Please Don’t Copy and Paste: Getting Privacy Policies Right



 

Whether your company has 5 employees or 500, if you operate online, you’re collecting user data—and that means you must have a privacy policy. But having a privacy policy isn’t just a legal requirement; it’s a powerful statement of your company’s ethics and values. Done right, it reflects a genuine commitment to transparency, accountability, and user trust. Unfortunately, too many businesses treat it as just another box to check.

In this episode of Priv, host Dona Fraser is joined by Wills Catling, Director at Myna Partners, for a candid and comprehensive conversation on what it really takes to get a privacy policy right. Together, they unpack the critical elements of a strong policy—from risk management and accountability to opt-in vs. opt-out frameworks, cookie strategies, and how to navigate the patchwork of state, federal, and international regulations. 

Key Takeaways

00:00 Introduction to Privacy Policies
03:25 Understanding Internal Governance for Privacy
08:04 The Importance of Accountability in Privacy
11:32 The Role of Privacy Notices as Contracts
17:50 Distinguishing Accountability from Internal Controls
20:52 Training and Compliance in Data Privacy
27:27 Common Mistakes in Drafting Privacy Notices
32:10 Building Trust Through Transparency
36:03 Navigating Opt-In vs. Opt-Out Consent
40:31 The Future of Cookie Banners and User Consent
44:24 The Challenge of Obtaining Informed Consent
46:08 Creating Effective Privacy Policies

Additional Resources: