A website privacy policy India businesses put up at launch is usually written once and never opened again. Almost every business website has one. Most were written once, often copied from a generator, and have not been read since. In the meantime the site added a chat widget, changed analytics, started taking payments and installed three plugins that set cookies.
A website privacy policy in India, like anywhere else, is only useful if it describes what the site actually does. This is a maintenance job, not a legal one, and it is the maintenance part this covers.
This is not legal advice. What follows is a practical review routine. For your specific obligations, take proper advice.
Why it falls out of date without anyone changing it
Because the site changes and the policy does not. Each of these adds data collection that a policy written earlier does not mention:
- A chat widget, which usually sets cookies and may store conversations on somebody else’s servers
- A change of analytics, or adding an advertising pixel
- A booking or payment integration, which shares customer details with a third party
- An email marketing plugin that stores addresses
- Embedded video, maps or fonts loaded from another company
None of these feel like a policy change when you install them. Collectively they are exactly what the policy is supposed to describe.
What to check, twice a year
List what actually collects data. Walk the site and note every form, every embedded service, every tracking script. Your plugin list is a good starting point, and the browser developer tools will show you which external domains a page loads from.
Compare that list to the policy. Anything on the list and not in the policy is the gap. This alone is most of the review.
Check the contact route works. A policy that names an email address is useless if nobody reads that mailbox. Send a test.
Check the date. A policy with a “last updated” date from three years ago tells a visitor it has not been looked at, whatever it says inside.
Check the linked pages still exist. Policies often link to a cookie page, a terms page, or a third party’s own policy. Those links break like any other.
The parts most often missing
From reviewing ordinary small business sites, the same gaps recur. The policy does not mention the analytics actually in use, because it was written before it was installed. It does not mention the chat widget at all. It refers to services the business stopped using. And it describes a contact form that has since been replaced by a different one collecting different fields.
None of these are dramatic. All of them make the document describe a different website than the one it sits on.
Cookie banners: get the order right
If you use a cookie banner, the thing worth checking is whether it actually does anything. Many banners are installed as a badge and configured to do nothing — the tracking scripts load before anybody clicks, so the banner is decoration.
Test it yourself in a private window: refuse everything, then look at whether the tracking still loads. If it does, the banner is not doing the job it was installed for, which is worth knowing regardless of what any regulation requires of you.
A generated policy is a starting point, not a document
Most small business policies come from a generator, and that is a reasonable place to start. The problem is that a generator asks what you do today and produces text describing that. It has no way of knowing what you added afterwards, and nothing prompts you to go back.
Two things are worth doing to whatever it produced. Read it once, properly, and delete anything that does not apply to you — generated policies routinely describe practices the business has never had, which makes the whole document less credible. And check it names the actual entity: the business name people would recognise, not a placeholder left in from the template.
A short policy that accurately describes a small website is worth considerably more than a long one describing a company that does not exist.
Where this sits in maintenance
Twice a year is enough to update privacy policy wording on most sites, plus one extra rule that catches nearly everything: whenever you add a plugin or service that touches visitor data, check the policy the same week. That is when you know what changed, and it takes two minutes rather than an afternoon of reconstruction later.
It sits in the same category as the other jobs that never become urgent — our website maintenance checklist puts it in the annual section, and keeping the site current is the version where somebody flags it when a new plugin arrives rather than six months later.