Home Blog Privacy Notice vs Privacy Policy: The Real Difference

GDPR

Privacy Notice vs Privacy Policy: The Real Difference

Posted by Kevin Yun|August 30, 2026

For the public-facing document on your website, yes, effectively they are the same thing, and you can call it either. Neither phrase appears anywhere in the GDPR. What the regulation requires is a defined list of information under Articles 13 and 14, which the ICO refers to as your "privacy information." The distinction practitioners draw is real but internal: a notice faces outward, a policy governs your own staff.

This article covers what the regulation actually says, where the two-term convention came from, why it survives despite having no legal basis, which documents a B2B SaaS genuinely needs, and what regulators penalise when they look at one of these pages. It does not cover how to write the document itself.

Neither Term Appears In The Regulation

Search the GDPR for "privacy notice" and you will not find it. Search for "privacy policy" and you will not find that either. Articles 12, 13 and 14 talk about information to be provided to the data subject, and Article 12 sets the standard for how that information must be delivered: concise, transparent, intelligible, in clear and plain language, and easily accessible.

The UK regulator has settled on its own phrase. On its right to be informed guidance, checked 8 August 2026, the ICO states that Articles 13 and 14 specify what people have the right to be informed about as a minimum, and that it calls this "privacy information." That is a third term, and it is the only one with any official standing in either jurisdiction.

So the honest answer to the title question is that you are choosing a label for a document whose contents are prescribed and whose name is not. Nobody has ever been fined for the word at the top of the page.

What Articles 13 And 14 Actually Require

The two articles split on one axis: where the data came from.

Article 13 applies when you collect personal data directly from the person. Someone signs up for your trial, fills in a form, emails your support desk. Article 14 applies when you obtain it from somewhere else, including an enrichment vendor, a public source, or your customer's account when they upload their own contacts.

Article 14 is the one most SaaS companies overlook, and it carries a timing obligation Article 13 does not. Where data is obtained indirectly, the information must be provided within a reasonable period and at the latest within one month, or at the point of first communication with the person if that is sooner.

Both articles require the same broad categories: who you are, why you are processing, your lawful basis, who receives the data, whether it goes to a third country and on what safeguard, how long you keep it, and what rights the person has. Your Article 30 record of processing activities is the natural source for most of that, which is why teams who maintain records of processing activities properly find this document much easier to write and much easier to keep accurate.

Where The Two-Term Convention Came From

The convention is a practitioner one, and it is genuinely useful even though it is not law.

A notice is a notification. It tells people what you do with their data. It is not an agreement, nobody signs it, and nobody should be asked to accept it. Requiring a tick box that says "I agree to the privacy notice" is a small but revealing error, because it implies consent is your lawful basis when it usually is not.

A policy in the ordinary corporate sense is an internal governance document. It tells your own staff how to handle personal data: who can access what, how long things are retained, what to do when a request arrives, when to escalate a suspected breach. It is written for employees, not customers.

Under that convention, the page on your website is a notice and the document in your handbook is a policy. The problem is that "privacy policy" became the settled label on the open web long before the GDPR existed, browsers and app stores ask for a "privacy policy" link by name, and changing it now would confuse more people than it clarifies.

Which Documents Your SaaS Actually Needs

Three, and they are genuinely different artefacts.

The public notice, whatever you call it, covering your website visitors, trial users and customers. The internal policy, telling your team how to handle data. And usually a separate employee-facing notice, because your staff are data subjects too and Article 13 applies to their data exactly as it applies to a customer's.

Two adjacent documents are frequently confused with these and are neither. Your data processing agreement is a contract with a customer or a vendor, not a notice to individuals, and it is a different instrument again from the confidentiality agreement it often arrives beside, as DPA versus NDA sets out. Your cookie banner is a consent mechanism under the ePrivacy rules, not a substitute for the information obligation. If you tell a reader where your data is hosted and where it is transferred, that belongs in the notice under Article 13(1)(f), and the underlying question of what residency actually means is worth understanding separately before you write that line, because most claims about it are broader than the facts support.

What Regulators Penalise Is Detail, Not The Title

The enforcement record is consistent on this point. What gets criticised is vagueness.

The ICO's monetary penalty notice against TikTok, published 15 May 2023 in relation to a £12.7 million fine issued that April, set out its detailed position on Article 13 in an annex. The pattern in that document, and in the Irish decisions it aligns with, is that generic statements about recipients, transfers, lawful bases and retention are not enough. Recipients should be described by activity, sector and location. Naming "standard contractual clauses" without more does not adequately explain a transfer.

None of that turns on whether the page said notice or policy. It turns on whether a reader could work out what actually happens to their data. A page that says "we may share your data with trusted partners" fails at any title.

Common Mistakes With Privacy Notices And Policies

Treating the public notice as a contract. Asking people to tick a box agreeing to it muddles the legal picture and suggests consent is doing work it is not. Notices inform; they are not accepted.

Publishing one document and calling it done. The customer-facing notice does not cover your employees, and the internal policy is not written for the public. Most teams find they need three documents once they look properly.

Forgetting Article 14 exists. Any personal data you did not collect directly from the person triggers a separate obligation with its own one-month deadline. Enrichment tools and customer-uploaded contact lists both land here.

Describing recipients in categories so broad they mean nothing. "Service providers" tells a reader nothing. Regulators have said repeatedly that the description should let someone understand the type, sector and location of who receives their data.

Letting the notice drift from reality. The document describes your processing as it was on the day it was written. Add a subprocessor, change a retention period or open a new region and the notice is now inaccurate, which is a transparency failure in itself.

FAQ

Is a privacy notice legally required under GDPR?

The information is required, not the document. Articles 13 and 14 oblige you to provide a specified list of details to data subjects. A published notice is simply the most practical way to discharge that obligation for a website or product, which is why essentially every organisation has one.

Can I call my page a privacy policy instead of a privacy notice?

Yes. Neither term appears in the regulation and no regulator requires a particular label. "Privacy policy" is the more recognised phrase publicly and app stores ask for it by name. The wording inside the document matters; the heading does not.

Do I need a separate privacy notice for employees?

Almost always yes. Your staff are data subjects and Article 13 applies to their data as it does to customers'. Employment processing covers payroll, performance, monitoring and absence, none of which belongs in a customer-facing notice and most of which employees have a right to know about.

What is the difference between a privacy notice and a data processing agreement?

A notice informs individuals about your processing. A data processing agreement is a contract between two organisations that sets out Article 28 obligations when one processes personal data for the other. Different audiences, different legal function, and one cannot substitute for the other.

Closing Thought

The two-term debate has consumed a remarkable amount of professional energy for a distinction the law never made. It persists because it flatters a certain kind of expertise: knowing that your page is technically a notice is an easy way to sound precise without saying anything a reader benefits from.

The useful question is whether someone reading your page could work out what actually happens to their data, and most published notices fail that test regardless of their title. If you want the underlying processing to be documented well enough that the notice writes itself, that is really a records problem. ComplyDog hosts a compliance portal on your own domain covering your DPA, subprocessor list, data subject request handling and security page, which keeps the facts a notice depends on in one maintained place. It does not write your privacy notice, and no tool should claim to.