Privacy & your data
How to read a privacy policy in ten minutes
Nobody reads privacy policies, and the documents are written knowing it. Here is how to extract the five things that actually matter, and the specific phrases that should slow you down.
Privacy policies are written to be legally complete, and legal completeness is the enemy of readability. The result is a document that technically discloses everything and practically communicates nothing.
You do not need to read one end to end. You need five answers, and they are almost always in predictable places. This guide is about finding them quickly.
Read it out of order
Skip the introduction entirely. It is scene-setting and it is never where the substance lives. Use the document's own navigation or your browser's find function and go straight to the sections that matter.
The five questions, in order of how much they should influence your decision:
1. Who else receives my data?
Look for a heading containing Sharing, Disclosure, Third parties, or Recipients. This is the single most important section in the document, and the one most likely to contain something you did not expect.
What you want is a specific, categorised list: which recipients, and for what purpose. Good policies name categories precisely — payment processing, fraud prevention, cloud hosting, customer support tooling — and many publish a live list of subprocessors.
What should concern you is a list of purposes so broad that it covers everything: "partners", "affiliates", "service providers", and "third parties we work with", with no indication of what they do. A list that cannot be narrowed is not a disclosure.
Pay particular attention to whether advertising or analytics partners appear here, and whether data is shared with them in a form that can be linked back to you.
2. Is it sold, or "shared" for advertising?
This has become a term of art. Several privacy laws define "sale" and "sharing" much more broadly than the everyday meaning — broadly enough that disclosing data to an advertising network in exchange for anything of value can qualify, even without money changing hands.
Search the document for sell, sale, and share. In policies covering certain jurisdictions you will find an explicit statement one way or the other, because the law requires one. If the answer is yes, there is normally an opt-out mechanism named in the same section. Use it.
3. How long is it kept?
Look for Retention, How long, or Storage period.
A meaningful answer gives you either a duration or a rule that resolves to one: deleted 30 days after account closure, kept seven years for tax records, retained for the life of the account plus a stated window.
A meaningless answer is "as long as necessary for the purposes described in this policy". That is circular — it means as long as we decide. It is unfortunately common and, on its own, not proof of bad behaviour. But a company that has actually thought about retention will usually tell you the number.
Check specifically for whether deletion of your account actually deletes anything, and what survives it. Backups, logs, and legally-mandated financial records typically do survive, and a good policy says so plainly instead of implying that everything vanishes.
4. What rights do I have, and how do I use them?
Look for Your rights, Choices, or Controls.
Depending on where you live, you may have rights to access a copy of your data, correct it, delete it, port it elsewhere, and object to certain processing. What you are checking is not whether the rights exist — largely they are set by law, not by the company — but whether the company has made them usable.
Concrete signals of a usable process:
- A named route: a specific email address, a form, or an in-product setting.
- A stated response time.
- An appeal or escalation path if a request is refused.
- The identity of the data controller and, where applicable, a data protection officer or representative.
If exercising a right requires you to send a letter to a postal address in another country, the rights are technically present and practically discouraged. Exercising your data rights covers the process end to end.
5. What happens if the company is acquired?
Search for merger, acquisition, or business transfer. Nearly every policy states that your data may transfer to an acquirer.
This clause is normal and almost universal, so its presence is not a warning sign. What is worth noticing is whether the company commits to anything at all around such a transfer — for example, notifying users, or requiring that the acquirer honour the existing policy. Many say nothing. The ones that make a commitment are telling you something about how they think.
The practical consequence: the privacy promises you are reading are made by the current owner, and companies change hands.
Phrases that should slow you down
Some formulations carry more weight than their length suggests.
- "We may..." — describes what is permitted, not what happens. A policy written entirely in may reserves maximum freedom and commits to nothing.
- "Including but not limited to" — the list you are reading is illustrative, not exhaustive.
- "Anonymised" or "de-identified" without explanation — these words carry specific legal meanings and are sometimes used loosely. Re-identification from supposedly anonymous datasets is a well-documented problem, particularly with location traces.
- "Aggregated data may be shared" — often reasonable, but worth understanding, because aggregate is a spectrum.
- "We use industry-standard security" — content-free. It tells you nothing about encryption, access control, or anything else.
- "By continuing to use the service, you accept the updated policy" — the policy can change unilaterally. Check whether they commit to notifying you of material changes.
Two things outside the policy itself
The change log. Better policies publish a version history or an effective date with a summary of what changed. A policy that quietly rewrites itself with no record is worth less than the same text with a record, because you cannot tell what you originally agreed to.
The cookie or tracking disclosure. Often a separate document, and often where the advertising and analytics detail actually lives. If the main policy is unexpectedly clean on tracking, this is usually why.
What good looks like
A policy worth trusting tends to share a few traits: it is written in plain sentences rather than defensive ones, it gives numbers where numbers exist, it names categories of recipients instead of gesturing at them, it makes rights easy to exercise, and it does not require a second document to understand the first.
None of that guarantees good behaviour — a policy is a statement of intent, not evidence of practice. But a company that has taken the trouble to be comprehensible has usually taken the trouble elsewhere too, and a company hiding straightforward facts behind unreadable prose is telling you something you should hear.
