposes, how to access and correct it, how to complain, and whether and where you disclose it overseas. From 10 December 2026, automated decisions too.

How often should a privacy policy be updated?

Whenever your practices change, and at least once every 12 months for the CCPA.

Is there a free privacy policy generator?

Yes. Our privacy policy generator covers the GDPR, UK GDPR, CCPA and India's DPDP Act. Add Australian and UAE sections yourself and have counsel review it.

Book a walkthrough

Keep your privacy notice and your practices in step.

Thirty minutes: we scan your site, compare it with your notice, and show consent and rights requests landing in the ledger.