Most small businesses run a privacy policy that mentions data types they don't collect, third parties they don't use, and lawful bases that don't apply. It's the corporate equivalent of a resume that lies - and regulators know how to spot it.
The three real risks
- DSAR failures. A user requests their data under GDPR or CCPA. If the policy says you collect X but the request produces Y, that inconsistency is evidence.
- Cookie mismatches. The policy says you use "analytics cookies." The site loads six advertising trackers. That's an enforceable gap in the EU.
- Missing "Do Not Sell or Share" mechanism. California doesn't care what your policy claims - it cares whether the link works.
What a defensible policy actually looks like
- Named data controller with a working contact.
- Actual data categories tied to actual processing activities.
- Lawful basis per activity (not one blanket "consent" line).
- Real list of third-party processors - Stripe, Klaviyo, GA4 - not "our trusted partners."
- Retention periods with numbers.
- Working DSAR intake and, for California, a working opt-out.
The cheap version isn't cheap
A privacy policy is the front door to your data-protection posture. Regulators, auditors and enterprise procurement teams read it first. A policy that doesn't match the site is a signal of everything else being loose.
Draft one with the Privacy Policy tool.