Use this checklist before publishing or certifying your privacy policy. Clerica scores disclosure clarity on verify pages — not legal adequacy — but strong items correlate with higher rubric scores and customer trust.
Checklist
- [ ] Privacy policy describes categories collected (12 months)
- [ ] Sources of PI identified
- [ ] Business/commercial purposes listed per category
- [ ] Categories disclosed to third parties documented
- [ ] Sale/sharing practices assessed with counsel
- [ ] Do Not Sell or Share link provided if applicable
- [ ] Sensitive PI categories disclosed (CPRA)
- [ ] Retention criteria published
- [ ] Access/know request method available
- [ ] Deletion request method available
- [ ] Correction request method available (CPRA)
- [ ] Limit sensitive PI use method if applicable (CPRA)
- [ ] Non-discrimination statement included
- [ ] Two or more designated request channels
- [ ] Request verification process documented internally
- [ ] Response timelines tracked (45 days + extension)
- [ ] Authorized agent process defined
- [ ] Employee/ B2B exemption assessed if applicable
- [ ] Policy updated when data practices change
- [ ] Financial incentive programs disclosed if offered
How Clerica uses this
Certification rubric rewards specificity, readable structure, and substantive coverage. Consumer-Friendly badge requires score ≥ 75 on active Certified subscription.
After publish
Material policy changes without updates may trigger integrity scan drift — downgrade certification until fixed.
Tools: Privacy Policy Generator · How to write a privacy policy · Business FAQ
Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.