June 23, 2026
How to Read a Privacy Policy: 8 Things That Actually Matter
Most privacy policies are designed to be ignored. Here is what to look for in under 10 minutes. and the red flags that should make you think twice.
The average privacy policy is 2,500 words long and written in legal language most people do not read. That is by design. A policy buried in jargon discourages scrutiny while providing legal cover. But you do not need to read every word. you need to know where to look and what eight specific things to check. This guide tells you exactly that.
1. What Data They Collect
Search for a section titled "Information We Collect" or "Data We Collect." The list should be specific. Vague language like "we collect information you provide" or "device and usage data" is a warning sign. it is deliberately broad enough to cover almost anything.
Look for these categories explicitly:
- Identity data: name, email, date of birth, government ID
- Contact data: address, phone number
- Financial data: card details, bank account, payment history
- Technical data: IP address, browser type, device identifiers, cookies
- Behavioural data: pages visited, clicks, search queries, purchase history
- Location data: GPS, inferred location from IP
- Communications: emails, support tickets, chat logs
The more categories listed, the more data the company holds. A password manager that collects behavioural data and sells it to advertisers is more concerning than one that collects only what is needed to run the service.
2. Why They Collect It (Legal Basis)
Under GDPR (which applies to UK and EU residents, and to any company serving them), companies must state their legal basis for processing each category of data. The six lawful bases are: consent, contract, legal obligation, vital interests, public task, and legitimate interests.
"Legitimate interests" is the most commonly abused. It allows companies to process data without your explicit consent if they can argue they have a business reason and it does not override your rights. It is valid in many cases. sending you a receipt, for example. but it is also used to justify ad targeting, profiling, and data sharing that most users would not expect.
Red flag language to watch for:
"We may process your data for our legitimate business interests". without specifying what those interests are
"By using the service, you consent to this policy". blanket consent on registration is not valid under GDPR
"We process data as described in this policy and as required by law". circular, says nothing
A well-written policy maps each data type to a specific legal basis. If the legal basis section is missing entirely, that is a red flag. especially for a UK or EU-based company where GDPR compliance requires it.
3. Who They Share It With
Find the section on data sharing or third parties. Every company shares data with some third parties. payment processors, hosting providers, analytics tools. That is normal. What matters is the scope and the specificity.
Concerning patterns:
- "We may share your data with our partners". no list of who those partners are
- "Affiliated companies". could mean dozens of entities in a large group
- "Advertising networks". your data goes to ad brokers who resell it further
- "Business transfers". your data is included in any acquisition or merger, often with no opt-out
Better policies name specific third-party categories (e.g., "Stripe for payment processing, Google Analytics for usage data") and link to their privacy policies. The California Consumer Privacy Act (CCPA) requires US companies to disclose whether they "sell" data. look for a "Do Not Sell My Personal Information" section if the company has US users.
Source: ICO. Guide to GDPR
4. How Long They Keep It
Search for "retention" or "how long we keep your data." Responsible policies specify retention periods by data type: account data kept for the duration of your account plus 6 years (typical for legal/tax reasons), marketing preferences retained until you unsubscribe, support tickets kept for 3 years, and so on.
Vague retention language. "we keep data as long as necessary" or "for a reasonable period". is the norm but falls short of best practice. Under GDPR, data should not be kept longer than necessary for its stated purpose. Indefinite retention is only justifiable for specific legal reasons.
Typical legitimate retention periods:
Financial records: 6–7 years (legal/tax requirements)
Account data: duration of account + short period for disputes
Marketing data: until unsubscribe or withdrawal of consent
Support tickets: 1–3 years
Analytics/behavioural data: 13–26 months (Google Analytics default)
If a policy says data is kept "indefinitely" or does not address retention at all, your data is likely being kept forever by default. which is both a privacy risk and, for GDPR-covered companies, a compliance issue.
5. Your Rights and How to Exercise Them
Under GDPR, UK GDPR, and similar legislation, you have specific rights: access (see what data they hold), rectification (correct inaccurate data), erasure (right to be forgotten), portability (receive your data in a machine-readable format), restriction (limit processing), and objection (stop certain processing, including direct marketing).
A compliant policy tells you how to exercise each right and what the response timeframe is. GDPR requires a response within one month, extendable to three for complex requests.
What a good rights section looks like:
✓ Lists each right by name
✓ Provides a specific contact method (email address or web form, not just "contact us")
✓ States the response timeframe
✓ Mentions the right to complain to the ICO (for UK) or relevant supervisory authority
If the rights section is absent or says "contact us to manage your data" with no further detail, exercise your right to erasure immediately after reading. then reconsider whether to use the service.
6. Cookies and Tracking
Look for a cookies section or a separate cookie policy link. Cookies fall into four categories: strictly necessary (required for the site to function), functional (remember your preferences), analytics (track usage), and marketing/advertising (track you across sites for ad targeting).
You should be able to accept or reject non-essential cookies independently. A cookie banner that only offers "Accept All" with no reject option is non-compliant under UK GDPR. Buried opt-outs. a reject option that requires 12 clicks compared to one-click accept. are technically compliant in some jurisdictions but deliberately designed to manipulate.
Marketing cookies are the most invasive. They feed data to advertising networks that build profiles on you across hundreds of websites. If a service you use for a non-advertising purpose (a tool, a form, a calculator) sets marketing cookies, ask why. and consider whether to use it without cookies enabled.
7. International Data Transfers
If the company is based outside your country, or uses third-party services hosted abroad, your data crosses borders. Under GDPR, data transfers outside the UK/EEA require additional safeguards: an adequacy decision (the destination country is deemed safe), Standard Contractual Clauses (SCCs), or Binding Corporate Rules.
The US does not have a blanket adequacy decision for UK transfers. the UK–US Data Bridge covers some US companies that have self-certified, but not all. If a policy says data may be transferred to the US without specifying the legal mechanism, that is worth noting, particularly for sensitive data.
Transfer mechanisms to look for:
UK–US Data Bridge (for certified US companies)
Standard Contractual Clauses (SCCs)
Binding Corporate Rules (for large multinationals)
Adequacy decisions (EU countries, some others)
8. When the Policy Was Last Updated
Find the "last updated" or "effective date" at the top or bottom of the policy. A policy that has not been updated in three or more years is likely out of date. GDPR alone has driven significant policy revisions since 2018, and any company that has not updated since then has probably not reviewed its practices either.
Also check: does the policy say it will notify you of material changes? A policy that says "we may update this policy at any time, and your continued use constitutes acceptance" removes your ability to meaningfully consent to changes. Better practice is email notification for significant changes and a changelog showing what changed.
The 10-Minute Privacy Check
You do not need to read every word. Use Ctrl+F to search for these terms and read the surrounding paragraph: "sell", "share", "third party", "legitimate interests", "transfer", "retention", "delete", "rights". That covers the eight areas above in under 10 minutes for most policies.
Quick red flag checklist:
☐ Policy sells or shares data with "partners" without naming them
☐ No retention periods specified
☐ Marketing cookies with no reject option
☐ Rights section missing or vague
☐ Last updated more than 3 years ago
☐ International transfers without stated legal mechanism
☐ Blanket consent on registration ("by using our service, you agree")
No policy is perfect. The goal is to identify companies that have made a genuine effort at transparency versus those using their policy as legal armour rather than user communication. The eight checks above separate the two categories quickly.
Try the calculator