What Is a Privacy Statement?
Short answer: it's the same thing as a privacy policy, just a different name for it. Here's what that actually means for you and what belongs in one.
Last updated: August 2026
The short answer
A privacy statement is a document that tells the people using your website, app, or service what personal information you collect from them, why you collect it, and what you do with it. It's a disclosure, not a contract; you're not asking anyone to agree to anything, you're telling them what already happens when they use your site.
If you've seen the terms "privacy statement," "privacy policy," "privacy notice," and "data protection notice" used seemingly interchangeably, that's because they mostly are. Different companies and different laws prefer different words, but they're describing the same kind of document.
Statement vs. policy vs. notice: is there a real difference?
Not a legal one, in most contexts. "Privacy policy" is the more common term in the United States. "Privacy notice" shows up more often in GDPR-influenced language, since the regulation itself uses "notice" to describe the information a business has to give people about their data. "Privacy statement" sits in between and is used by both camps.
Where it can matter is internal company usage: some organizations use "privacy policy" for the internal governance document that tells employees how to handle data, and reserve "privacy statement" or "privacy notice" for the public-facing version. If you're a small business publishing one document for your website, this distinction usually doesn't apply to you. Pick the name that matches how your audience searches or refers to it, and stay consistent once you've picked it.
What actually goes in a privacy statement
Requirements vary by which laws apply to your visitors, but most privacy statements cover the same core ground:
- Who you are. Your business name and how to contact you about privacy questions.
- What you collect. Names, emails, payment details, cookies, analytics data, device information, whatever actually applies.
- Why you collect it. To fulfill orders, respond to inquiries, run analytics, serve ads, and so on.
- Who else sees it. Third-party services like analytics providers, payment processors, or ad networks.
- What rights people have. This section grows if you have visitors covered by GDPR (EU/UK) or CCPA/CPRA (California), both of which give people specific rights to access, correct, or delete their data.
- How to reach you. A working contact method for privacy-related questions.
The one thing that shouldn't go in one: language copied from someone else's site. Privacy statements are protected by copyright like any other written work, and more practically, a copied statement describes someone else's data practices, not yours.
When you actually need one
If your site collects any personal information at all, including through a contact form, an email signup, or basic analytics, you're already in the territory where most privacy laws expect a statement. The General Data Protection Regulation (GDPR), in effect in the EU since May 2018, requires it for anyone with EU or UK visitors. California's Consumer Privacy Act and its amendment, the CPRA, require it for many businesses handling California residents' data. California's older CalOPPA law requires a conspicuously posted privacy policy from any commercial website collecting personal information from California residents, regardless of where the business itself is located.
In practice, that combination covers the vast majority of public websites. If you're not sure where your visitors are coming from, it's simpler to publish a statement than to try to verify you have zero visitors from any regulated location.
Frequently asked questions
Can I just copy someone else's privacy statement?
No. Privacy statements are copyrighted, and more importantly, a copied statement describes someone else's actual data practices, not yours. It won't accurately reflect what your business does, which defeats the point of having one.
Do I need a lawyer to write one?
Not necessarily, for a straightforward website with typical data collection (contact forms, analytics, maybe ads). A generator or template can get you a reasonable starting point. If your business handles sensitive data, operates internationally, or has an unusual business model, a lawyer's review is worth the cost.
Is "privacy notice" the same as "privacy statement"?
Functionally, yes, in almost every context you'll encounter as a small business owner. "Notice" is more common in GDPR-influenced writing, but it describes the same kind of document.
Related reading: how a privacy policy differs from your terms of service, and disclaimer examples if you need a narrower statement limiting a specific claim rather than disclosing your data practices.
Sources
- General Data Protection Regulation (Regulation (EU) 2016/679), in effect since May 25, 2018
- California Online Privacy Protection Act (CalOPPA), Cal. Bus. & Prof. Code §§ 22575–22579
- California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)
This page describes the general existence and purpose of these laws. It doesn't cover current compliance thresholds or specific requirements, which change and should be verified directly against the current statutory text or with a lawyer before you rely on them.