TL;DR, Quick Answer
6 min readA website privacy policy should explain who controls the data, what is collected, why, legal basis, recipients, retention, rights, transfers, cookies, analytics, and how people can contact you.
A privacy policy is not decorative legal furniture, and the privacy policy requirements analytics adds are the ones teams most often get wrong: what is collected, why, who receives it, and for how long.
A privacy policy is not a decorative legal page. It is where a website explains what personal data it collects, why it collects it, who receives it, how long it is kept, and what rights people have.
For analytics-heavy sites, the privacy policy must be specific enough to describe tracking, cookies, pixels, events, vendors, and advertising uses. Vague language such as "we may collect information to improve services" is rarely enough.
GDPR Privacy Notice Requirements
GDPR Articles 13 and 14 set transparency requirements for personal data collected directly from people or obtained indirectly. A practical privacy policy should include:
- The controller's identity and contact details.
- Data protection officer contact details, if applicable.
- Categories of personal data collected.
- Purposes of processing.
- Legal basis for each purpose.
- Legitimate interests, if relied on.
- Recipients or categories of recipients.
- International transfers and safeguards.
- Retention periods or criteria.
- Data subject rights.
- Right to withdraw consent.
- Right to lodge a complaint with a supervisory authority.
- Whether data provision is required and consequences of not providing it.
- Whether automated decision-making or profiling occurs.
The GDPR text is the authoritative starting point (GDPR Article 13, GDPR Article 14).
Analytics Disclosures
For web analytics, disclose:
- Which analytics tools you use.
- What data they collect.
- Whether cookies or similar technologies are used.
- Whether identifiers are persistent.
- Whether IP addresses are stored or truncated.
- Whether data is shared with vendors or ad platforms.
- Whether data is used for cross-site advertising.
- How users can opt out or change consent.
- Retention period for analytics data.
If you use Google Analytics, Google states that Analytics uses cookies such as _ga to distinguish visitors (Google Privacy and Terms). Your policy should not imply that no identifiers are used if your implementation uses them.
If you use cookieless privacy-first analytics, say that clearly, but do not overclaim. Explain what is still collected, such as page URL, referrer, browser, device type, and approximate location.
- Uses cookies such as _ga to distinguish visitors
- Identifiers can be persistent and link activity over time
- Data may be shared with vendors or ad platforms
- Policy cannot claim no identifiers are used
- No analytics cookies
- Still collects page URL, referrer, browser, device type, approximate location
- State this clearly without overclaiming
- Easier to describe, defend, and verify

Cookie Policy and Consent
Many websites combine a privacy policy with a separate cookie policy. Either structure can work if users can understand the information.
Your cookie disclosure should include:
- Cookie or technology name.
- Provider.
- Purpose.
- Duration.
- Whether it is essential or optional.
- Whether third parties receive data.
- How preferences can be changed.
Regulators often treat analytics cookies as non-essential unless a narrow exemption applies. The UK ICO says organisations need a consent mechanism that lets users control non-essential cookies and similar technologies (ICO).
CCPA/CPRA Additions
If the CCPA applies, your notice also needs California-specific disclosures. The California Attorney General summarises consumer rights including access, deletion, correction, opt-out of sale or sharing, and limits on sensitive personal information (California OAG).
Covered businesses should address:
- Categories of personal information collected.
- Sources of personal information.
- Business or commercial purposes.
- Categories of third parties disclosed to.
- Sale or sharing disclosures.
- Sensitive personal information use.
- Rights request methods.
- Non-discrimination.
- "Do Not Sell or Share" mechanisms where required.
Common Privacy Policy Mistakes
- Listing tools that are no longer used.
- Omitting tag manager pixels added by marketing.
- Saying data is anonymous when it is pseudonymous.
- Failing to mention international transfers.
- Hiding retention behind "as long as necessary."
- Forgetting session replay, heatmaps, A/B testing, and chat widgets.
- Sending personal data in URLs while claiming minimal collection.
- Not explaining consent withdrawal.
Practical Maintenance Workflow
Review the privacy policy whenever:
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
- A new analytics or advertising tool is added.
- A tag manager container changes.
- A new region is targeted.
- A vendor changes subprocessors.
- A cookie banner changes.
- Data retention settings change.
- New events collect account or form-related data.
Privacy policies drift because websites drift. Keep a simple register of data collection points and compare it to the published notice every quarter.
The best privacy policy is easy to write because the data practices are simple. A privacy-first analytics setup with no cookies, no advertising sharing, no full IP storage, and aggregate reporting is easier to explain, easier to defend, and easier for visitors to trust.
Analytics Wording Should Match Reality
Avoid absolute claims unless the implementation supports them. "Anonymous analytics" is only accurate if data cannot reasonably identify a person. Many analytics systems are pseudonymous, not anonymous, because they use identifiers or can link activity over time.
Better wording is specific: "We use cookieless analytics to count aggregate page visits, referrers, device type, and country-level location. We do not use analytics cookies or sell analytics data." Then verify the configuration regularly.

Match the Policy to the Tag Inventory
Before publishing, compare the policy against a live crawl of your site. List every script, iframe, cookie, local-storage key, tracking pixel, chat widget, font provider, form tool, and embedded media service. Then check whether each item appears in the privacy policy, cookie notice, or vendor register with the same purpose and retention story.
This catches common drift. Marketing may remove a pixel but leave it in the policy, making the notice look scarier than reality. Or a new A/B testing script may appear without any disclosure. A quarterly tag-to-policy review keeps the public notice aligned with what visitors actually experience.
Policy Review Checklist
Before publishing the policy, document every analytics event collected, the decision it supports, whether it uses storage or identifiers, which vendors receive it, and when raw records expire. Then test the live site in a clean browser profile.
The policy is ready only when the notice, vendor register, consent behavior, and browser evidence tell the same story. If the network panel shows a tracker the policy does not explain, fix the implementation or the wording before launch.
Frequently Asked Questions
What must a GDPR-compliant privacy policy disclose about data collection?
Under GDPR Articles 13 and 14, the policy needs the controller's identity and contact details, the categories of personal data collected, and the purposes and legal basis for each purpose. The recipients, retention periods, and international transfers involved go in as well. It should also cover data subject rights, the right to withdraw consent, and the right to lodge a complaint with a supervisory authority.
Can a cookie policy live inside the main privacy policy?
Either structure works as long as people can understand the information. Many sites combine the two into one document, while others keep a standalone cookie policy listing each cookie's name, provider, purpose, duration, and whether it is essential or optional.
Does Google Analytics use cookies?
Google states that Analytics uses cookies such as _ga to distinguish visitors. A policy should not imply that no identifiers are used if the site's actual implementation relies on them.
What data does cookieless analytics still collect?
Cookieless, privacy-first analytics can still record page URL, referrer, browser, device type, and approximate location even without cookies. Say this plainly instead of implying that nothing gets tracked.
Does the CCPA require disclosures beyond the GDPR ones?
Yes, if the CCPA applies. A California-facing notice also needs categories and sources of personal information collected, business or commercial purposes, categories of third parties, sale or sharing disclosures, sensitive personal information use, rights request methods, non-discrimination, and "Do Not Sell or Share" mechanisms where required.
What is the difference between anonymous and pseudonymous analytics data?
Anonymous data cannot reasonably identify a person, while pseudonymous data uses identifiers or can link activity over time without attaching a name. Many analytics systems are pseudonymous rather than anonymous, so calling them "anonymous" in a policy overstates what the setup actually does.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
How often should a privacy policy be reviewed?
Review it whenever a new analytics or advertising tool gets added, a tag manager container changes, a new region gets targeted, or a vendor changes subprocessors. Also review it when a cookie banner changes, retention settings change, or new events start collecting account or form data. Comparing a data collection register against the published notice every quarter catches the drift between them.
What does a tag-to-policy review involve?
A tag-to-policy review lists every script, iframe, cookie, local storage key, tracking pixel, chat widget, font provider, form tool, and embedded media service running on the site. Each one then gets checked against the privacy policy, cookie notice, or vendor register for a matching purpose and retention story. This catches cases where marketing removes a pixel but leaves it in the policy, or adds a new A/B testing script without disclosing it.
Are analytics cookies treated as essential under cookie consent rules?
No, regulators typically treat analytics cookies as non-essential unless a narrow exemption applies. The UK ICO says organisations need a consent mechanism that lets users control non-essential cookies and similar technologies.
What are common mistakes in a privacy policy?
Common mistakes include listing tools that are no longer used, omitting tag manager pixels added by marketing, and describing pseudonymous data as anonymous. Others are failing to mention international transfers, hiding retention behind "as long as necessary," forgetting session replay, heatmaps, A/B testing, and chat widgets, and sending personal data in URLs while claiming minimal collection.
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Articles


A Practical Overview - GDPR vs CCPA
Scope, consent, sensitive data, enforcement and transfers all differ. What a California-safe setup still gets wrong the moment European rules apply.


Explained Clearly - GDPR Analytics Without Consent
A GDPR analytics tool can sometimes run consent-free, but the conditions are narrow. The two questions that decide it: device storage, and personal data.


A Practical Guide to Privacy Management Tool
Consent, data mapping, DSAR, DPIA, vendor risk: a privacy management tool solves one of five different problems. Which category your obligations need.

