Six common mistakes small businesses make with their privacy policy

A privacy policy is a statement or a legal document that discloses the ways you gather, use, disclose and manage a customer, website visitor, or clientโ€™s data. It fulfils your legal requirement to protect a customer or clientโ€™s privacy. However, many businesses’ privacy policies simply don’t stack up legally, writes Love Your Legals founder, Shalini Nandan-Singh.

When did you last think about your privacy policy? Never? Itโ€™s not surprising.

Small business owners have their priorities pulled in many different directions, and their privacy policy usually isnโ€™t anywhere near the top of the list. A privacy policy is one of those things where you donโ€™t realise how important it is until itโ€™s too late. If youโ€™re debating whether you need a one for your business, read this first.

When I speak with small business owners about their legal obligations, their privacy policy has one or more of these issues to address:

1. They donโ€™t have a privacy policy

Every business needs a privacy policy. If youโ€™re collecting personal details via a website, Facebook ad, paper form, website cookie or any other means, your business needs a policy for collecting and protecting that data.

In Australia, theย Privacy Act 1988 (Privacy Act) is the Australian legislation that sets the obligations for handling personal information about individuals.

General Data Protection Regulations (GDPR)ย across the European Union are very specific in their protection of the privacy of EU residents and those with an IP address located in the EU, whilst theย California Consumer Privacy Act (CCPA)ย also gives individuals more control over the personal information collected by businesses.

Though your business operates from Australia, if you are:

  • conducting business online
  • open to accepting business or subscribers from other countries
  • collecting data of any kind online from customers or visitors that may be located in the EU

… then GDPR laws apply to you. Iโ€™ve got a quick and useful checklist you can download to check your compliance with GDPR requirements. Download it here.

There are sizeable fines for breaching Privacy Acts, so complying is essential.

Privacy policy document on laptop screen

2. Having a privacy policy but not following it

A privacy policy means little if itโ€™s added to your website and you donโ€™t follow it. Adding a policy from a website provider without reading it is risky. The policy may cover obligations for a country you donโ€™t operate in, or set requirements for your business that you canโ€™t or wonโ€™t follow.

Itโ€™s not uncommon to hear that a client has copied and pasted a policy from a friend or competitorโ€™s website. Whilst I understand that a custom-drafted privacy policy may be out of reach for many small businesses, you need to have a policy that reflects YOUR business, not someone elseโ€™s.

Your business procedures should reflect what your privacy policy has said it will do. Donโ€™t risk your business by using someone elseโ€™s policy.

3. Making their policy difficult to understand

Privacy policies donโ€™t have to be complicated. How will you implement it into your business procedures if itโ€™s too difficult for you to understand?

There are some essential factors that you should understand, including,

  • what personal information includes,
  • how you collect that personal information, and
  • what you do with it, including storage.

Avoid legalese, and donโ€™t overcomplicate it. Yes, you have a variety of obligations to consider for privacy, but complicating it will make it harder to follow.

4. Not understanding what procedures need to support the policy

When youโ€™re writing or updating your policy, this is an excellent opportunity to reflect on what processes you have in place and if you can improve them.

For example, โ€˜We take your credit card details and store them in our filing cabinet in the office’ doesnโ€™t sound professional and secure when written down. (If this is your current practice, please improve it immediately.)

Small businesses are likely collecting and storing information in a variety of places, including:

  • Through websites
  • Through social media
  • Stored in their CRM
  • Stored in their phone
  • Stored in paper files
  • Collected and stored in their email

How you then use each of these platforms needs to tie in with your privacy obligations. For example, if you use contractors or overseas virtual assistants, do you have processes in place that ensure you continue to follow your privacy policy?

Screen showing various forms of data

5. Not considering the privacy of everyone interacting with the business

Privacy requirements apply to all the people who interact with your business, not just customers. Your privacy policy should reflect how you manage obligations for many individuals, including, but not limited to:

  • clients and customers
  • potential clients
  • contractors
  • employees
  • visitors
  • volunteers
  • suppliers

Consider each area of your business in the policy. Do you have client lists up in an office that others can see? Do you store client details in a filing cabinet or on your desktop? Are you providing customer details to a third party, etc.?

6. Not updating their privacy policy when needed

Businesses change and grow over time. Youโ€™ve almost certainly changed how you use and manage personal information if youโ€™ve been in business for a year or two.

Have you added new products or services, started a joint venture, or started working with contractors or new technology? It could be time to update your privacy policy.

Donโ€™t forget, laws change over time too. Put a time in your calendar to review your policy, update it as needed, or get practical legal advice to make it effective for your small business.


This article was originally posted on Love Your Legals, read the original here.

Want more? Get our newsletter delivered straight to your inbox!ย Follow Kochieโ€™s Business Builders onย Facebook,ย Twitter,ย Instagram, andย LinkedIn.