Use this checklist before publishing or certifying your privacy policy. Clerica scores disclosure clarity on verify pages — not legal adequacy — but strong items correlate with higher rubric scores and customer trust.
Checklist
- Controller legal name and contact published
- EU/UK representative appointed if required (Art. 27)
- DPO contact listed if DPO appointed
- Purposes listed for each processing activity
- Legal basis identified per activity (Art. 6)
- Legitimate interest assessment documented where used
- Categories of personal data described specifically
- Special category data addressed if processed (Art. 9)
- Recipients/subprocessors named or categorized
- International transfer mechanism stated (SCCs, adequacy)
- Retention periods or criteria per category
- Data subject rights listed with exercise instructions
- Supervisory authority complaint right mentioned
- Automated decision-making/profiling disclosed if used
- Source of data stated for indirect collection (Art. 14)
- Cookie/analytics practices align with policy text
- Children's data addressed if under-16 processing
- Policy linked in footer and at collection points
- Last updated date visible
- Material changes communicated to users when required
How Clerica uses this
Certification rubric rewards specificity, readable structure, and substantive coverage. Silver Verified badge requires score ≥ 75 on active Certified subscription.
After publish
Material policy changes without updates may trigger integrity scan drift — downgrade certification until fixed.
Tools: Privacy Policy Generator · How to write a privacy policy · Business FAQ
Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.