Source material
A privacy notice has two audiences and is organised for the one that does not ask questions
Privacy notices are structured around a statutory checklist: lawful bases, categories of data, recipients, transfers, retention, rights. That structure is correct and it is not how a single customer has ever approached the document. They arrive with two questions, neither of which is a heading, and the notice answers both somewhere in a section named after a legal concept.
Why this one is harder than it looks
The organising principle is a compliance list rather than a set of questions. Every heading names a category of obligation, which means the document is easy to audit and hard to search. A passage from the lawful basis section is a fine passage; it is simply not an answer to anything a customer typed.
The two questions people actually ask are what do you hold about me and how do I get it deleted. In most notices, the first is spread across a categories section and a sources section, and the second is one line inside a rights section that lists six other rights around it. Neither has a heading in the customer's words, so both match weakly, and a weak match is a refusal.
Retention is usually a table, and a retention table is one of the fragile ones. Converted from a web page or a spreadsheet it becomes a Markdown table, which is fine if it is a plain grid, and loses its meaning entirely if a merged header or a footnote marker was carrying the distinction between two rows. A retention period attached to the wrong category is a specific and serious kind of wrong answer.
Subprocessor and recipient lists change, and that changes what indexing them means. If the same list is published in three places and the text is identical, it is stored once, which is harmless. The danger is the copy that drifted: a list that differs by one name is different text, so it is stored as well, and either version can be retrieved. Finally, a request under any of these rights is a request with a clock on it in many markets, and it belongs with a person rather than being handled as a piece of information.
What it has to contain
Structure rather than wording. A passage pulled out of this document has to stand on its own, because that is the only form in which it will ever be read.
| A heading for each of the two questions people bring | Something close to what information we hold about you and how to ask us to delete your information. Plain, in the second person, sitting near the top. The regulator-facing sections stay exactly as they are underneath. |
|---|---|
| One named route for a request, written in the body text | An address, a form, or a named team, in the text of the notice rather than only in a page footer or a header link, because links are not the text and the passage carries only the text. Plus what to include so the request can be handled without a second exchange. |
| A retention table that is a plain grid | First row is the header, one word per cell, no merged cells, no footnote markers doing the work of a column. One row per category, with the category named in the row rather than implied by a heading above the table. |
| A recipient or subprocessor list with one home and a date | Published in exactly one place, carrying the date it was last checked. Every other page that needs it points at that one rather than reproducing it, so there is never a second version to drift. |
| The compliance sections kept whole and unedited | Lawful bases, categories, transfers, rights, supervisory authority. These are not the problem and should not be trimmed to make room. The additions go above them, not instead of them. |
The rewrite, in order
Add the two headings people actually search for
Write a short section under each. What we hold about you should list the concrete things: your name and contact details, what you ordered, messages you sent us, how you used the site. Concrete nouns match questions; the phrase categories of personal data does not, because nobody types it.
How to ask us to delete your information should describe the act rather than the right. Where to send it, what to say, what happens next, and roughly how long it takes where you trade. The rights section can continue to name the right formally; this section exists to be found by somebody who does not know its name.
Neither section changes what the notice says. They restate, in searchable words, material that is already there, which is why this is a safe addition to a document that has usually been reviewed carefully.
Put the request route into the text, not into a link
A great many notices handle this with a hyperlink or a footer address, and neither survives into a passage as an answer. The address or the form name has to be in a sentence: requests go to this address, or use the form named here, and include this so we can find you.
Say what you need to identify somebody, too. Half the delay in handling these requests is a first reply asking for details the notice could have asked for up front, and that first reply is time on a clock that in many markets has already started.
Fix the retention table before anything converts it
Open it and remove every merged cell, including the decorative ones. Put the category name in its own column so each row is complete on its own line. Replace footnote markers with words inside the cell, because a marker whose footnote is elsewhere in the page is a pointer, and pointers do not travel with passages.
Then add one sentence above the table saying what the periods are measured from: the end of the relationship, the date of the order, the last contact. That is the same anchor problem a cancellation policy has, and it has the same fix.
Give the recipient list one home and a habit
Decide which page owns the list, delete every other copy, and put the date it was last reviewed on the page itself. A dated list is a list somebody can see is stale. An undated one is indistinguishable from a current one, and the assistant will quote it with equal confidence either way.
Put a reminder somewhere real to check it on a schedule. This is the part of a privacy notice most likely to be out of date, because it changes when a supplier changes and nothing about that event prompts anybody to open the notice.
What happens if you skip it
A lawful basis quoted at somebody who asked to be deleted
The message is short and often upset: delete everything you have on me. The strongest matching passage is the one about processing and lawful bases, because that is the section with the most words about holding data. What comes back is an accurate paragraph about why the business is entitled to process information, cited, and read by the customer as a refusal.
It was not a refusal and it was not wrong, and that is what makes it costly. It reads as an institution explaining its entitlements to somebody who asked for something simple, and it does not tell them where to send the request. A single heading in their words, with an address under it, converts that entire exchange into one useful answer and a request that reaches a person.
Check it against this
Before you index it
- There is a heading in plain words for what you hold and one for deletion
- The request route appears in body text, with what to include
- The retention table is a plain grid with the category named in each row
- A sentence above the table says what the periods are measured from
- The recipient list lives in one place and carries a checked date
- The compliance sections are intact and unedited
- Nothing in the notice invites the assistant to handle a request itself
Questions
- Should the assistant handle deletion requests?
- No. A request of this kind starts a clock in many markets and has to be logged, identified and acted on by a person. What the document should do is make the route unmissable, so the assistant's answer is a correct and specific handover rather than a paragraph of policy.
- We publish the notice in several languages. Does that cause a problem?
- Not by itself. Different translations are different text, so they are stored separately and each can be retrieved. The thing to watch is drift: if one language is updated and another is not, both remain available and there is nothing in either that says which is current.
- Our notice is a long single page. Should we split it?
- Splitting helps if the split is by question rather than by legal heading, because passages from a long uniform page all look alike and compete. If you only do one thing, add the two customer-facing sections at the top rather than reorganising the whole notice.
Keep reading
- The question this document answersWhat the visitor is really asking, and where an answer becomes a handover.
- How to write a returns policy an AI assistant can answer fromWhy a passage about the return window answers confidently without the exclusions, and how to restructure the document so it cannot.
- Writing a cancellation policy an assistant can quote accuratelyNotice periods are relative to something the passage does not carry. How to write a cancellation policy that survives being read in pieces.
- How to structure warranty terms for a retrieval assistantThree warranties get conflated by customers. How to separate them, state the void conditions, and write what parts and labour excludes.
- Every kind of source materialWhat to feed an assistant, and the surgery each document needs first.
Try it on your own material
Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.