---
title: "Privacy Law: How to Draft a Privacy Policy That Builds User Trust"
description: This article describes some of the factors that go into drafting a well-crafted privacy policy.
image: https://spzlegal.com/hubfs/41.png
---

[Skip To Content](https://spzlegal.com/blog/privacy/drafting-privacy-policy#main-content)

[![spz-legal-logo-2024](https://spzlegal.com/hubfs/logos/spz-legal-logo-2024.svg)](https://spzlegal.com/)

- [Clients](https://spzlegal.com/our-clients) 
    - [Featured Clients](https://spzlegal.com/our-clients)
    - [Case Study: Verto Education](https://spzlegal.com/verto-case-study)
    - [Case Study: Kong Studios](https://spzlegal.com/kong-studios-case-study)
    - [Case Study: WindBorne](https://spzlegal.com/windborne-case-study)
    - [Case Study: Tango](https://spzlegal.com/tango-case-study)
    - [Case Study: Sown To Grow](https://spzlegal.com/sown-to-grow-case-study)
    - [Case Study: Capture6](https://spzlegal.com/capture6-case-study)
    - [Case Study: Datava](https://spzlegal.com/datava-case-study)
    - [Case Study: Voxel](https://spzlegal.com/from-scrappy-startup-to-selling-to-fortune-100)
- [Team](https://spzlegal.com/team) 
    - [About Us](https://spzlegal.com/team)
    - [Becky Mancero](https://spzlegal.com/team/becky-mancero)
    - [David De La Flor](https://spzlegal.com/team/david-de-la-flor)
    - [Elizabeth Thorne](https://spzlegal.com/team/elizabeth-thorne)
    - [Gea Kang](https://spzlegal.com/team/gea-kang)
    - [Hannah Porter](https://spzlegal.com/team/hannah-porter)
    - [Hash Zahed](https://spzlegal.com/team/hash-zahed)
    - [Jessica Sulahian](https://spzlegal.com/team/jessica-sulahian)
    - [Morgan Kasenchak](https://spzlegal.com/team/morgan-kasenchak)
    - [Paige Southworth](https://spzlegal.com/paige-southworth)
    - [Ryan Shaening Pokrasso](https://spzlegal.com/team/ryan-shaening-pokrasso)
    - [Sam Taylor](https://spzlegal.com/team/sam-taylor)
    - [Tami Gore](https://spzlegal.com/team/tami-gore)
    - [Specialists](https://spzlegal.com/our-partners)
- [Services](https://spzlegal.com/business-law-services) 
    - [Formation & Corporate](https://spzlegal.com/business-law-services/formation)
    - [Mergers & Acquisitions](https://spzlegal.com/business-law-services/mergers-acquisitions)
    - [Funding](https://spzlegal.com/business-law-services/funding)
    - [Hiring & Equity Compensation](https://spzlegal.com/business-law-services/employment)
    - [Data Privacy](https://spzlegal.com/business-law-services/data-privacy)
    - [IP Protection](https://spzlegal.com/business-law-services/ip-protection)
    - [Commercial Agreements](https://spzlegal.com/business-law-services/sales-agreements)
- [Startup Center](https://spzlegal.com/startup-center) 
    - [Formation & Corporate](https://spzlegal.com/startup-center/formation-and-corporate-topics)
    - [Mergers & Acquisitions](https://spzlegal.com/startup-center/mergers-and-acquisitions)
    - [Funding](https://spzlegal.com/startup-center/funding)
    - [Hiring & Equity Compensation](https://spzlegal.com/startup-center/hiring)
    - [IP Protection](https://spzlegal.com/startup-center/ip-protection)
    - [Data Privacy](https://spzlegal.com/startup-center/data-privacy)
    - [Commercial Agreements](https://spzlegal.com/startup-center/commercial-agreements)
- [Blog](https://spzlegal.com/blog)
- [Contact](https://spzlegal.com/contact)

- [LinkedIn](https://www.linkedin.com/company/spz-legal)

# Demystifying Privacy Law: Drafting a Privacy Policy

[Contracts](https://spzlegal.com/blog/tag/contracts), [Data Privacy](https://spzlegal.com/blog/tag/data-privacy)

![](https://spzlegal.com/hs-fs/hubfs/41.png?width=760&height=428&name=41.png)

If your business collects [personally identifiable information (or PII)](https://spzlegal.com/blog/data-privacy/personally-identifiable-information) about your customers, you will need a privacy policy to let them know how you plan to collect, use, share and secure information about them. In an increasingly digitalized world, privacy policies command nearly the same level of respect as mission statements. Privacy policies set out an organization’s first principles of consumer protection and provide a roadmap of how sensitive issues such as PII are handled. This article describes some of the factors that go into a well-drafted privacy policy--and the factors that we advise our clients to think through. 

## Choosing Your Founding Principles

After laying out an approach with respect to PII, companies should identify and establish their convictions on the topic of information privacy and build a working policy around those principles. The Federal Trade Commission [urges](https://www.ftc.gov/sites/default/files/documents/reports/federal-trade-commission-report-protecting-consumer-privacy-era-rapid-change-recommendations/120326privacyreport.pdf) organizations to adopt the following three propositions as privacy pillars:

### Privacy By Design

> Privacy should be built in at every stage of product development.

Too often, consumer privacy issues are relegated to organizational back-burners. [High-profile data breaches](https://www.huffingtonpost.com/kyle-mccarthy/32-data-breaches-larger-t_b_6427010.html) and [widespread public concern over the security of personal information](https://www.eff.org/nsa-spying) have made it perilous for companies to continue to ignore these matters. Institutional handling of such sensitive topics impact vital metrics of trust, accountability, and transparency. You should include privacy protections as essential ingredients in any services offered.

### Simplified Choice

When engaging in transactions, consumers should feel empowered to make informed decisions about how their personal information will be used. Companies should build simple processes that allow clients to choose the extent to which their information will play a role in organizational actions, whether it be third-party data exchange or PII storage. Offer consumers clear options, and let them make the decisions.

### Greater Transparency

When it comes to collecting and using customer information, companies should err on the side of transparency. It’s a bad idea to bury information policies in hyperlinked asides concealed by an avalanche of legalese. The more opaque the process seems, the less likely you are to gain the trust of your clients. Share openly, and make sure your customers know what is happening to their sensitive information.

## Constructing An Elegant Statement

Once you’ve laid the bedrock for your organization’s privacy policy, it is time to pen the policy itself. The best privacy statements are simple, readable documents that outline procedures and collection practices while allowing consumers to exercise their discretion by choosing how their information is shared. The following suggestions borrow heavily from the California Attorney General’s guidelines on [“Making Your Privacy Practices Public.”](https://oag.ca.gov/sites/all/files/agweb/pdfs/cybersecurity/making_your_privacy_practices_public.pdf)

### Readability

Avoid lengthy, unreadable privacy policies couched in technical jargon and obscure legal phrasing. Use plain language and intuitive formatting, such as “layered” statements that rank and explain issues in order of relevance. Where possible, standardize your use of terminology and strive for succinct declarations.

### Online Tracking

Make sure your organization’s policies regarding cookies and other online tracking methods are clear and easy to find. Where possible, ensure your customers are informed of the various “Do Not Track” protections [available in most Web browsers,](https://support.google.com/chrome/answer/2790761) and describe your site’s response to “Do Not Track” requests.

### Data Use & Data Sharing

Explain your use of personally identifiable information in simple, clear terms. Note any relevant storage or sharing procedures, and detail with whom and under what circumstances you intend to share PII, including how you intend to share information with law enforcement.

### Individual Choice & Access

Where possible, describe the choices your customers have in how their personal information is shared, accessed, used and stored. Create opt-outs for certain non-vital uses of PII, and be sure to pinpoint your organization’s policies relating to unauthorized information use and the length of time sensitive details are stored in company servers.

### Accountability

Provide company contact information for customers who have questions relating to privacy issues, and highlight avenues of redress in the case of data breaches or other informational malfeasance.

## Review

Broadcast your intention to conduct regular privacy reviews. These reviews will ensure your company is living up to its promises, and will provide your customers with some much-needed peace of mind.

## Privacy Certification Programs

Consider adopting privacy certification programs such as [TRUSTe](https://www.truste.com/) to better improve your institution’s handling of privacy-related matters and promote consumer trust as well as corporate accountability.

For more information on how to construct a great privacy policy, [contact us](https://spzlegal.com/contact).

---

*DISCLAIMER: The information in this article is provided for informational purposes only and should not be construed or relied upon as legal advice. This article may constitute attorney advertising under applicable state laws.*

[![spz-legal-logo-2024](https://spzlegal.com/hubfs/logos/spz-legal-logo-2024.svg)](https://spzlegal.com/)

Categories

- [Funding](https://spzlegal.com/blog/tag/funding)
- [Incorporation](https://spzlegal.com/blog/tag/incorporation)
- [Employment](https://spzlegal.com/blog/tag/employment)
- [Contracts](https://spzlegal.com/blog/tag/contracts)
- [Data Privacy](https://spzlegal.com/blog/tag/data-privacy)
- [M&A](https://spzlegal.com/blog/tag/ma)
- [Firm Culture](https://spzlegal.com/blog/tag/firm-culture)
- [News](https://spzlegal.com/blog/tag/news)
- [Social Enterprise](https://spzlegal.com/blog/tag/social-enterprise)
- [Acquired](https://spzlegal.com/blog/tag/acquired)
- [Intellectual Property](https://spzlegal.com/blog/tag/intellectual-property)
- [Client Engagement](https://spzlegal.com/blog/tag/client-engagement)
- [Nonprofit](https://spzlegal.com/blog/tag/nonprofit)
- [AI](https://spzlegal.com/blog/tag/ai)
- [Artificial Intelligence](https://spzlegal.com/blog/tag/artificial-intelligence)

Recent Posts

- [Becky Mancero Recognized by Best Lawyers: Ones to Watch for Second Consecutive Year](https://spzlegal.com/blog/becky-mancero-best-lawyers-ones-to-watch-2026)
- [What We Fix in Diligence Over and Over Again Before a Financing or Exit](https://spzlegal.com/blog/startup-legal-issues-before-financing-exit)
- [Becky Mancero on the Melissa Widner Podcast: Cap Tables, Equity Mistakes, and AI in the Legal World](https://spzlegal.com/blog/becky-mancero-on-the-melissa-widner-podcast-cap-tables-equity-mistakes-ai-in-the-legal-world)
- [Spinning Out a Product Into a New Startup: Legal Issues Founders Need to Solve Early](https://spzlegal.com/blog/spinning-out-product-new-startup-legal-guide)
- [Converting an LLC to a Corporation: When It Makes Sense and How to Do It Without Creating a Mess](https://spzlegal.com/blog/converting-llc-to-corporation-startup-guide)
- [The Role of LOIs in M&As: Structuring Letters of Intent](https://spzlegal.com/blog/the-role-of-lois-in-mas-structuring-letters-of-intent)
- [Exit Structures: Mergers, Acquisitions, & Tax Treatment](https://spzlegal.com/blog/exit-structures-mergers-acquisitions-tax-treatment)
- [Due Diligence Best Practices: Be Prepared for M&A Success](https://spzlegal.com/blog/due-diligence-best-practices-be-prepared-for-ma-success)

Locations

**San Francisco Bay Area, California**

**Milwaukee, Wisconsin**

**Los Angeles, California**

**Denver, Colorado**

**Miami, Florida**

**Austin, Texas**

Contact Us

[Email](https://spzlegal.com/contact)

Follow Us

- [LinkedIn](https://www.linkedin.com/company/spz-legal)

Startup Topics

- [Formation](https://spzlegal.com/blog/tag/incorporation)
- [Funding](https://spzlegal.com/blog/tag/funding)
- [Employment](https://spzlegal.com/blog/tag/employment)
- [Intellectual Property](https://spzlegal.com/blog/tag/intellectual-property)
- [Data Privacy](https://spzlegal.com/blog/tag/data-privacy)
- [Commercial Agreements](https://spzlegal.com/blog/tag/contracts)
- [M&A Law](https://spzlegal.com/blog/tag/ma)

© 2026 [SPZ Legal, P.C. Startup Lawyers](https://spzlegal.com/)

- [Terms of Use](https://spzlegal.com/terms)
- [Privacy Policy](https://spzlegal.com/privacy)

[![California Chambers Spotlight 2025 Award](https://spzlegal.com/hs-fs/hubfs/ca-chamber-spotlight-2025-badge.jpg?width=300&height=300&name=ca-chamber-spotlight-2025-badge.jpg)](https://chambers.com/law-firm/spz-legal-p-c-120:23727975)

 DISCLAIMER: The information on this website is provided for informational purposes only and may not be updated over time. Nothing on this website should be construed as legal advice or relied upon in any way. No attorney-client relationship is intended to be created through this website. This website may be considered attorney advertising in some states. Prior results do not guarantee a similar outcome.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Aaron Murphy",
    "url" : "https://spzlegal.com/blog/author/aaron"
  },
  "dateModified" : "2026-05-22T17:46:46.909Z",
  "datePublished" : "2019-06-12T01:12:31.000Z",
  "headline" : "Privacy Law: How to Draft a Privacy Policy That Builds User Trust",
  "image" : [ "https://spzlegal.com/hubfs/41.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://spzlegal.com/blog/privacy/drafting-privacy-policy",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://spzlegal.com/hubfs/logos/spz-legal-logo-2024.svg"
    }
  }
}
```