The Legal Housekeeping Most Sites Skip
Last updated:
Know what you collect
- Form submissions, stored in the database and emailed
- Analytics, which may or may not be personal data depending on configuration
- Any tracking pixels from advertising platforms
- Chat conversations, if you have chat
- Comments, if enabled
Most businesses can name two of those five. The audit takes an hour and it is the foundation of everything else.
The privacy notice
What you collect, why, how long you keep it, who you share it with, and how someone exercises their rights. Written plainly, not copied from a generator.
A generated notice that describes practices you do not follow is worse than a short accurate one.
Consent, where required
- Necessary cookies do not need consent; tracking generally does
- Consent must be a genuine choice, not a wall with one button
- Record what was consented to and when
- Make withdrawing consent as easy as giving it
Be able to find and delete
If someone asks what you hold about them, you need to search form submissions, comments, chat logs, analytics and any CRM. Most businesses have never tried.
Do it once as an exercise. It takes an afternoon and it turns a future deadline into a routine task.
Retention
| Data | Reasonable retention |
|---|---|
| Form submissions | As long as the enquiry is live, then delete |
| Chat conversations | 30–90 days |
| Analytics | As configured, typically 14–26 months |
| Comments | Indefinitely, if published |
Indefinite retention of form submissions is the most common quiet failure, because nobody ever decided anything.
Frequently asked questions
Do we really need a cookie banner?
Can we use a privacy policy generator?
Who is responsible for this?
What if we get a data request?
Not sure what your site collects?
An hour answers it. Happy to help you audit and write something accurate.