The Difference between Privacy Notice & Privacy Policy

Patrick Oh
DataFrens.sg
Published in
2 min readJul 21, 2022

If you visit organisation’s website, you will quickly know whether they truly understand about Privacy Protection by simply looking at what they labelled as their Privacy Notice. You will find that more than 90% of organisations will use Privacy Policy on their website which is WRONG!

Privacy Notice is for the PUBLIC and Privacy Policy is for Internal Use.

Privacy Notice seeks to inform the PUBLIC how the organisation handles the collect, store, use & disclose, transfer and dispose of their data.

Privacy Policy set the rules and regulation the staff needs to observe with regards to the obligations listed in the PDPA.

The outline of the various Obligations required by the Privacy Regulation will be similar, but Privacy Notice is about informing the Public the organisation’s Data flow cycle and how it comply with the Privacy Regulation. However, the Privacy Policy which is an Internal document for the staff will set the Rules and Regulation for the staff to follow.

You will be shocked that Law Firms, Privacy consultants, MNCs, etc. are making this mistakes and calling their Privacy Notice as a Privacy Policy. This simply shows they do not understand what is a Notice and what is a Policy.

So how to draft out a Privacy Policy for your staff?

  1. Keep it short and simple to understand. Don’t write it like a legal document which your staff might not even understand. Most legal documents are written to confuse the other party while protecting self.
  2. Have the Obligations listed accordingly, preferable with regards to the Data Flow Process (Collection — Storage — Use & Disclosure- Transfer- Disposal) so that it is easier for the staff to follow sequentially.
  3. Use Action verbs because Privacy Policy is for staff to take action and not notifying them. When it is short and simple to understand, it will be easy for the staff to quickly read and take action.

Take NOTE!

Organisation’s Policy is not to impress but to implement!

A Message from DataFrens…

Thanks for being a part of our community!

Do join us here at:

Read all our DataFrens articles here at:

--

--

Patrick Oh
DataFrens.sg

Patrick is Singapore Certified Mgmt Consultant providing PDPA consultancy, Performance mgmt and Solutions Design and Community Development.