Privacy policy covers data retention + user rights + legal basis - comprehensive GDPR-friendly disclosure
This check looks for three specific disclosures that GDPR (General Data Protection Regulation) Articles 13 and 14 require: data retention periods, user rights such as access and erasure, and the legal basis for processing. On this site, the privacy policy mentions all three, which regulators treat as the baseline signals of a genuinely complete policy. This is a positive finding. Regulators look for these three signals first when reviewing a complaint, and sites that have all three in place rarely face enforcement action purely over policy completeness. It's a solid foundation that most of the other privacy checks in this audit build on top of. No fix needed, this is already done well. Your privacy lawyer should review the policy yearly to keep retention periods, the list of third parties the policy names, and the contact details for data access requests current, since the content being accurate matters as much as it being present in the first place.
Why this matters
This is a positive finding. Regulators look for these three signals first when reviewing a complaint, and sites that have all three in place rarely face enforcement action purely over policy completeness. It's a solid foundation that most of the other privacy checks in this audit build on top of.
How to fix it
No fix needed, this is already done well. Your privacy lawyer should review the policy yearly to keep retention periods, the list of third parties the policy names, and the contact details for data access requests current, since the content being accurate matters as much as it being present in the first place.