Practical tips and tools

for business management

Tips and forms to help you grow, manage and develop your business. From financial planning templates to practical advice on risk management and day-to-day operations.

Featured articles

How is a company's credit limit determined?

A brief explanation of how to determine a company's credit limit for post-payment. Practical calculation example

Useful contacts for business growth

Useful and Capitalia-verified service providers that can be useful for the development of any business

3 books to improve productivity

Ideas on how to focus your energy on the work with the greatest impact can be gleaned from these three books

Table of contents

Business development

Loans for companies

Company management

Investments and sale of bills

Does your website need a privacy policy?

Since time immemorial, people have been accustomed to providing their services or goods only for an appropriate remuneration. You pay either with your money or with your data for every product or service you consume. You pay both ways for using some services - for example, a Netflix subscription not only charges a few euros from your bank account every month, but also collects your data about the movies and series you watch.

Since the misuse of personal data can have a significant impact on people's lives, regulators are taking various measures to protect personal data. One of these measures is the need for a privacy policy required by the European Union's General Data Protection Regulation (GDPR).

What is the privacy policy?
The GDPR requires that when using personal data, people must be told why and how their data will be used and what their rights are in relation to their personal data.
This information is usually reflected in a document called a privacy policy, which is published on the company's website.

What is personal data?
Personal data is any information that can be used to identify a natural person. Personal data may include, for example, first name, last name, phone number, email address, location, age, IP address, work email address and other information.
However, personal data is not company data that does not relate to any specific person (for example, an email address info@website.com).

When does your website or application need a privacy policy?
The main criterion is simple - if your company uses personal data, you must have a privacy policy.
Typical cases where personal data is used are when the company:
  • uses online contact forms;
  • send email notifications;
  • process payments;
  • supplies goods or services;
  • analyze website or app visits;
  • uses online questionnaires;
  • uses live chat or chatbot;
  • company users have user profiles.

In these cases, the company uses personal data and the GDPR requires the company to have a privacy policy. If a company uses personal data but you don't have a privacy policy, data protection authorities can fine the company.

In addition, your business service providers may also require you to have a privacy policy. For example, it is currently required by the App Store, Google Play, Google Analytics, Facebook, Shopify, as well as several payment service providers.

Why is a privacy policy important?
If you have an appropriate privacy policy:
  • you comply with the law (GDPR).
  • you avoid unexpected fines. If a company does not comply with the GDPR, you can be fined up to €20 million or 4% of your total worldwide annual turnover (whichever is greater).
  • One of the largest fines for privacy policy non-compliance with GDPR was received by WhatsApp in the amount of 225 million euros.
  • Recently, small businesses and individuals in Europe have also often been fined for not having a privacy policy or for not having enough information in their policies.
  • Thanks to the privacy policy, the company will gain the trust of its customers. Customers will know why you need their personal data and how it will be used.
  • The Company will comply with the request for privacy policies that may be required by third parties such as payment service providers, app stores and others.

What information should be included in the privacy policy?
The privacy policy should tell you how and why you use personal data. Other information required by the GDPR must also be provided, such as:
  • company/organization information and contact information;
  • which particular website, app or activities are covered by the privacy policy;
  • what personal data is used;
  • why and how the company uses personal data;
  • legal basis for the use of personal data;
  • how long personal data is stored;
  • to whom you disclose your users' personal data and whether you transfer personal data outside the EEA (European Economic Area);
  • users' rights, including the right to submit a complaint to a supervisory authority (in Latvia – Data State Inspectorate).

How can I create a privacy policy?
  • Law firm: The best option, but usually not cheap and does not offer an immediate solution.
  • Online generator: For example, Ligalio's privacy policy generator allows you to instantly create a privacy policy for a website or app at a friendly price using a self-help tool.
  • Templates/templates: usually offer a “generic” version of a privacy policy that does not meet the needs of a particular company, as each company uses personal data differently.
  • Write it yourself: unless you are a lawyer or GDPR specialist, we do not recommend this.

Where should I put my privacy policy on my website or app?
The GDPR does not specify where exactly you must place your privacy policy on your website or app. However, the privacy policy should always be easily accessible. This means that a person does not have to search for information, but it should be immediately clear where and how this information can be accessed.

A direct link to the privacy policy must be clearly visible on every page of the website. Therefore, the most popular place to place a privacy policy on a website is at the bottom of the page, in the footer.

Also, your privacy policy should be easily visible and accessible in your app.