does my website need a privacy policy? yes — and here is the shortest honest version of why
cybersecurity · Apr 5, 2026 · 4 min read
the question is usually asked hopefully, by someone who has seen lawyers’ fees. the honest answer: if your site has a contact form, you are collecting personal data — a name, an email, a message — and every privacy law that matters (gdpr in europe, ccpa in california, and their cousins) says you owe those people a clear description of what happens to it. that description is the privacy policy.
what it actually is
not a shield, not a formality: a list. who you are, what you collect, why, how long you keep it, who else sees it (hosting, newsletter tools, analytics), and how a person can ask to see or delete theirs. that last part is a real right under gdpr — people can write and ask, and you need to be able to answer.
i practiced what this post preaches: my own site’s data flows are public in what this site actually sends — every third-party origin, itemized. that post is a privacy policy in article form, and it came from the same exercise: list what leaves, decide what should, write it down.
the smallest one that works
- list what you collect. form fields, analytics, cookies. most small sites collect three things, not thirty.
- name the processors. your host, your email tool, your analytics. by name — they are listed in their own gdpr terms, ready to copy as names, not text.
- say how long. “until you ask me to delete it” is a valid answer for a contact form.
- give the deletion path. an email address that a human reads. the right to be forgotten is exercised by email, not by notarized letter.
a page like this fits on one screen and is worth more than a 4,000-word template nobody reads — including its author.
the one shortcut that backfires
copying another site’s policy. beyond the legality of it, the copy describes tools you do not use and omits the ones you do — a document that is wrong in both directions, which is worse than none. generators and templates are fine as skeletons; the filling-in is yours, and it is the part that matters.
FAQ
my site is just a one-pager with a form — really?
really. the form is the trigger, not the size of the site. the one-pager’s policy is the shortest of all, which makes this the cheapest compliance in business.
do i need cookie consent too?
that is a separate question with its own logic — answered in do i need a cookie banner. the short version: the banner depends on what you track, not on the policy existing.
can i get fined for a missing policy?
enforcement against tiny businesses is rare; complaints from angry people are not. the realistic risk is a grievance, and the realistic cost is the week you spend handling it badly.
the closing thought
a privacy policy is the written form of a decision you have already made — or should make — about what your site collects. make the list once, publish the page, answer the rare email honestly. that is the whole law, at small-business scale.
if you want the data flows listed and the pages written as one piece:
- web development in Parma — builds where the privacy page is written from the actual stack
- what this site actually sends — my own list, public, as the example