What Is a Privacy Policy?
TL;DR
A privacy policy is the public notice telling people what personal data an organisation collects, why, who it is shared with and what rights they hold over it. GDPR Articles 13 and 14 set the required contents in the EU and UK, and California requires a conspicuously posted policy from sites collecting personal information about its residents.
What has to be in a privacy policy under GDPR?
Article 13 covers data collected from the person and Article 14 covers data obtained from anywhere else. Between them they require the identity and contact details of the controller, the purposes and the lawful basis for each, the legitimate interests where that is the basis relied on, the recipients, any transfer outside the EEA and the safeguard used, the retention period or the criteria for setting it, the individual rights including objection and complaint to a supervisory authority, and whether providing the data is obligatory.
Article 14 is the one outreach programmes have to read carefully, because a purchased or enriched contact list is data obtained elsewhere. It requires the source of the data to be disclosed, and it sets a deadline: within a reasonable period after obtaining the data, and at the latest within one month.
What does California require?
CalOPPA requires an operator of a commercial website or online service that collects personally identifiable information about California residents to post a privacy policy conspicuously. The policy has to identify the categories of information collected and the categories of third parties it may be shared with, describe any process for a consumer to review and request changes to their information, and describe how material changes to the policy are announced.
The CCPA layers more on top for businesses it covers: a notice at collection, disclosure of the categories collected and shared, and the mechanics of exercising the rights it grants. Drafting either is a legal exercise, and what a definition can offer instead is the list of sections a reviewer will look for first.
Why does a privacy policy matter for cold outreach?
It is where the source question gets answered. The most common reaction to an unexpected email is where did you get my address, and Article 14 already requires that answer to exist in writing. A policy that cannot give it is describing a data sourcing problem rather than a drafting one.
It also has to be reachable. Transparency information is only provided if the person can actually get to it, which is why outreach programmes link the policy from the message footer and from any landing page rather than pasting it into the body of an email.
Frequently asked questions
No. Terms of service are a contract about using a product. A privacy policy is a notice about data handling that the law requires you to publish, and it takes effect whether or not anyone accepts it. Publishing one does nothing about the need for the other.