Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Privacy Policy
"I need a privacy policy for a data privacy business that outlines data collection, storage, and sharing practices, includes user consent mechanisms, and complies with GDPR and CCPA regulations, updated annually."
What is a Privacy Policy?
A Privacy Policy tells people exactly how your business collects, uses, and protects their personal information. It's a legal requirement under Philippine data protection laws, especially the Data Privacy Act of 2012, for any organization that handles personal data.
This document explains your data practices to users - from what details you gather to how you store them safely. It covers important points like data sharing with third parties, user rights, and security measures. Companies in the Philippines must display their Privacy Policy clearly on websites and apps, making it easy for users to understand how their information is managed.
When should you use a Privacy Policy?
You need a Privacy Policy as soon as you start collecting any personal information from customers or users in the Philippines. This includes basic contact details, online tracking data, or any other information that could identify someone. For example, when launching a website, mobile app, or starting an e-commerce business, having this policy in place is essential from day one.
Under the Data Privacy Act, businesses must provide this policy before collecting data through online forms, customer surveys, or membership registrations. It's particularly crucial when handling sensitive information like financial details or health records. Getting your Privacy Policy ready early helps avoid legal issues and builds trust with your users.
What are the different types of Privacy Policy?
- Privacy Policy Agreement: The most comprehensive type, covering all aspects of data handling and user rights - ideal for businesses with extensive data collection
- Cookie Consent Policy: Specifically focuses on website tracking technologies and online data collection methods
- CCTV Privacy Notice: Specialized policy for physical surveillance systems in buildings or facilities
- Privacy Agreement: A simplified version for small businesses or specific data processing activities
- GDPR Notice: Enhanced policy for Philippine companies dealing with European customers or data
Who should typically use a Privacy Policy?
- Business Owners & Companies: Responsible for creating and implementing Privacy Policies, especially those collecting customer data online or in physical stores
- Data Protection Officers (DPOs): Required by Philippine law to oversee privacy compliance and maintain these policies in organizations
- Website Operators: Must display Privacy Policies and ensure proper data collection practices on their platforms
- Users & Customers: Protected by these policies when sharing personal information with businesses
- Legal Professionals: Draft and review policies to ensure compliance with the Data Privacy Act and other regulations
How do you write a Privacy Policy?
- Data Collection Audit: List all personal information your organization collects, including online forms, cookies, and physical records
- Purpose Mapping: Document why you collect each type of data and how you use it
- Security Measures: Detail your data protection methods, storage systems, and access controls
- Third-Party Sharing: Identify all external partners who receive or process your collected data
- User Rights: Outline how individuals can access, correct, or delete their personal information
- Template Customization: Use our platform to generate a compliant Privacy Policy that includes all these elements according to Philippine law
What should be included in a Privacy Policy?
- Company Identity: Full business name, contact details, and Data Protection Officer information
- Data Collection Scope: Clear list of personal information types being gathered and processing methods
- Legal Basis: Specific grounds under the Data Privacy Act for collecting and processing data
- Data Usage Statement: Detailed explanation of how collected information will be used and stored
- Security Measures: Description of safeguards protecting personal information
- User Rights Section: Process for accessing, correcting, or deleting personal data
- Third-Party Sharing: Details about data transfers to other organizations or countries
What's the difference between a Privacy Policy and a Cookies Policy?
A Privacy Policy and a Cookies Policy are often confused, but they serve different purposes under Philippine data protection laws. While both deal with user data, their scope and focus differ significantly.
- Scope of Coverage: A Privacy Policy covers all aspects of personal data handling, from collection to disposal. A Cookies Policy specifically addresses website tracking technologies and browser-based data collection
- Legal Requirements: The Data Privacy Act mandates a comprehensive Privacy Policy for all organizations handling personal data. A Cookies Policy is mainly needed for websites using tracking technologies
- Content Focus: Privacy Policies detail all data processing activities, user rights, and security measures. Cookies Policies explain technical tracking methods, types of cookies used, and how to control them
- Implementation Timing: Privacy Policies must exist before any data collection begins. Cookies Policies are needed specifically when launching websites or online services
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it