Why your website needs a privacy policy - Zephyra Studio
If a site has a contact form, Google Analytics, or anything else that records information about a visitor, it is processing personal data, and that means it needs a privacy policy. This is not a formality copied from another site, it is a specific page stating what gets collected, why, and for how long.
When the law requires one
Serbia's data protection law (aligned with the GDPR) applies to anyone processing personal data, not just large companies. A name and e-mail from a contact form, an IP address logged by analytics, even a cookie that remembers a return visit, all of these are personal data.
The line is not "do I collect data for marketing", it is "does the site record anything tied to a specific visitor, anywhere". Very few sites with a form or analytics fall under that line.
What it actually needs to say
A privacy policy is not one paragraph at the bottom of an about page. It should be its own page, linked from the footer, that clearly answers a few questions.
- What data is collected (name, email, phone, payment details, cookies, IP address)
- Why it is collected, the actual purpose, not a vague "for business operations"
- How long it is kept before deletion
- Whether it is shared with third parties (hosting, e-mail provider, analytics, payments), and which ones
- How a visitor can request access, correction, or deletion of their data
- Who to contact with privacy questions
The most common mistake
The most common problem is not a missing privacy policy, it is a generic one copied from another site that mentions tools the site does not actually use. That is worse than it sounds: if an inspector or a visitor notices the text describing, say, a Facebook Pixel the site does not have, the whole page loses credibility, and the actual legal requirement still is not met.
Source
Key takeaways
- A privacy policy is required as soon as a site collects any data tied to a specific visitor, not only for online stores.
- It has to state specifically what data, why, for how long, and who it is shared with, not a vague statement.
- A copied policy that mentions tools you do not use is worse than a short but accurate one.
Conclusion
If you are not sure whether your site has a privacy policy, or you have one but suspect it does not accurately describe what the site actually does, that is something we check and fix as part of regular website development and maintenance.
Frequently asked questions
If a site has a contact form, Google Analytics, or anything else that records information about a visitor, it is processing personal data, and that means it needs a privacy policy. This is not a formality copied from another site, it is a specific page stating what gets collected, why, and for how long.