Skip to content

Trust, Risk, and Regulated Communication

Privacy Notice Content Intake

Collect accurate processing facts, purposes, data flows, recipients, retention, choices, rights routes, security contacts, and responsible owners.

Free editable Markdown · Privacy teams, product managers, and legal operations teams ·

Download Markdown

Accessible HTML preview

Blank template

The downloaded file contains the same fields in editable Markdown.

Scope and ownership

Product/service and version
[Exact scope]
Markets and audiences
[Regions and user types]
Controller/responsible entity
[For qualified review]
Product owner
[Name/team]
Engineering/data owner
[Name/team]
Security contact
[Role/channel]
Privacy/legal reviewer
[Role]
Current notice and date
[URL; YYYY-MM-DD]
Change triggering intake
[Feature, vendor, field, purpose, market]

Processing record

Data category
[User-recognizable description]
Specific fields/examples
[No live personal data]
Source and collection point
[User, device, vendor, derived]
Required or optional
[Product consequence]
Purpose
[Specific activity]
System and owner
[Where processed]
Recipients/vendors
[Role and service]
Transfer/location
[For qualified review]
Choice/control
[Setting, consent, opt-out, other]
Retention/deletion
[Period, trigger, method, exceptions]

Review checks

  • Inventory covers submitted, observed, derived, and third-party data.
  • Technical labels are translated into understandable categories.
  • Purposes are specific to real processing.
  • Vendors, recipients, locations, and transfers are complete.
  • Product choices and consequences were tested.
  • Retention includes trigger, deletion process, and exceptions.
  • Rights and contact routes work in the live experience.
  • Qualified reviewers own legal conclusions and final notice wording.

How to use this template

  1. Define the product, audience, markets, versions, systems, and responsible owners in scope.
  2. Inventory data categories with source, collection point, requirement, sensitivity, and user expectation.
  3. Map purposes, systems, recipients, vendors, disclosures, transfers, and choices.
  4. Document retention, deletion, rights-request routes, contacts, and update triggers.
  5. Validate against the live product and qualified reviews before drafting or changing any notice.

Describe data in user-recognizable terms

Inventory information people provide, data generated through use, device and network information, inferred or derived data, support records, payment information, cookies or similar technologies, uploaded content, and data received from others. Connect technical fields to a description a person can understand without hiding sensitive categories inside “usage data.” Identify source, collection point, whether the field is required, and what happens if it is not provided. Record data about non-users and children explicitly where relevant.

Trace each purpose and flow

For every data category, record the specific operational purpose, system, responsible team, location, recipient, processor, disclosure, and transfer. Avoid vague purposes such as “improve services” without describing the activity. Distinguish service delivery, security, analytics, personalization, communication, advertising, legal compliance, and research. Capture automated decisions or profiling and the product choices a person can use. Qualified privacy reviewers should determine legal basis and jurisdictional language, not a content writer guessing from a template.

Make lifecycle and contact routes real

Document default retention, event that starts the period, deletion or anonymization process, backups, exceptions, and owner. Verify access, correction, deletion, objection, opt-out, appeal, and complaint routes as applicable, including authentication and expected response handling. Link to current security and incident contacts without promising “complete security.” Assign notice-update triggers for new vendors, features, fields, purposes, markets, or policy decisions and test that published links work.

See the fields in context

Fictional example: recipe-board collaboration

Pantry Pin is an invented service. The data flow below is illustrative and not a privacy notice.

  • Data: Fictional account email, board title, invited collaborator email, and service-generated access logs.
  • Purpose: Deliver account access, send the requested invitation, and investigate security events; each is recorded separately.
  • Vendor: An invented email provider processes invitation delivery under review, not vaguely listed as “partners.”
  • Retention question: Product owner must define what happens to pending invitations after expiration and deletion.
  • Publication gate: Privacy and legal reviewers confirm terminology, applicable rights, transfers, and live controls before drafting.

Frequently asked questions

Is this template a privacy notice?

No. It gathers operational facts for qualified teams to assess and draft the appropriate notice for applicable products and jurisdictions.

Who should complete the intake?

Use people who own the live processing: product, engineering, data, security, support, marketing, vendors, and privacy or legal reviewers.

Can the notice say data is never stored?

Only if qualified owners verify that statement across logs, backups, vendors, support, and every in-scope system. Avoid absolute claims without complete evidence.

When should the intake be reopened?

After material changes to data, purpose, vendor, recipient, location, retention, choice, audience, market, or applicable requirements.

File details

File name
privacy-notice-content-intake.md
Format
Markdown (.md)
Size
3 KB
Designed for
Privacy teams, product managers, and legal operations teams

Usage note: Use this intake to gather operational facts for qualified privacy and legal review; do not publish it as a privacy notice or treat it as legal advice. Complete it with product, engineering, security, support, marketing, vendor, and data owners who know the live system. Verify deployed behavior and contracts. Do not paste secrets, credentials, or unnecessary personal data into the worksheet.