Use this checklist before publishing or certifying your privacy policy. Clerica scores disclosure clarity on verify pages — not legal adequacy — but strong items correlate with higher rubric scores and customer trust.
Checklist
- Privacy policy describes categories collected (12 months)
- Sources of PI identified
- Business/commercial purposes listed per category
- Categories disclosed to third parties documented
- Sale/sharing practices assessed with counsel
- Do Not Sell or Share link provided if applicable
- Sensitive PI categories disclosed (CPRA)
- Retention criteria published
- Access/know request method available
- Deletion request method available
- Correction request method available (CPRA)
- Limit sensitive PI use method if applicable (CPRA)
- Non-discrimination statement included
- Two or more designated request channels
- Request verification process documented internally
- Response timelines tracked (45 days + extension)
- Authorized agent process defined
- Employee/ B2B exemption assessed if applicable
- Policy updated when data practices change
- Financial incentive programs disclosed if offered
How Clerica uses this
Certification rubric rewards specificity, readable structure, and substantive coverage. Silver Verified badge requires score ≥ 75 on active Certified subscription.
After publish
Material policy changes without updates may trigger integrity scan drift — downgrade certification until fixed.
Tools: Privacy Policy Generator · How to write a privacy policy · Business FAQ
Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.