LegalDoc
4 stepsfrom ₦5,000Policy Pro

How to Write a Privacy Policy

A privacy policy tells people what personal data you collect, why, and what they can do about it. Here is how to answer the form honestly, question by question.

Create a Privacy PolicyWord and PDF, ready in minutes
Preview of the Privacy Policy template

What a privacy policy is

A privacy policy is the public statement of what you do with people's personal information.

It says what you collect, why you collect it, who you share it with, how long you keep it, and what rights the person has over it.

Personal data is broader than most people assume. A name and an email are obvious. So are a phone number, a delivery address, an IP address, and the analytics identifier that follows somebody around your site.

The policy is not a formality bolted on at launch. It is the document a regulator asks for first, and the one a cautious customer reads before handing over their details.

Who needs one

Every website or app that collects anything about the people who use it, which in practice is all of them.

A contact form collects data. A newsletter signup collects data. Analytics collects data. An order collects a great deal of it.

In Nigeria the Nigeria Data Protection Act 2023 governs how personal data is handled, with the Nigeria Data Protection Commission as regulator. Businesses handling data at scale carry registration and reporting duties on top of publishing a policy.

If you have customers in Europe or the United Kingdom, GDPR reaches you regardless of where you are based. The same is true of California residents and the CCPA.

Before you start

Make an honest list of what you actually collect before you open the form.

Walk your own site as a visitor. Note every form, every signup, every checkout field.

Then list the tools that collect on your behalf: analytics, advertising pixels, chat widgets, email platforms, payment processors.

Those third parties belong in the policy too, because you are sharing data with them.

A policy that describes a business you do not run is worse than none, since it misleads the person reading it.

The walkthrough

Filling in the form, step by step

Every question you will be asked, what it means, and an example of a good answer.

1

Website or app

This first answer sets who the policy speaks to and which collection methods it describes.

A website policy covers browsing, forms, cookies and server logs. An app policy covers device level collection, which is a wider net: device identifiers, operating system, crash diagnostics, and any permission the app requests such as camera, location or contacts.

App store reviewers compare the permissions your app requests against what your policy discloses. A mismatch there is a common reason for rejection, so answer for the surface you are actually publishing.

Privacy Policy for?
Choose Website for a browser based site, including a store or blog. Choose App for a mobile application, where the policy must also account for device identifiers and any permissions the app requests. If you run both, publish a policy for each rather than stretching one to cover both.
2

Where the policy applies, and under whose law

The URL scopes the policy and the country sets the legal frame.

Scope matters more than people expect. A policy covers the property it names. If you run several sites or a separate app, each needs its own policy or an explicit statement that one document covers them all.

The country determines the baseline regime. For a Nigerian business that is the Nigeria Data Protection Act 2023. That baseline does not displace foreign law: if you serve customers in Europe or California, their rules apply to their residents on top of your own.

What is your website URL?
The site this policy governs, for example www.yourbusiness.com. Name the exact property. Running one policy across several domains without saying so leaves it unclear which site the visitor is reading about.
Enter the Country
Where your business operates from, which sets the primary data protection regime. Enter Nigeria for a Nigerian business. Serving customers elsewhere does not change this answer; it adds obligations, handled in the questions further down.
3

Who is responsible for the data

Data protection law works through accountability, and accountability needs a name attached.

The entity you give here is the data controller: the one that decides what is collected and why. It is the name a regulator writes to and the name a customer complains about.

An address is not decoration either. People exercising their rights, and regulators making enquiries, need somewhere to send correspondence. A policy naming no contactable entity fails at the first question anybody asks of it.

Pick One
Choose I am a Business or Startup where a registered business name or company operates the site. Choose I am an Individual if you run it personally. Individuals still have obligations under data protection law, so this answer changes the wording rather than removing the duties.
Name of Business/ Startup
The registered name of the entity that decides how personal data is used, for example Lumen Digital Limited. This is the data controller, and it should be the same entity named in your terms and on your invoices.
Address of Business
A postal address where the business can be reached about data matters, with street, city and state. Regulators and individuals exercising their rights write here, so it needs to be real.
4

What you collect and which rules you follow

This is the substance. The first answer builds the inventory, and the compliance questions decide which rights sections appear.

Be complete about what you collect. Understating it is the failure that causes trouble, because the policy is measured against what your site actually does, not against what you meant to write.

On the compliance questions, answer by reference to who your users are rather than where you are. GDPR follows European and UK residents wherever your servers sit. CCPA follows California residents. The Data Protection Act 2018 in the form is the United Kingdom statute that sits alongside UK GDPR.

One gap worth knowing: the form does not yet offer a Nigeria Data Protection Act 2023 option. A Nigerian business should still comply with the NDPA, and where the form permits free text you can name it. Turning on GDPR wording produces a policy close to what the NDPA expects, since the two regimes share their structure of lawful basis, individual rights and breach reporting.

What type of personal information do you collect from users?
Tick everything you actually receive, including data collected by tools rather than typed into a form. Walk your own signup and checkout before answering. Under-declaring here is the most common defect in a published policy, because the site is judged against what it does.
Can visitors/ users buy goods (physical, digital)?
Answer Yes if anything is sold through the site. Purchases bring in billing and delivery details, payment processor sharing, and the records you must keep for tax, all of which the policy then explains.
Can visitors/users create accounts?
Say Yes where visitors can register and sign in. Accounts mean stored credentials, profile details and activity history, and they raise a retention question the policy must answer: what becomes of that data when somebody deletes their account.
How can visitors/users contact you as regards your privacy policy
Tick the channels you will monitor. This is the route people use to ask what you hold about them or to request deletion, and data protection law expects those requests to be answered within set periods. An unmonitored channel here creates a compliance problem, not just a service one.
Phone No.
A number reaching somebody who can handle a data question, if you ticked phone. Include the country code where you serve customers abroad, for example +234 801 234 5678.
Email
The address for privacy enquiries, if you ticked email. A dedicated address such as privacy@yourbusiness.com is worth setting up, because these requests carry deadlines and should not sit in a general inbox.
Link
A contact or privacy request page, if you ticked that option, for example www.yourbusiness.com/contact. Make sure the form behind it reaches somebody who knows what a data request is.
Do you want your privacy policy to comply with CCPA
Answer Yes if you have users in California. The CCPA gives them rights to know what is collected, to request deletion, and to opt out of the sale of personal information, and the policy adds a section covering those.
Do you want your privacy policy to comply with GDPR
Answer Yes if you have users in the European Union or the United Kingdom. GDPR applies by reference to where the person is, not where you are. It adds lawful basis, individual rights, retention and breach notification wording, which also aligns closely with what Nigerian law expects.
Do you want your privacy policy to comply with Data Protection Act 2018
This is the United Kingdom statute that operates alongside UK GDPR. Answer Yes if you have UK users. It is separate from the Nigeria Data Protection Act 2023, which applies to Nigerian businesses regardless of how you answer here.

Ready to make yours?

Answer those questions in the builder and download a finished privacy policy in Word and PDF.

Start now, ₦5,000

After you download it

1

Publish it before you collect anything

Link it in the footer and beside every form that gathers details. A policy published after data collection began does not cover what you already took.

2

Make the rights requests work

Somebody has to answer when a person asks what you hold or asks you to delete it. Decide who that is before a request arrives, because the response times are short.

3

Check your Nigerian obligations

The Nigeria Data Protection Act 2023 goes beyond publishing a page. Businesses processing personal data at scale carry registration and reporting duties with the Nigeria Data Protection Commission, so check whether yours does.

4

Update it when you add a tool

Every new analytics platform, pixel or chat widget collects something. Adding one without updating the policy is how a policy quietly stops describing the site.

Questions people ask

What is a privacy policy for a website?

The public statement of what personal information the site collects, why, who it is shared with, how long it is kept, and what rights the person has over it.

Does my Nigerian website need a privacy policy?

Yes. The Nigeria Data Protection Act 2023 governs how personal data is handled, and any site with a contact form, newsletter, analytics or checkout is collecting personal data.

Do I need GDPR wording if I am based in Nigeria?

If you have users in the European Union or United Kingdom, yes. GDPR applies by reference to where the individual is, not where your business or servers are.

What counts as personal information?

More than a name and email. Phone numbers, delivery addresses, IP addresses, device identifiers and analytics identifiers all count, including data collected by third party tools on your behalf.

Where should the privacy policy link go?

In the footer, and next to every form that collects details, including signup and checkout. A policy people were never shown is difficult to rely on.

What happens if I do not have one?

You risk regulatory attention, and practical problems too: payment processors and app stores commonly require a policy, and cautious customers check for one before entering their details.

Documents that go with this

Terms used on this page

Read more on this

Step by step guides for every document on LegalDoc

Browse all guides
How to Write a Privacy Policy for a Website — LegalDoc