Because of the fact that I'm building my own CMS to encase my new project, I feel the need to write my own privacy policy to explain to my user's how their information is handled on the website. What should I include in the policy? What do you suggest? Thanks! :great:
You should include:
- A glossary for any advanced terminology (so those unfamiliar with terms will be able to easily understand.)
- What data is stored.
- How it's stored (mentioning if you use encryption and what level of encryption might be a good idea. )
- Who has access (like what level of admins/staff)
- Why they have access.
- What this information is used for.
- Under what situations information will be shared (legal proceedings, investigations, etc...)
- A note about limited liability (anything entered into the system is done so knowing that administrators can see this information and that while all reasonable measures to ensure data safety and security will be taken, this information could still end up being shared with others.)
- A note about consent. (That by using this system they give their consent for data to be collected and stored as outlined earlier.)
I can't think of anything else beyond that off the top of my head.
You may still want to type one out yourself to keep the formatting uniform with the rest of your site, but there are a lot of "privacy policy generators" out there that you can use to get the information, terminology, etc. from.