Privacy Policy vs Privacy Notice
Last reviewed: · By Victor Humenhuk (CIPP/US certified)
A privacy policy is an internal governing document that tells an organization's own staff how personal information must be handled. A privacy notice is an external statement that tells individuals what is collected, why, who receives it, and how to exercise their rights. Everyday usage blurs the two, because the document posted on a website is almost always labeled a privacy policy even though it functions as a notice. The distinction still matters: the external document is the one that creates legal exposure, since a promise the organization does not keep can be a deceptive practice under Section 5 of the FTC Act.
The internal versus external split
The clean way to hold the distinction is by audience, and the topic on privacy policy versus privacy notice uses the same split.
A privacy policy faces inward. It is the organization's own rulebook: which roles may access which data, what the retention periods are, how vendors are approved, how a rights request is routed, what happens on suspicion of a breach. It is usually longer, more specific and more operational than anything a customer would ever see, and it is the document an auditor or regulator asks for when testing whether a program is real.
A privacy notice faces outward. It is a disclosure to individuals, and its content is often prescribed: the categories of personal information collected, the purposes, the categories of recipients, retention periods, the rights available and how to exercise them, and how to complain. It should be accurate about what the organization does, which means it is downstream of the internal policy rather than a substitute for it.
Common usage does not follow this split. CalOPPA requires a "privacy policy" to be conspicuously posted online, HIPAA requires a "notice of privacy practices," and the GLBA requires "privacy notices" - all of them external documents. Use the statute's label when you cite it, and keep the internal versus external question in mind when you are deciding which document you actually need.
Privacy policy vs privacy notice compared
| Privacy policy | Privacy notice | |
|---|---|---|
| Audience | Internal - employees, contractors, sometimes vendors | External - consumers, employees as data subjects, patients, students |
| Purpose | To direct behavior and establish accountability inside the organization | To inform individuals and enable them to exercise choice and rights |
| Typical content | Roles and responsibilities, access rules, retention schedules, vendor due diligence, incident escalation, training requirements | Categories collected, purposes, recipients, sale or sharing and how to opt out, retention, rights, contact and complaint routes, effective date |
| Level of detail | Operational and specific | Plain language and readable; often layered |
| Who signs off | Privacy office, legal, and executive owners | Legal, with sign-off that it matches actual practice |
| Legal exposure if wrong | Weak internal controls, findings on audit, difficulty demonstrating accountability | Direct - an inaccurate statement can be a deceptive practice under Section 5 of the FTC Act or a state UDAP statute |
| Change management | Versioned internally, with training on change | Versioned publicly, with an effective date and, for material changes affecting previously collected data, affirmative consent |
What U.S. law requires in an external notice
There is no single federal notice requirement, so the content comes from whichever regimes apply.
- CalOPPA requires operators of commercial websites and online services that collect personally identifiable information about California consumers to conspicuously post a privacy policy identifying the categories collected and the categories of third parties they are shared with, describing the process for reviewing and requesting changes, describing how consumers are notified of changes, stating an effective date, and disclosing how the operator responds to Do Not Track signals.
- The CCPA, as amended, requires a notice at collection and a comprehensive privacy policy covering categories collected, sources, business purposes, recipients, retention, the rights available, and the sale and sharing opt-out, with a "Do Not Sell or Share My Personal Information" link where applicable.
- The GLBA Privacy Rule requires an initial notice at the start of a customer relationship and, historically, an annual notice. The FAST Act created an exception: a financial institution need not deliver the annual notice if it has not changed its policies and does not share nonpublic personal information in a way that triggers an opt-out right.
- HIPAA requires covered entities to produce and distribute a notice of privacy practices describing uses and disclosures, individual rights, and the entity's duties.
Across all of them the same failure mode recurs: a notice drafted from a template rather than from a data inventory. If the notice describes practices the organization does not have, or omits ones it does, the document has created risk rather than reduced it.
How notices should be delivered and changed
Delivery is part of the obligation, not an afterthought. Three patterns do most of the work:
- Layered notice - a short top layer covering the points most people care about, linking through to the full text. It solves the readability problem without cutting required content.
- Just-in-time notice - a short disclosure at the moment of collection, such as when location access or a camera permission is first requested. This is the most effective format because it arrives when the decision is actually being made.
- Mobile and small-screen notice - shortened formats and icons, with the full notice reachable from the app store listing and inside the app.
On changes, the settled U.S. position is that a business may change its practices going forward with notice, but applying a materially different practice retroactively to information already collected under an older promise requires affirmative consent. The FTC established that principle in its Gateway Learning consent order, where a company began renting customer information after having promised it would not. Keep dated versions of every published notice: if an enforcement action asks what you promised a consumer in a given year, the archived version is the evidence.
Related study notes
- Privacy Policy vs Privacy Notice
- Delivering Privacy Notices - Layered, Just-in-Time, and Mobile
- Drafting, Updating, and Versioning the Privacy Policy
- Business Obligation - Notice and Transparency
- The GLBA Privacy Rule
Frequently asked questions
Is the document on my website a privacy policy or a privacy notice?
Functionally it is a notice, because its audience is external. Almost everyone labels it a privacy policy, and some statutes including CalOPPA use that word, so the label is fine. What matters is that it accurately describes your practices and contains the content the applicable laws require.
Do I need both an internal policy and an external notice?
Yes, if you are running a privacy program rather than just a website. The internal policy is what makes the external notice true, and it is the document regulators and auditors ask for when testing whether stated practices are actually implemented.
Can I change my privacy notice whenever I want?
You can change practices going forward with adequate notice. Applying a materially different practice to personal information already collected under an earlier promise generally requires affirmative consent from the affected individuals, a principle the FTC established in its Gateway Learning consent order.
What happens if my privacy notice is inaccurate?
An inaccurate external statement is the classic broken privacy promise. The FTC can pursue it as a deceptive practice under Section 5 of the FTC Act, and state attorneys general can pursue it under state UDAP statutes, with outcomes typically including a consent order and years of compliance obligations.
Test yourself
Try the free CIPP/US practice questions, or read the full CIPP/US study guide - free.