Use this checklist before publishing or certifying your privacy policy. Clerica scores disclosure clarity on verify pages — not legal adequacy — but strong items correlate with higher rubric scores and customer trust.
Checklist
- [ ] Controller legal name and contact published
- [ ] EU/UK representative appointed if required (Art. 27)
- [ ] DPO contact listed if DPO appointed
- [ ] Purposes listed for each processing activity
- [ ] Legal basis identified per activity (Art. 6)
- [ ] Legitimate interest assessment documented where used
- [ ] Categories of personal data described specifically
- [ ] Special category data addressed if processed (Art. 9)
- [ ] Recipients/subprocessors named or categorized
- [ ] International transfer mechanism stated (SCCs, adequacy)
- [ ] Retention periods or criteria per category
- [ ] Data subject rights listed with exercise instructions
- [ ] Supervisory authority complaint right mentioned
- [ ] Automated decision-making/profiling disclosed if used
- [ ] Source of data stated for indirect collection (Art. 14)
- [ ] Cookie/analytics practices align with policy text
- [ ] Children's data addressed if under-16 processing
- [ ] Policy linked in footer and at collection points
- [ ] Last updated date visible
- [ ] Material changes communicated to users when required
How Clerica uses this
Certification rubric rewards specificity, readable structure, and substantive coverage. Consumer-Friendly badge requires score ≥ 75 on active Certified subscription.
After publish
Material policy changes without updates may trigger integrity scan drift — downgrade certification until fixed.
Tools: Privacy Policy Generator · How to write a privacy policy · Business FAQ
Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.