Most people don’t think about a privacy policy until something prompts them — installing Google Analytics, adding a contact form, or setting up cookie consent. At that point, you realise the site has been collecting data all along, even if you never consciously set it up that way.
On almost every WordPress site I build, this comes up early. Basic analytics, plugin behaviour, and embedded third-party tools all process visitor data in some form. Without a privacy policy, your site doesn’t explain any of that, which creates a transparency problem from day one.
The good news is that writing one isn’t complicated. You don’t need a legal background — you need a structured page that accurately describes what your site does, written clearly enough for a visitor to understand.
Quick Answer
To create a privacy policy page for your website: create a new WordPress page titled “Privacy Policy”, add sections covering data collection, cookies, third-party services, and user rights, customise the content to match your actual setup, then publish and link it in your footer.
Why This Matters — the Real Penalty Structure, Not Just “Compliance Risk”
A privacy policy is not optional if your site collects any form of user data — and most sites do. Contact forms, analytics tools, commenting systems, and embedded content all fall into this category. GDPR applies to any site serving visitors in the EU regardless of where the site is hosted, and its penalty structure is more specific than “compliance risk” suggests: a two-tier system caps lower-severity violations at €10 million or 2% of global annual turnover, and serious violations — including a fundamental failure of transparency, which is exactly what operating with no privacy policy at all represents — at €20 million or 4% of global annual turnover, whichever figure is higher in each tier. Most small sites will never see anywhere near that scale of enforcement, but the structure exists specifically to scale with the size of the business being fined, not just flat per-violation amounts.
There’s also a more immediate, practical requirement that applies regardless of GDPR: advertising and analytics platforms enforce their own privacy policy rules independently of any government regulator. Google AdSense’s program policies specifically require publishers to have a privacy policy that discloses the use of cookies and third-party ad-serving technology — a site without one simply won’t pass AdSense approval, and an approved site that removes its policy risks the account itself, not just a theoretical legal exposure.
What to Include in a Privacy Policy
A privacy policy doesn’t need to be long, but it does need to be accurate. These are the sections every WordPress site should cover:
- What data you collect — names, email addresses, IP addresses, browsing behaviour, and anything submitted through forms.
- How you collect it — contact forms, analytics scripts, cookies, newsletter signups, or account registration.
- Why you collect it — to respond to enquiries, improve the site, send emails, or process orders.
- Who you share it with — third-party services like Google Analytics, payment processors, email platforms, and hosting providers.
- How long you keep it — retention periods for different types of data.
- User rights — the right to access, correct, or delete their data, and how to make a request.
- Cookie use — what cookies your site sets and why. This often links to a separate cookie policy page.
- Contact information — how visitors can reach you with privacy-related questions.
How to Create the Page in WordPress
Step 1: Create a new page
In your WordPress dashboard, go to Pages → Add New. Title the page “Privacy Policy”. WordPress may have already created a draft version when you installed it — if so, you can edit that instead of starting from scratch.
Step 2: Write the content
Work through the sections listed above, filling in the details that apply to your specific site. Be specific rather than generic — “we use Google Analytics to track page visits and user behaviour” is more useful than “we may collect certain data”. The more accurately the policy reflects your actual setup, the better it serves both legal and trust purposes.
WordPress also includes a Privacy Policy Guide under Settings → Privacy which links to documentation from plugin developers explaining what data their plugins collect. This is a useful reference when auditing what your site actually does — every plugin you’ve installed is a potential data-collection point, and it’s easy to forget one is even running by the time you’re writing the policy months later.
Step 3: Use a generator as a starting point (optional)
If you want a structured starting point rather than a blank page, a privacy policy generator can help. They ask questions about your site and output a template you then customise. GDPR.eu’s privacy notice guide is a reliable reference for understanding what a compliant notice should cover. Always review and adapt any generated output — a template that doesn’t reflect your actual data practices is worse than no policy at all, since an inaccurate policy is itself a transparency violation rather than a defence against one.
Step 4: Publish and link it in your footer
Publish the page once the content is ready. Then add a link to it in your site footer — this is the standard location visitors expect to find it. In WordPress, go to Appearance → Menus (or your theme’s footer widget area) and add the Privacy Policy page as a link.
Also go to Settings → Privacy and set this page as your official Privacy Policy page. WordPress uses this setting for certain built-in features like the default registration form.
What About Visitors Outside the EU?
GDPR gets most of the attention because of its enforcement scale, but it isn’t the only privacy law that can apply to a small site. California’s CCPA (updated and expanded by the CPRA) creates similar disclosure obligations for sites serving California residents once certain revenue or data-volume thresholds are crossed, and several other US states and countries have since passed comparable laws of their own. Most small sites won’t clear those thresholds, but the broader principle holds regardless of which specific law technically applies: describe what you actually collect and why, in plain language, and keep the page current as your tools change. A policy written to be honestly accurate tends to satisfy the substance of most of these frameworks even before you check which one technically governs a given visitor.
Practical Tips
- Update it when your setup changes. Adding a new plugin, analytics tool, or email platform is a reason to revisit the policy. An outdated policy is a liability.
- Don’t copy another site’s policy. Policies reflect specific data practices. A copied policy that doesn’t match your site is inaccurate and potentially worse than none.
- Keep the language plain. Write for a visitor, not a lawyer. Short sentences and clear explanations serve everyone better than dense legal prose.
- Link to third-party privacy policies where relevant. If you use Google Analytics, linking to Google’s privacy policy gives visitors more information about how their data is handled downstream.
Common Mistakes
- Publishing a generic template without editing it. Placeholder text left in, or sections that don’t apply to your site, undermine the policy’s credibility and accuracy.
- Not mentioning cookies. If your site uses cookies — and almost every WordPress site does — the policy needs to address this. Many sites also need a separate cookie consent banner for GDPR compliance.
- Hiding it. The footer is the expected location. Burying it in a secondary menu or leaving it unlinked means visitors can’t find it when they need it.
- Treating it as a one-time task. Your site’s data practices evolve over time. The policy needs to keep pace.
Related Legal Pages
A privacy policy is one of several legal pages most websites should have. The others are a terms and conditions page, which governs how visitors may use the site, and a cookie policy, which explains specifically what cookies are set and why. These are all part of the essential pages every website should have before launch — along with an About page, Contact page, and any other pages relevant to your site’s purpose.
For most websites, these three legal pages can be created and maintained without professional legal help. That said, professional review may be worth considering if you’re running an e-commerce store, collecting sensitive personal data, operating in heavily regulated industries, or serving audiences in multiple jurisdictions with specific legal requirements — particularly once a site is large enough that a GDPR or CCPA enforcement action, however unlikely, would represent a real financial exposure rather than a purely theoretical one.
Conclusion
Create the page, fill in the sections accurately, and link it in the footer. Once it’s in place, update it whenever your site’s setup changes — new plugins, new analytics tools, or new forms are all reasons to revisit it. If you’re building out all the essential pages for a new site, working through the essential steps to building a WordPress website gives you a clear sequence to follow from setup through to launch.

Etienne Basson works with website systems, SEO-driven site architecture, and technical implementation. He writes practical guides on building, structuring, and optimizing websites for long-term growth.