How to Read a Privacy Policy. What to Look For and What They Hide

These documents are written so as not to be read. Let us examine how to read them correctly.

Why a privacy policy is not a boring formality

The average privacy policy is about 4,000 words. Reading it takes 18 minutes. Studies show that fewer than 10% of users read it, even partially. Companies know this. And write it exactly so — long, legalistic, with references within the document to other documents that also no one reads. But inside these documents is everything they do with your data. Openly. Officially. Written by their own hands. You do not need to read everything. You need to know where to look.

The structure of any privacy policy — how it is arranged

Almost all privacy policies have one and the same structure. As soon as you understand it — navigating becomes easy. What they collect — a list of types of data. Usually written broadly and vaguely. A red flag — phrases like «and other information» without specification. Why they collect — the purposes of processing. It is precisely here that the most interesting thing is hidden. Purposes must be specific under GDPR — but are often written so broadly that they cover anything at all. To whom they transfer — a list of third parties. The most important section. It is precisely here that it becomes clear how many companies receive your data. How long they store — the periods. If it says «as long as necessary» without specifics — this is a violation of the data-minimisation principle (Art. 5 GDPR). Your rights — usually the most honest section, because GDPR obliges it to be written correctly. Transfer abroad — critically important for EU residents. If the data goes to the US, Russia, China — there must be a legal basis.

Red flags — phrases that should alert you

Here are concrete wordings found in real documents. Alongside — what they mean in practice.

«We may transfer data to our partners»

What this means in practice: the list of «partners» is nowhere specified. This is a standard wording that gives the right to transfer data to anyone — advertising brokers, analytics platforms, subsidiaries. Without your additional consent. What GDPR requires: Article 13/14 obliges the company to list the categories of recipients or specific recipients. «Partners» without decoding — a violation of the transparency principle.

  • What to do: in a request under Art. 15, demand the full list of third parties to whom your data has been transferred.

«We use data to improve our services»

What this means in practice: one of the vaguest wordings in the industry. Behind «improving services» can hide the training of algorithms, building advertising profiles, A/B testing on you, analysing behaviour for monetisation. What GDPR requires: Article 5(1)(b) — the purpose of processing must be specific, explicit and lawful. «Improving services» — not a specific purpose. A real example — Google: Google’s Privacy Policy says «we use information to improve our services». Behind this hides, among other things, the training of language models on your Gmail letters and Drive documents — if you did not turn this off in the settings.

«We may use data to personalise advertising»

What this means in practice: this is a direct admission of profiling. They build your profile and sell access to it to advertisers. This is written openly — but most do not notice. What GDPR requires: Article 21 gives you the right to object to profiling for the purposes of direct marketing. The company is obliged to stop immediately. A real example — Meta: Meta’s policy explicitly states that data about your behaviour outside the platform (via the Facebook pixel on other sites) is used for ad targeting. Even if you are not logged in at the moment of visiting these sites.

«We may disclose data at the request of the authorities»

What this means in practice: this is a standard wording. But there is a critical difference — in which jurisdiction the servers and headquarters are located. A real example — VKontakte: Russian legislation obliges companies to provide data to the FSB on request without a court decision and without notifying the user. This is not written in the Privacy Policy — but it is the legal reality for any Russian company. For an EU resident this means that their data on VKontakte’s servers is accessible to Russian intelligence services bypassing any European protection mechanisms.

«We store data as long as necessary to provide the service»

What this means in practice: «as long as necessary» — they decide this themselves. In practice this means indefinite storage until you demand deletion. What GDPR requires: Article 5(1)(e) — data must be stored no longer than necessary for a specific purpose. The company is obliged to specify concrete periods or criteria for determining them. A real example — TikTok: in TikTok’s policy the storage periods are vague and tied to «business purposes». At the same time TikTok stores biometric data — face patterns from videos — which falls under Article 9 GDPR (special categories of data). Their processing requires explicit consent.

«By pressing “Accept”, you agree to our policy»

What this means in practice: this is an attempt to obtain «consent» to everything at once with one click. What GDPR requires: Article 7 — consent must be free, specific, informed and unambiguous. For each purpose of processing — separately. Consent «to everything» through an «Accept» button is not lawful consent under GDPR if it covers several different purposes without the possibility of choice.

«We transfer data to countries outside the EU»

What this means in practice: the data goes to jurisdictions without European protection. What GDPR requires: Chapter V — transfer is permissible only with an adequacy decision or standard contractual clauses (SCC). The US — after the cancellation of the Privacy Shield and before the adoption of the Data Privacy Framework in 2023 — was considered an unsafe jurisdiction. Russia and China do not have an adequacy decision. A real example — TikTok: TikTok’s data centres are partly located in China. ByteDance — a Chinese company. Chinese legislation obliges companies to provide data to government bodies. European regulators have repeatedly investigated TikTok precisely on this basis.

  • HOW TO READ A PRIVACY POLICY IN 5 MINUTES — A PRACTICAL ALGORITHM

You do not need to read the whole document. Here is what to do

  • Step 1 — Ctrl+F for keywords. Search: «partners», «third parties», «advertising», «transfer», «outside», «biometrics», «profiling». This immediately leads you to the most important sections.
  • Step 2 — The section on transferring data to third parties. Read carefully. Is there a specific list or only vague categories? Is there a mention of advertising networks or data brokers?
  • Step 3 — The section on transfer abroad. Which countries are mentioned? What legal basis is indicated — SCC, an adequacy decision, or nothing?
  • Step 4 — The section on storage periods. Are there specific figures? Or only «as long as necessary»?
  • Step 5 — The section on your rights. Is there a DPO contact? Is the regulator you can complain to indicated? If not — this is already a violation of Art. 13 GDPR.

What to do with what you found

Found a wording that seems like a GDPR violation — record it. Screenshot, date, a link to the specific section of the document. This is a ready-made basis for a request under Art. 15 — «provide all data that you process on the basis of this purpose». This is a ready-made basis for an objection under Art. 21 — «stop processing for the purposes of profiling». This is a ready-made basis for a complaint to the regulator — «the company processes data without a specific legal purpose in violation of Art. 5(1)(b)».

  • The document they wrote themselves — becomes evidence against them.

The bottom line

A Privacy Policy is not protection for the user. It is legal cover for the company. But it is precisely for this reason that the truth is written there. The company’s lawyers are obliged to write what they do — otherwise the document itself becomes a violation. Read not to understand — but to find. One phrase without a legal basis — is already an entry point for a complaint.

  • They wrote this themselves. Use it.

← All journal entries