← all articles

What a privacy policy actually commits a company to

Almost everyone has clicked “I agree” on a privacy policy without reading it. I have too, and I run websites for a living. The document looks like boilerplate, and a lot of it is. But a privacy policy is also one of the few places where a company writes down, in public, what it says it will do with your data.

That matters because the words carry weight. A policy is not a legal shield for the company alone. In many places it is a statement the company can be held to, by regulators and sometimes by customers. If you understand what it commits a company to, and what it quietly leaves open, you can decide in a few minutes whether to hand over your details. This is general education, not legal advice.

what it is

A privacy policy is a public document where an organisation describes what personal data it collects, why it collects it, who it shares it with, how long it keeps it, and what rights you have over it. “Personal data” means anything that can identify you, alone or combined with other information. Your name and email are obvious. Your IP address, device ID, location and browsing history count too.

Two things are worth separating early.

  • a privacy policy: a description of the company’s practices. It tells you what they say they do.
  • terms of service: the contract about using the product. It tells you what you and the company owe each other.

They often sit side by side in a website footer, and people mix them up. The policy is mostly a disclosure. The terms are mostly a contract. Both can matter, but they do different jobs.

A policy also differs from a promise of perfect security. Saying “we protect your data” is a commitment to take reasonable steps. It is not a guarantee that nothing will ever leak.

how it works

The mechanism has three layers: the law that requires the document, the text the company writes, and the enforcement that follows when the two do not match.

Many jurisdictions require a company to tell you what it does with your data at the moment it collects it. Three I run into most often:

  • the EU: the General Data Protection Regulation requires organisations to give people clear information about processing, including purposes, recipients and retention periods, and to have a lawful basis for the processing.
  • Singapore: the Personal Data Protection Act 2012 sets obligations around consent, purpose limitation, notification, protection and retention. The Personal Data Protection Commission publishes guidance and enforcement decisions in plain view. I am based here, so this is the regime I deal with most.
  • the US: there is no single federal privacy law covering everything. A patchwork of state laws and sector rules applies, and the Federal Trade Commission uses its authority over unfair or deceptive practices to police what companies say. Its privacy and security guidance for business is a good read if you want to see how regulators think.

The details differ, but the shared idea is simple: say what you do, then do what you say.

the text itself

A typical policy has the same sections in roughly the same order. Collection (what data), use (what for), sharing (who else gets it), retention (how long), your rights (access, correction, deletion), security, and a contact route. Many also have a “changes to this policy” clause.

Each section is a statement of fact the company is making. If a policy says “we do not sell your personal information” and the company then sells it, that gap is the problem. The wording is what creates the exposure.

enforcement

When regulators act, the question is often whether a company’s behaviour matched its own words. A company that says one thing in its policy and does another can be accused of deception, even if nothing in the policy was illegal on its face. A company that says nothing at all about a practice has a harder time claiming you agreed to it.

This is why careful companies write policies that are vague. Vague language gives them room. “We may share data with trusted partners to improve our services” commits them to very little, because “trusted partners” and “improve” can mean almost anything. When I read a policy, I am looking for specific commitments, and noting where the language goes soft.

why it matters

Reading a policy, even badly, gives you information you cannot get elsewhere. Here are the practical reasons I care.

  • it tells you who the real audience is. If a free app’s policy lists advertising partners and data brokers, you are part of the product. The policy often shows how the business makes money before the marketing page does.
  • it sets a baseline you can point to. If a company later behaves differently from what it wrote, you have a document to cite when you complain to the company or to a regulator such as the PDPC.
  • it explains what survives deletion. Policies describe retention, and that is where “delete my account” gets complicated. I wrote about that gap in what actually gets deleted when you delete it.
  • it shows what is collected without you doing anything. Location, device identifiers and metadata can be collected in the background. For a sense of how much leaks even when content is encrypted, see metadata explained: what encryption does not hide.

Policies matter in everyday situations too. A hotel wifi login page or an airline check-in app asks for consent on the spot, and the policy behind it is longer than most people expect. I went through a few of these in what you agree to at a hotel or airport.

common misconceptions

“if there is a privacy policy, my data is private”

No. The name is misleading. A privacy policy describes what a company does with data, including sharing it. Plenty of policies say, in plain words, that your data will be shared widely. The document exists because the law requires disclosure, not because the company promises privacy. A policy can be perfectly compliant and still describe a lot of sharing.

“clicking agree means I gave up all my rights”

Usually not. In the EU and Singapore, your statutory rights, such as access to your data or the ability to withdraw consent, generally do not disappear because you clicked a button. A company cannot normally contract out of data protection law through its own policy. Rules differ by country and by situation, so check the regulator’s own guidance if something specific is at stake.

“the company can’t change it”

They can, and most policies say so. A “changes to this policy” clause lets the company update the text, usually with a notice period or a banner. This is why a policy you read once, years ago, may not describe what happens today. Some companies email you about material changes. Others only update the page date. If something sensitive is at stake, save a copy of the version you agreed to, or check an archive of past versions.

“a long policy means a careful company”

Length is not quality. Some of the most thorough policies I have read were short and specific. Some of the longest were padded with generic text that said little. The test is whether the document answers the five questions that matter: what is collected, why, who gets it, how long is it kept, and how do I get it deleted. If you cannot find those answers, the company has either been vague on purpose or has not thought it through.

how I read one in ten minutes

I do not read every word. I search the page for a handful of terms and read around them.

  • “sell” or “share”: does the company sell data or share it for advertising?
  • “retain” or “retention”: how long is data kept, and is there a number, or just “as long as necessary”?
  • “delete”: can I delete my account and data, and how?
  • “transfer”: does data leave the country, and under what safeguards?
  • “third parties” or “partners”: are they named, or described only by category?

A policy that names its processors and gives specific retention periods is making real commitments. A policy that relies on “may”, “from time to time” and “trusted partners” is making very few. Neither tells you the company is good or bad, but it tells you how much you can hold it to.

If you use tools that create separate identities or browser profiles, the policy still applies to the data collected through them. Fingerprinting and tracking get complicated fast, and the sister site antidetectreview.org covers that side in more depth.

where to go from here

If this was your first time looking closely at what a policy says, these are the next things I would read.

If you only take one thing away, make it this: a privacy policy is a list of claims. Read it for the specific ones, notice the vague ones, and keep a copy of anything that matters. That is not legal advice, but it is a habit that costs very little and tells you a lot.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-10-02.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →