Skip to main content

Privacy Policy - How to Read One in Minutes

About 2 min read

A privacy policy is a document that states how a business collects, uses, and stores users' personal information and to whom it is provided. It is "that long text" you are asked to accept when signing up or launching an app for the first time, but it is actually the only official clue that lets you know in advance where your personally identifiable information will flow. You do not need to read it in full: if you focus on the right sections, you can roughly judge a service's stance in a few minutes. This glossary page explains its legal standing and the knack of reading one.

Legal Standing

Japan's Act on the Protection of Personal Information does not mandate a document called a "privacy policy" as such, but it does require businesses to publish the purposes of use of personal information in advance, or to promptly notify or publish them after collection, and most businesses publish a privacy policy as the vehicle for this. Elsewhere, the EU's GDPR (in effect since May 2018) requires concise and transparent explanations of collection, processing, storage, and transfer, and California's CalOPPA, enacted in 2003, requires commercial sites that collect state residents' personal information to conspicuously post a privacy policy. In short, the major jurisdictions share an institutionalized duty to explain what is collected and how.

The Five Sections Worth Checking

What to checkWhy it matters
1. Scope of data collectedWhether items disproportionate to the service's function (location, contacts, etc.) are included
2. Purposes of useWhether advertising and marketing uses are included beyond providing the service
3. Third-party sharingWho receives the data, and whether recipients are described broadly, such as "advertising partners"
4. Retention and deletionWhether data remains after account closure and whether a deletion request contact is stated
5. Contact and business identityWhether the operator's identity can be confirmed; a policy with no contact point deserves low trust

Living with the "Nobody Reads It" Problem

The fact that privacy policies go unread is a structural problem, not weak willpower. A 2008 study by McDonald and Cranor at Carnegie Mellon University estimated the average privacy policy at about 2,500 words, taking roughly 10 minutes to read, and concluded that being hard to read, they are read infrequently. Reading every policy in full for every service you use is unrealistic. The practical compromise has three parts: (1) concentrate your reading time on services you entrust with a lot of personal data (finance, healthcare, dating, and the like), (2) for everything else, skim only the five points above, and (3) always check whether extra checkboxes on the consent screen (newsletter opt-ins, data-sharing opt-ins) are already ticked. Screen designs that rush consent or make refusal hard are called dark patterns, and they are themselves a signal for gauging a business's attitude.

There are also defenses available after you consent. See the privacy settings guide article for concrete steps to narrow collection through social media and phone settings, and the article on privacy versus convenience for a realistic way to balance the two.

Common Misconceptions

The biggest misconception is "having a privacy policy means my personal data is protected." A privacy policy is essentially a declaration of what is collected and what it is used for, and depending on its content it may openly declare broad collection and third-party sharing. Judge by the content, not the existence. "Reading is pointless because I cannot use the service without consenting" is also wrong. Even without the freedom to refuse, you retain room to act: narrowing collection through settings, choosing an alternative service, and minimizing the information you enter. Reading is information gathering not just for deciding whether to consent, but for deciding how to use the service.

Real-World Use Cases

"When I had narrowed my choice of budgeting apps down to two, the tiebreaker was the privacy policy. One said nothing in its third-party section beyond 'partnered advertising providers,' while the other concretely listed the categories of recipients and purposes, and even spelled out the data deletion steps upon account closure. The features were almost identical, so I chose the latter. It was a five-minute skim, but for picking a service I would trust with my bank account details, it was the cheapest insurance I could buy."

Frequently Asked Questions

What is a privacy policy?
It is a document stating how a business collects, uses, and stores users' personal information and to whom it is provided. Japan's personal data protection law requires businesses to publish or notify the purposes of use, and most publish a privacy policy as the vehicle for this. Similar explanation duties are institutionalized in major jurisdictions abroad, such as the EU's GDPR and California's CalOPPA.
Do I need to read a privacy policy in full?
Realistically, no. A 2008 Carnegie Mellon study estimated an average of about 2,500 words and roughly 10 minutes to read, so reading every policy in full is unrealistic. Concentrate full reads on services you entrust with a lot of personal data (finance, healthcare, dating, and so on), and for the rest skim five points: data collected, purposes of use, third-party sharing, retention and deletion procedures, and the contact point.
Which parts of a privacy policy reveal a risky service?
There are four red flags: (1) collection items disproportionate to the service's function (a single-purpose app demanding location or contacts), (2) vague, broad third-party recipients such as "advertising partners," (3) no mention of retention periods or deletion procedures, and (4) no verifiable contact point or business identity. In addition, consent screens with data-sharing checkboxes pre-ticked (dark patterns) are another sign of a business's attitude.

Related Terms

Was this article helpful?