Skip to content

Is your website's privacy policy up to date? Why it is worth reviewing

Woman working on a laptop in a bright office
Photo: Pexels.com / olia danilevich

Could you confidently explain what your website's privacy policy covers and whether it still reflects how your business operates? Many businesses create this document when launching a website or online store, then leave it untouched for years. Meanwhile, they may add a contact form, switch payment providers, introduce a CRM system, work with new partners, or start collecting more customer data.

In this article, we look at what a privacy policy should include, the risks of an incomplete or outdated document, and when to review it. If you do not yet have a privacy policy or need a new version, Doqubit offers a guided process to create a privacy policy step by step for an online store or a website with a contact form.

When does a website need a privacy policy?

Article 13 of the General Data Protection Regulation, or GDPR, requires organizations collecting personal data directly from an individual to explain how that data will be processed. This includes, for example, the data controller's identity and contact details, the purposes and legal basis for processing, the recipients of the data, and information about transfers to third countries, where applicable.

In practice, a website privacy policy is one of the most common ways to bring this information together and make it available to visitors. The information must be clear, understandable, and reflect how the business actually operates.

Even a simple contact form can involve processing personal data. It may ask for a person's name, email address, phone number, and message. Online stores usually process a wider range of data, including order details, delivery addresses, billing details, and other information needed to complete a purchase.

Informing visitors about data processing is therefore not just a concern for large companies with extensive customer databases. It also matters to a small business with a single contact form on its website.

Two colleagues reviewing information on a laptop together
Photo: Pexels.com / Alena Darmel

Publishing a privacy policy is not enough

A common misconception is that adding a "Privacy policy" page to a website takes care of personal data protection. What matters most is what the document says and whether it reflects how personal data is actually processed.

A review by Latvia's Data State Inspectorate illustrates this. In 2024, the Inspectorate assessed the privacy policies of 30 businesses registered in Latvia that sold goods online or by mail order. The review examined compliance with the information requirements in Article 13 of the GDPR and identified several problems: privacy policies that were hard to find, overly general wording, and insufficient explanations of the purposes and legal bases for processing.

Text copied from another website will not necessarily suit your business, even if the two websites look similar or operate in the same sector.

That is why creating a privacy policy with Doqubit starts with questions about your business and its website. You provide information about the personal data involved, how it is used, and the service providers involved. The result is a privacy policy you can publish on your company's website. Like other Doqubit documents, the privacy policies have been developed with lawyers, taking legal requirements into account.

What should a privacy policy include?

The content depends on how your business processes personal data. These questions are a useful starting point for a review:

  • Who processes the personal data? Identify the company or organization acting as the data controller and provide its contact details.
  • What personal data is collected? This might include names, email addresses, phone numbers, delivery addresses, order details, or other customer information.
  • What is the data used for? Explain whether it is needed to process orders, arrange deliveries, prepare invoices, communicate with customers, or serve another specific purpose.
  • What is the legal basis for processing? Depending on the situation, this may be the performance of a contract, compliance with a legal obligation, consent, or another basis provided for in the GDPR.
  • Who may receive the data? Identify the recipients or categories of recipients, such as couriers, payment service providers, accountants, or hosting companies.
  • How long is the data kept? State the retention period or the criteria used to determine it.
  • What rights do individuals have? Explain the rights to access, correct, and erase their data, restrict or object to processing, exercise the right to data portability, and withdraw consent, to the extent that these rights apply in the particular situation. Also explain the right to lodge a complaint with the Data State Inspectorate.

This is a starting point for reviewing the document. Depending on the processing involved, you may also need to include other information required by the GDPR, such as contact details for a data protection officer, if one has been appointed, or information about transfers outside the European Economic Area and automated decision-making.

Woman thinking through her work at a laptop
Photo: Pexels.com / Vitaly Gariev

What can happen if personal data is not managed properly?

A privacy policy is only one part of personal data protection. A business must both inform people clearly and put appropriate data processing and security procedures in place.

When an infringement occurs, the Data State Inspectorate can take various measures, such as issuing a warning, ordering the infringement to be remedied, or restricting the processing of personal data. For certain GDPR infringements, the maximum fine is €20 million or, for a business, 4% of its total worldwide annual turnover in the preceding financial year, whichever is higher. Each case is assessed individually, taking into account the nature and extent of the infringement and other circumstances.

The cyber incident at Latvia's Road Traffic Safety Directorate (CSDD) also highlighted the importance of understanding and protecting the data an organization holds. In August 2026, third parties obtained data contained in historical payment receipts. According to CERT.LV's August report, the incident affected approximately 1.2 million individuals. The Data State Inspectorate has opened an investigation, including into CSDD's technical and organizational data protection measures.

This does not mean that an inadequate privacy policy caused the breach. The case is a reminder of a broader responsibility: a business needs to know what data it holds, why it keeps it, how long it keeps it, and how it protects it.

Smaller issues can also have consequences. If a privacy policy is unclear or outdated, customers may not understand why a phone number is requested, who receives their address, or how long the business will retain information submitted through a contact form. For the business, this may be a sign that its own data processing activities are not fully understood either.

When should you review your privacy policy?

A privacy policy should not be a document you think about only when building a website. It is worth reviewing whenever there is a significant change in how personal data is processed. For example, when:

  • a new contact form or registration option is introduced;
  • an online store adds a new delivery or payment partner;
  • the business starts using a new CRM or email marketing platform;
  • new types of personal data are collected;
  • the purpose for which data is used changes;
  • data retention practices change;
  • new analytics or marketing tools are introduced;
  • the company or the contact details listed in the privacy policy change.

The simplest way to check whether the document is still current is to compare it with your day-to-day business processes. Does it cover all data recipients? Are the retention periods still correct? Does it mention the marketing tools you use? If the answers no longer match what is published on your website, the privacy policy needs updating.

If the document needs updating or replacing, a guided set of questions can help you gather the necessary information and reduce the risk of overlooking important sections.

Privacy policies for online stores and websites with contact forms

The basic principles are similar, but the data and processes involved can be very different. A privacy policy for an online store usually covers orders, payments, deliveries, communications, invoices, and sharing data with the service providers involved. A website with a contact form typically has a simpler process, mainly involving the data needed to respond to inquiries.

A generic text with only the company name and contact details changed will therefore not always accurately describe how a particular website operates.

Doqubit offers two separate documents: a privacy policy for an online store and a privacy policy for a website with a contact form. You can choose the option that fits your situation and prepare it through a guided process, instead of adapting a single generic template to different websites.

Man working on a laptop at a table
Photo: Pexels.com / Mikhail Nilov

How can you make preparing a privacy policy easier?

The hardest part is often not writing the text, but working out what information the document needs. You need to identify the personal data collected, its purposes, the recipients and service providers involved, and the retention periods.

Doqubit, a document creation platform developed in Latvia, makes this process easier. The document's structure is already in place, and you answer questions about your business and its data processing step by step. Your answers determine which fields appear for your situation. You can review and edit the information you have entered before generating the document.

If your website does not yet have a privacy policy, or the existing one no longer reflects how personal data is actually processed, choose the appropriate document on Doqubit and prepare it to match your business.

Official sources and content review

Content reviewed on September 16, 2026.

Sources

This article provides general information about standard situations and is not a substitute for individual advice from a lawyer or data protection specialist. If your business has appointed a data protection officer, consult them on specific questions.

Back to blog

Find the document that fits your situation.

Choose a document