Privacy policy doesn't name who personal information is shared with
This check looks for a section in the privacy policy naming the categories of third parties, such as advertising networks, payment processors, or analytics providers, that receive personal information collected on the site. On this site, the privacy policy is present and third-party services are loading, but the policy text never actually names the categories of recipients it shares data with. Australia's Privacy Principle 6 (APP 6) and GDPR (General Data Protection Regulation) Article 13(1)(e) both require disclosing who receives personal information, not just that it might be shared in general terms. Visitors and regulators alike are left unable to tell which third parties actually get their data, which is a specific and commonly checked disclosure gap. Your privacy lawyer should add a 'Who we share your information with' section naming the categories of recipients, such as payment processors, email marketing platforms, or advertising networks, and briefly explaining why each one receives data. This requires an actual inventory of the site's third-party integrations first, so budget around two hours including that review.
Why this matters
Australia's Privacy Principle 6 (APP 6) and GDPR (General Data Protection Regulation) Article 13(1)(e) both require disclosing who receives personal information, not just that it might be shared in general terms. Visitors and regulators alike are left unable to tell which third parties actually get their data, which is a specific and commonly checked disclosure gap.
How to fix it
Your privacy lawyer should add a 'Who we share your information with' section naming the categories of recipients, such as payment processors, email marketing platforms, or advertising networks, and briefly explaining why each one receives data. This requires an actual inventory of the site's third-party integrations first, so budget around two hours including that review.