Every day, organizations collect personal data from their customers through websites, mobile apps, registration forms, and a range of digital services. The data collected can include names, email addresses, phone numbers, physical addresses, and even transaction records.
At the same time, consumers are increasingly concerned about how their data is used. The Cisco Consumer Privacy Survey 2024 shows that 53% of global consumers are aware that data privacy regulations exist in their countries. In other words, more and more people are paying attention to how organizations collect, use, store, and share personal data.
That is why organizations need to explain their data practices openly, rather than simply collecting data. A Privacy Notice helps communicate this information to customers while supporting compliance with global privacy frameworks such as the GDPR, the CCPA, and Indonesia’s UU PDP.
What Is a Privacy Notice?
A Privacy Notice is a document that explains how an organization collects, uses, stores, shares, and manages personal data. Its primary purpose is to provide transparency to data subjects about the data processing activities carried out by the organization.
Through a Privacy Notice, customers can learn what data is collected, the purposes for which it is used, who may access it, and the rights they hold over that data. This transparency is a core principle across major data protection regulations, including the GDPR, the UU PDP, and the CCPA.
In practice, a Privacy Notice is typically presented at the point where data is first collected, such as account registration pages, sign-up forms, mobile apps, or customer service portals.
For example, when a customer subscribes to a newsletter, the Privacy Notice can explain that their email address will be used to send product information, promotions, or service updates. This way, customers understand the purpose of data use before providing their personal information.
What Should a Privacy Notice Include?
A Privacy Notice should generally include information about the organization’s identity, the types of personal data collected, the purposes of processing, the legal basis for processing, the data retention period, any third parties that receive the data, data subject rights, and privacy-related contact information.
This information helps customers understand how their personal data is managed while supporting transparency and data privacy compliance. In general, a Privacy Notice covers:
- Organizational identity, to explain who is responsible for processing personal data, including the company name and relevant contact information.
- Types of personal data collected, such as names, email addresses, phone numbers, addresses, transaction data, payment information, or other data relevant to the services provided.
- Purposes of data processing, for example account creation, transaction processing, service delivery, customer communication, or marketing activities.
- Legal basis for data processing, such as consent, contractual obligation, legal obligation, or legitimate interest, depending on the law that applies.
- Data retention period, to explain how long data will be stored and when it will be deleted or destroyed.
- Third parties that receive the data, such as cloud service providers, email marketing vendors, payment providers, or logistics partners that support business operations.
- Data subject rights, including the right to access, rectify, delete, restrict processing, withdraw consent, or object to certain uses of data.
- Privacy-related contact information, such as a privacy email address, a privacy compliance team, or a Data Protection Officer (DPO) who can be contacted with questions or requests about personal data.
The clearer the information set out in the Privacy Notice, the easier it is for customers to understand how their data is used and what rights they hold over that data.
What Is a Privacy Policy?
A Privacy Policy is a policy document that explains in more detail the approach, rules, and practices an organization applies to managing personal data.
If the Privacy Notice functions as notification to data subjects, the Privacy Policy usually functions as a reference document that explains the organization’s personal data management framework more comprehensively.
In practice, a Privacy Policy often covers a wider range of information, such as:
- The personal data protection principles adopted by the organization.
- Data security mechanisms.
- Data transfer governance.
- Management of cookies and tracking technologies.
- Data retention policies.
- The process for handling data subject requests.
- Privacy incident reporting mechanisms.
Because its scope is broader, a Privacy Policy is generally a longer document than a Privacy Notice.
It is common for organizations to publish their Privacy Policy on a dedicated page on their website, accessible at any time by customers, business partners, regulators, and any other party needing more in-depth information about the organization’s personal data protection practices.
In a mature data privacy program, the Privacy Policy and the Privacy Notice are often used together to meet both transparency needs and data governance documentation requirements.
Privacy Policy vs. Privacy Notice
Although the Privacy Policy and Privacy Notice serve different functions, the two complement each other in supporting privacy transparency and compliance.
The Privacy Notice focuses on informing data subjects when data is collected, while the Privacy Policy explains the organization’s personal data management policies more comprehensively.
| Aspect | Privacy Notice | Privacy Policy |
|---|---|---|
| Definition | A notice that explains to data subjects how their personal data is collected, used, stored, and shared. | A policy document that explains the organization’s approach, principles, and governance in managing personal data. |
| Main Purpose | To fulfil the transparency obligation toward data subjects. | To document the organization’s personal data protection policies and practices. |
| Information Focus | Data processing activities relevant to the individuals whose data is collected. | The organization’s governance framework, policies, procedures, and commitments regarding data privacy. |
| Audience | Customers, app users, prospective customers, employees, or other data subjects. | Customers, regulators, auditors, business partners, investors, and other stakeholders. |
| Level of Detail | Concise, specific, and easy to understand. | Longer, comprehensive, and covering various aspects of personal data management. |
| Typical Content | Types of data collected, purposes of processing, legal basis, retention period, data subject rights, and recipients of the data. | Data protection policies, data governance, retention, transfer, cookie use, data subject rights, and compliance mechanisms. |
| How It Is Delivered | Displayed at or before the point where personal data is collected. | Published as a document or policy page that can be accessed at any time. |
| Typical Location | Registration forms, checkout pages, mobile apps, contact forms, or customer portals. | A “Privacy Policy” page on the company website or portal. |
| When It Is Used | When the organization collects personal data or introduces a particular processing activity. | As an ongoing reference on the organization’s personal data protection practices. |
| Role in Compliance | Helps meet the transparency obligation required by regulations such as the GDPR, UU PDP, and CCPA. | Supports the documentation of privacy data governance and demonstrates the organization’s commitment to personal data protection. |
In short, the Privacy Notice is communication to data subjects, whereas the Privacy Policy is the organization’s internal and external policy on how data is managed.
Why Is a Privacy Notice Important for Your Organization?
A Privacy Notice matters because it is the vehicle for transparency, explaining how personal data is collected, used, stored, and shared with other parties.
That transparency helps organizations meet compliance obligations, build customer trust, and reduce the risk of disputes over the use of personal data.
1. Supporting Regulatory Compliance
Data privacy regulations around the world require organizations to provide data subjects with clear information about their personal data processing activities.
A Privacy Notice helps an organization demonstrate that data collection and use are carried out openly and in line with the transparency principle that underpins leading data protection laws.
When an organization begins mapping its personal data within a privacy compliance program, the Privacy Notice is often one of the first documents evaluated during compliance audits or assessments.
2. Improving Transparency and Accountability
A Privacy Notice helps an organization explain information that customers need to know, such as the types of data collected, the purposes of data use, the data retention period, and any third parties that may receive the data.
The clearer the information provided, the easier it is for an organization to demonstrate accountability in managing personal data.
3. Building Customer Trust
Trust is one of the most valuable assets in the digital economy. Customers are generally more comfortable interacting with organizations that are open about their data management practices.
This is reinforced by the Cisco Consumer Privacy Survey 2024, which found that 75% of consumers will not buy from organizations they do not trust to handle their personal data.
These figures show that data transparency is not only a compliance issue but also a factor that can influence purchase decisions and customer loyalty.
4. Protecting Corporate Reputation
In an era of social media and free-flowing information, privacy issues can quickly escalate into reputational risk.
Organizations often face public criticism not because of a data breach, but because customers feel they were never given a proper explanation of how their data would be used.
A clear Privacy Notice can help reduce misunderstandings and demonstrate an organization’s commitment to responsible data governance.
5. Reducing the Risk of Privacy Disputes
One common driver of privacy disputes is not the data processing activity itself, but the lack of transparency about that activity.
When customers understand from the outset how their personal data will be used, the potential for conflict over data use for marketing, analytics, service personalization, or collaboration with third parties can be minimized.
Legal Foundations of a Privacy Notice
A Privacy Notice rests on solid legal ground because data protection regulations around the world require organizations to provide data subjects with clear information about their processing activities.
Although the terminology and the details of the obligations differ from one law to another, most modern regulations share the same principle: individuals have the right to know how their personal data is collected, used, stored, and shared.
1. Privacy Notice under the GDPR
Under the General Data Protection Regulation (GDPR), transparency is a binding legal principle enshrined directly in Article 5(1)(a), which requires all processing of personal data to be lawful, fair, and transparent in relation to the data subject.
From this general principle, the GDPR derives more specific obligations through Articles 12, 13, and 14, which together form what is known as the “Right to be Informed.”
Article 12 governs how information must be provided: concisely, transparently, intelligibly, in an easily accessible form, and using clear and plain language. In other words, the text must not only be complete, but also genuinely readable.
The GDPR implicitly recognizes that long legal documents full of jargon provide little real transparency if, in practice, nobody reads them.
What must be disclosed is set out in Article 13 (for data collected directly from the data subject) and Article 14 (for data obtained from third parties). This includes:
- the identity and contact details of the Controller, including the Data Protection Officer’s contact details where applicable
- the purposes and legal basis of the processing (referring to Article 6 for valid legal bases)
- the recipients or categories of recipients of the data
- the period for which the data will be stored
- the data subject’s rights, including the right to withdraw consent
- the right to lodge a complaint with a supervisory authority
For data collected directly, this information must be provided at the time of collection. It cannot be given later.
In practice, satisfying both Article 13/14 and the readability standard of Article 12 is challenging. The list is long, yet the text must remain concise.
The solution most organizations use is the layered-notice approach: present a summary of the key information in the first layer, then provide the full explanation in a more detailed Privacy Policy.
This approach was explicitly endorsed by the Article 29 Working Party (now the European Data Protection Board) as a proper way to avoid information fatigue without diminishing the substance of the information duty.
A Privacy Notice, therefore, is the primary mechanism organizations use to meet all their transparency obligations under Articles 12 to 14 of the GDPR at once.
2. Privacy Notice under Indonesia’s UU PDP
Transparency is not merely an ethical value in personal data protection. In Indonesia, it is a legal obligation explicitly set out in the UU PDP.
Law No. 27 of 2022 on Personal Data Protection (UU PDP) establishes transparency as one of the core principles of personal data processing, as stated in Article 16(2). This means every data collection and processing activity must be carried out openly toward data subjects.
This obligation is then made concrete in Article 21(1) of the UU PDP. Before or at the time of collection, the Personal Data Controller must provide data subjects with information covering:
- the identity and official contact details of the Personal Data Controller
- the legal basis and purpose of the processing
- the types of data collected and their relevance
- details of the information collected
- the processing and document retention period
- the rights held by the data subject
If any of that information changes, Article 21(2) requires the Controller to notify the data subject before the change takes effect, not after.
Note also that this information duty is directly tied to the validity of consent. Article 22 of the UU PDP provides that consent to the processing of personal data given without adequate prior information may be declared void by law.
From a business perspective, this means a company cannot simply display an “I agree” checkbox on a registration form without explaining what the user is agreeing to.
Websites, apps, or digital services that collect customer data need a document that sets out all of the information duties above clearly. That document is what we call a Privacy Notice.
When a privacy compliance program is first being built, the Privacy Notice is usually the first document examined, because it reflects how far the company has gone in meeting the openness principle required by the UU PDP.
Learn about the UU PDP: The Personal Data Protection Law (UU PDP) regulates how personal data must be managed and protected, and sets out the rights of data subjects along with the responsibilities of the parties that process such data.
Learn about the PDP Law
The Personal Data Protection Law (UU PDP) regulates how personal data must be managed and protected, while also defining the rights of data subjects and the responsibilities of parties that process such data.
UU PDP
Deepen your understanding and explore the provisions in detail by downloading this PDF. Your data is safe with us!
3. Privacy Notice under the CCPA/CPRA
In the United States, there is no federal data protection law equivalent to the GDPR or the UU PDP. Instead, regulation exists at the state level, and California is both the strictest and the most influential through the California Consumer Privacy Act (CCPA), in force since 2020 and reinforced by the California Privacy Rights Act (CPRA), which became fully operative in 2023.
The CCPA/CPRA transparency obligation centers on the concept of “Notice at Collection,” set out in Civil Code Section 1798.100. Every business that collects consumers’ personal data must provide notice at or before the point of collection, not afterward. It must cover:
- the categories of personal data collected and the purposes for which they are used
- whether the data is sold or shared with third parties
- the length of time each category of data is retained, or the criteria used to determine that period
For more sensitive data, the CPRA adds a separate layer of obligations through Section 1798.121, which gives consumers the right to limit the use of their sensitive personal information.
If a business uses these categories beyond what is needed to provide the service, it must provide a clear opt-out mechanism, including a link titled “Limit the Use of My Sensitive Personal Information” on its homepage.
The consumer rights that must be described in the Privacy Notice are fairly extensive, each with its own legal basis:
- the right to know and access data (Sections 1798.100, 1798.110)
- the right to delete data (Section 1798.105)
- the right to correct inaccurate data (Section 1798.106, added by the CPRA)
- the right to opt out of the sale or sharing of data (Section 1798.120)
- the right to limit the use of sensitive data (Section 1798.121)
- the right to non-discrimination for exercising the rights above (Section 1798.125)
Section 1798.130 then regulates the business’s obligations regarding the privacy policy: the document must list all the consumer rights above along with the methods for submitting requests, including at least one toll-free phone number.
One thing that distinguishes CCPA/CPRA from the GDPR is that these rules explicitly separate the Notice at Collection (a brief notice at the point of collection) from the Privacy Policy (a complete document detailing the business’s full privacy practices).
Both are mandatory and complement each other; neither one can replace the other.
How Does a Privacy Notice Protect Your Customers’ Data Privacy?
A Privacy Notice protects customers’ data privacy through transparency and control, not through security technology. The document helps customers understand how their personal data is used so they can make more informed decisions about the information they give to an organization.
1. Helping Customers Understand How Data Is Used
A Privacy Notice provides information about the types of data collected, the purposes for which it is used, the parties that receive the data, and how long the data is retained.
With that information, customers can understand the consequences of providing their personal data and assess whether the data use matches their expectations.
For example, customers can learn whether an email address they provide is used only to send transaction confirmations, or also for marketing campaigns, service personalization, or the analysis of customer behavior.
2. Enabling Customers to Exercise Their Privacy Rights
A Privacy Notice also explains the rights held by data subjects. These rights can include:
- The right to access personal data.
- The right to rectify inaccurate data.
- The right to delete certain data.
- The right to withdraw consent.
- The right to restrict data processing.
- The right to object to certain uses of data.
Without clear information about these rights, customers are often unaware that they have control over the use of their personal data.
3. Reducing Unseen Data Processing
One of the core principles of personal data protection is avoiding use of data beyond the reasonable expectations of the data subject.
A Privacy Notice helps ensure that customers understand the processing activities an organization carries out before data is used for a particular purpose.
In this way, the risk that customers perceive the organization as using data covertly or opaquely can be minimized.
During privacy audits, a frequently found issue is a mismatch between the purpose of data use communicated to customers and the data use actually happening in business operations. An accurate Privacy Notice that is updated regularly helps reduce this risk.
4. Building Organizational Trust and Accountability
Public awareness of data privacy continues to rise.
The Cisco Consumer Privacy Survey 2024 shows that more than half of global consumers are aware that data privacy regulations exist in their countries. The higher that awareness, the greater customers’ expectations for transparency in the use of personal data.
For organizations, this means transparency is no longer viewed merely as a legal obligation, but also as a factor that affects customer trust and organizational reputation.
When an organization openly explains how personal data is used, stored, and protected, customers have a stronger basis to trust that organization.
In the long term, consistent transparency helps build a culture of accountability, strengthens data governance, and supports a sustainable data privacy compliance program.
Ready to Manage Privacy Compliance as a Business Risk?
See how GRC helps map personal data risks, monitor UU PDP compliance, and prepare your organization for audits without cumbersome manual processes.
Conclusion
A Privacy Notice is a document that explains how an organization collects, uses, stores, and shares personal data. It is an essential part of data governance transparency and helps organizations meet their obligations under regulations such as the GDPR, the UU PDP, and the CCPA.
For organizations, a Privacy Notice not only supports compliance, but also helps build customer trust, reduce the risk of privacy disputes, and strengthen data governance. For customers, it provides clarity about how their data is used and the rights they hold over that data.
A Privacy Notice should therefore not be seen as a mere legal formality, but as part of good personal data protection practice and responsible governance.
FAQ
If an organization collects personal data, it must be transparent about how that data is used. A Privacy Notice is one of the most common ways to meet that obligation.
A Privacy Notice explains the use of personal data to data subjects, while a Privacy Policy explains the organization’s data management policies and practices in greater depth.
Before or at the time personal data is first collected, for example through a website, app, or registration form.
Yes, if they collect customers’ personal data such as names, email addresses, phone numbers, or transaction data.
No. A Privacy Notice is also needed for apps, registration forms, customer portals, and marketing activities that collect personal data.




