No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

5 Ways Your Company’s Privacy Policy Could Be Insufficient

How to Rework the Policy for Maximum Effectiveness

by Brian Kint
June 24, 2019
in Data Privacy, Featured
concept of weakness - illustration of businessman shooting arrow at an Achilles heel

Ill-crafted privacy policies can put a company and its customers’ data at significant risk. Cozen O’Connor’s Brian Kint examines five of the most common ways an organization’s policy could be lacking and provides solutions for how to remedy those issues.

Well-thought-out internal privacy policies and procedures are an essential part of any company’s information management program. These internal policies should not be confused with a company’s external privacy notice, which informs the company’s customers as to how it may process, store and share their personal data. Rather, the company’s internal privacy policy sets forth company goals with respect to protected data and defines company procedures to ensure that those goals are met. Here are five of the top ways privacy policies are deficient.

1. It Isn’t Properly Documented

It goes without saying that a company’s privacy policies and procedures themselves should be written down and stored in an accessible location, but all of the underlying information giving rise to those policies and procedures should be thoroughly documented as well. This documentation should include a comprehensive description of the company’s systems, data and data flows. Documenting this information along with the privacy policy will make it easier to identify when the circumstances underlying the policy have changed so that the policy is in need of an update (see #2 below). It will also ease any transition when new employees become responsible for the company’s information management program. Spending extra time up front to thoroughly inventory, understand and document company data will pay dividends down the road.

2. It Hasn’t Been Appropriately Updated

Businesses change over time. A company may enter a new line of business in which it gathers a new category of customer data. Or a company’s use of personal information may shift between aggressive and conservative over time. For example, a company may see an opportunity to position itself as a privacy leader in its industry, or it may have to tighten up its data protection practices to minimize reputational harm after a data breach. Such internal changes warrant a re-examination of the company’s privacy policy.

External changes happen as well. New laws and regulations in the field of data privacy are a seemingly daily occurrence. Businesses must account for these changes by appropriately revising their privacy policies. Moreover, even if a business periodically updates its privacy policy when a new law or regulation is passed, it must occasionally look at its privacy policy more holistically to ensure it is in accordance with the company’s goals and the regulatory scheme as a whole.

3. One Blanket Policy Applies to All Categories of Data

Given the alphabet soup of laws that apply to privacy and data protection, a blanket privacy policy is often insufficient. Privacy laws differ in their definitions of what constitutes protected information. For example, a company may hold personally identifiable information under a state privacy law and also hold protected health information under HIPAA. These different categories of data may require separate privacy policies. Similarly, laws such as the GDPR categorize personal data separately from sensitive personal data with different grounds for processing each. Therefore, privacy policies must separately account for and deal with all of the categories of data that a company processes and place appropriate procedures and safeguards around each.

4. It Does Not Appropriately Limit Defined User Roles

Even where a privacy policy properly accounts for all categories of data within an organization, it still must ensure that only appropriate users and systems have access to that data. Any privacy policy must therefore establish appropriate access barriers across departments and lines of business. For example, while it may be appropriate to give a certain category of employee (e.g., managers) high-level access to company data within their department, it may not be appropriate to give that category of employee high-level access to company data across the organization. The privacy policy must account for this by ensuring that employees only have the access to company data necessary to carry out their job functions. While this adds a layer of complexity to the administration of user accounts and access rights, it is necessary to ensure that only those with a need to know have access to sensitive data.

5. It Hasn’t Been Adequately Communicated to the Workforce

Even the best-conceived and most comprehensive privacy policy won’t do much good if it isn’t communicated throughout the organization. Moreover, simply posting the company’s privacy policy on the company intranet or including it in an employee handbook may be insufficient. Appropriate employees need training on the policy with refresher training as policies evolve. Client or customer-facing employees in particular warrant special attention, as they have to be able to externally communicate the contours of the company’s privacy policies and procedures. Regular internal communication about the company privacy policy also ensures that privacy is at the forefront of employees’ minds, rather than just an afterthought.

Developing a comprehensive internal company privacy policy and implementing procedures to put that policy into action is certainly not an easy task; it requires input from multiple stakeholders and buy-in from all levels of the corporate structure. Moreover, once a privacy policy is in place, it must be viewed as a living document that is regularly reviewed, analyzed and updated. Nevertheless, having a complete and updated policy in place is essential to protect your company and your customers’ data.

Tags: GDPR
Previous Post

Combating Regulation by Enforcement: A Strategic Framework for Responding to State Agency Overreach

Next Post

3 Potential Risks When Working with Third-Party Vendors

Brian Kint

Brian Kint

Brian Kint is a Philadelphia-based member of the Data Privacy & Security Practice at Cozen O’Connor. Brian’s mix of legal knowledge and IT experience make him uniquely situated to advise clients on constantly changing data privacy and cybersecurity issues. Both an attorney and a certified information privacy professional (CIPP/US), he can speak the language of the law as well as the language of the IT professionals responsible for developing and implementing technology solutions to adhere to the law and to the organization’s data security strategy. He can be reached at bkint@cozen.com.

Related Posts

us flags on wall street

A Field Guide to Privacy Law for Companies Entering the US Market

by Kevin Coy and Erin Doyle
July 20, 2026

Businesses wanting to operate in the US have a variety of laws and regulations to consider

data privacy concept human figure padlock

Data Privacy Rules Built for Human Behavior Have an AI Agent Problem

by Srikanth Sallaka
June 8, 2026

Regulators are beginning to treat under-governed AI deployments as intentional conduct

internet of things and cloud devices

EU Data Act: Time for a Reality Check

by Zach Judge-Raza and Jamie Elbert
March 17, 2026

New rules could spark compliance tension: share too much personal data run afoul of GDPR, share too little and face...

small child using smartphone

The US Is Not Alone in Regulating Children’s Data Privacy. Here’s a Primer on the Global State of Play.

by Ceren Canal Aruoba
February 2, 2026

Emerging policies extend beyond data privacy into product governance and algorithmic accountability

Next Post
leaking pipe

3 Potential Risks When Working with Third-Party Vendors

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights