Privacy Policy
Privacy Policy
Why a Website Needs One
A privacy policy tells visitors what information your website collects about them, how you use it, and who else might see it. For many businesses, having one isn't optional — it's a widely recognized best practice, and depending on the laws that apply to your business (see the KCDPA and Other Laws pages on this site), it may be a legal requirement. Beyond compliance, a clear privacy policy builds trust with visitors and customers, gives your business a documented, consistent standard to follow internally, and can help limit liability by setting clear expectations about what you do and don't do with the information people share with you.
What Should Be In It
While the specific content will depend on your business and what your site actually collects, a well-drafted privacy policy generally addresses:
What information you collect — for example, information visitors provide directly (like a name, email, or message submitted through a contact form), and information collected automatically (like IP addresses, browser type, or analytics data).
How you collect it — directly from the visitor, or automatically through cookies, forms, or third-party tools like hosting platforms or analytics services.
How you use the information — responding to inquiries, operating and improving your site, marketing, or other stated purposes.
Who has access to it — internally within your business, and any third parties (such as your website host, email provider, or payment processor) who may process it on your behalf.
How long you keep it, and your data retention practices.
The choices and rights available to visitors — such as how to request access to, correction of, or deletion of their information, and how to contact you with questions or requests.
How you protect the information — a general description of your security practices, along with an acknowledgment that no method of transmission or storage is completely secure.
Contact information for privacy-related questions or requests.
Any legally required disclosures specific to the laws that apply to your business, such as rights created under the KCDPA, COPPA's parental notice and consent requirements if applicable, or disclosures required by other states' privacy laws if you do business there.
How Often It Should Be Updated
A privacy policy shouldn't be a "set it and forget it" document. At minimum, it should be reviewed and updated whenever your data practices materially change — for example, if you add a new tool that collects visitor information (like a new form, chatbot, or analytics service), start using a new third-party vendor that processes personal data, or begin operating in a way that brings a new law into scope (such as crossing a data-processing threshold under the KCDPA or another state's privacy law). Beyond triggered updates, it's good practice to review your privacy policy at least once a year even if nothing has obviously changed, simply to confirm it still accurately reflects what your site does. Most privacy policies include a "Last Updated" date at the top for exactly this reason — it signals to visitors, and to you, when the document was last confirmed accurate.
Other Important Points
Accuracy matters more than length. A privacy policy that overstates your protections, or that no longer reflects what your business actually does, can create legal exposure of its own — regulators and courts generally treat privacy policies as enforceable representations to consumers.
Make it easy to find. A privacy policy tucked away where visitors can't reasonably locate it undermines its purpose and may not satisfy legal notice requirements in jurisdictions that require one.
Keep it in plain language. Dense legal jargon may satisfy a technical requirement but does little to actually inform your visitors — a key goal of most privacy laws, including the KCDPA's "accessible, clear, and meaningful" standard.
A privacy policy and Terms and Conditions serve different purposes. A privacy policy addresses data practices specifically; Terms and Conditions govern broader use of your site. Many businesses have both, and they should be kept consistent with one another.
An Example to Reference
As a working example of how these elements come together in practice, you're welcome to look at KYBIZ.org's own Privacy Policy, which addresses many of these same elements. It won't be a perfect template for every business (it's tailored to a joint educational project involving a law school clinic and a state agency), but it can serve as a useful reference point for structure and tone.