Privacy Policy vs Privacy Notice: The Difference for CIPP/US
A privacy policy is the internal document that tells employees and contractors how personal information must be handled. A privacy notice is the external statement given to consumers describing what the organisation collects and does. In everyday U.S. usage the consumer-facing document is often labelled a policy, but the exam keeps the two roles distinct.
Practical example
A retailer posts a document on its website that describes the data it collects and the choices customers have. That is a notice, whatever its heading. The internal standard telling staff how long to keep the data is the policy. If the website statement promises something the internal practice does not deliver, the FTC can treat the gap as a deceptive practice under Section 5.
Common mistake
Answering from the document's label instead of its audience. Exam questions describe who reads the document and what it does; that determines whether it is a policy or a notice.
Notices carry legal weight because regulators hold organisations to what they say. Under FTC Act Section 5, a statement in a notice that does not match practice can be deceptive, and under state laws such as the CCPA the notice at collection must contain specific elements. Policies carry operational weight: they are the evidence of a privacy program, referenced in audits, contracts and training.
For CIPP/US study, expect questions that give a fact pattern and ask what kind of document it describes, which regulator would care about a mismatch, or what a notice must contain under a named statute.
How this supports CIPP/US study
Use this lesson to connect a privacy programme decision with the relevant regulator, duty or enforcement route. Continue with the CIPP/US exam questions.
| Aspect | Privacy policy | Privacy notice |
|---|---|---|
| Direction | Internal | External |
| Audience | Employees and contractors | Customers, potential customers, users, and (sometimes) employees |
| Purpose | Implement privacy goals/vision; guide PI handling | Provide transparency; treated as a promise to consumers |
Both describe how PI is collected, used, shared, and stored. If a U.S. organization violates a promise made in a policy that is also communicated in the notice, the FTC or a state attorney general may bring an enforcement action for a deceptive practice.
Key terms - quick answers
What is “Privacy policy”?
What is “Privacy notice”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.