Chapter 4: Information Management and Privacy Risk Management

Privacy Policy vs Privacy Notice: The Difference for CIPP/US

A privacy policy is the internal document that tells employees and contractors how personal information must be handled. A privacy notice is the external statement given to consumers describing what the organisation collects and does. In everyday U.S. usage the consumer-facing document is often labelled a policy, but the exam keeps the two roles distinct.

Practical example

A retailer posts a document on its website that describes the data it collects and the choices customers have. That is a notice, whatever its heading. The internal standard telling staff how long to keep the data is the policy. If the website statement promises something the internal practice does not deliver, the FTC can treat the gap as a deceptive practice under Section 5.

Common mistake

Answering from the document's label instead of its audience. Exam questions describe who reads the document and what it does; that determines whether it is a policy or a notice.

Notices carry legal weight because regulators hold organisations to what they say. Under FTC Act Section 5, a statement in a notice that does not match practice can be deceptive, and under state laws such as the CCPA the notice at collection must contain specific elements. Policies carry operational weight: they are the evidence of a privacy program, referenced in audits, contracts and training.

For CIPP/US study, expect questions that give a fact pattern and ask what kind of document it describes, which regulator would care about a mismatch, or what a notice must contain under a named statute.

How this supports CIPP/US study

Use this lesson to connect a privacy programme decision with the relevant regulator, duty or enforcement route. Continue with the CIPP/US exam questions.

Policy vs notice
AspectPrivacy policyPrivacy notice
DirectionInternalExternal
AudienceEmployees and contractorsCustomers, potential customers, users, and (sometimes) employees
PurposeImplement privacy goals/vision; guide PI handlingProvide transparency; treated as a promise to consumers

Both describe how PI is collected, used, shared, and stored. If a U.S. organization violates a promise made in a policy that is also communicated in the notice, the FTC or a state attorney general may bring an enforcement action for a deceptive practice.

Key terms - quick answers

What is “Privacy policy”?
High-level internal document implementing privacy goals and informing employees/contractors how PI must be handled.
What is “Privacy notice”?
External statement providing transparency to consumers about an organization's privacy practices; treated as a promise.

Sources and study method

This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.