With increased regulation of privacy rights, you would expect data owners to be keener on data collection and processing practices. However, there is increasing evidence that whilst online users are concerned about their privacy, they hardly ever take time to read online privacy policies. They instead have an expectation that regardless of what you say in your privacy policy, you will respect their privacy rights.
Therefore, your users’ disinterest in your privacy policy does not give you the right to use their information as you please. In fact, in addition to providing an online privacy policy, you should show that your organization walks the “talk” of the policy. In other words, you should do what your policy says. This not only gives credence to your brand but also protects you from legal disputes.
Best Practices for an Online Privacy Policy
1. Be Factual
2. Make it clear and simple
3. Obtain User Consent
4. Make Your Privacy Policy Readily Accessible
Provide an easily accessible link to your Privacy Policy on your website or on your app. For websites, the standard practice is to place the privacy policy at the footer of your homepage. You should also include it in all places where you request your user’s to key in personal information. For mobile apps, the link may be placed on the welcome screen of your App and on an accessible drop-down menu within your app.
5. Demonstrate Accountability
6. Follow Data Minimisation Approach
Collect only the amount of personal data that is relevant for the purposes that you have identified in your policy. In the context of your online business/website/app, ask yourself what is the absolute minimum information you require and how do you intend to use it? For example, if it is a blog, you may need only email addresses so you can alert your followers of new posts or you can send them newsletters on the latest topics or trends. Telephone numbers and IDs may not be necessary. On the other hand, if you are selling products through your app or website, you may need a host of information for purposes of the contract. This may include full names, email, phone numbers, credit/debit card information etc. But even here, be careful to seek only what you require. The bottom line, be clear on why you need the information you are collecting. Avoid collecting data on the off-chance that it may be useful in the future.