How to Write a Privacy Notice for a Sri Lankan Website
A practical, people-first approach to explaining how a website or digital service collects, uses, protects, and shares personal data.
A privacy notice is a trust document
A privacy notice should not be hidden, vague, or written only for lawyers. It should help visitors understand what happens to their information and give them a clear route to ask questions. A useful notice makes the organisation more transparent while helping internal teams document what they actually do with personal data.
SECTION 1
Start with a plain-language summary
Use a short opening that explains what the notice covers and why it matters. Avoid using legal language as a substitute for clarity.
SECTION 2
Identify who is responsible
State the organisation name, relevant contact details, and the privacy contact route that visitors can use for questions or rights-related requests.
SECTION 3
Explain what data you collect
List relevant categories such as names, contact details, account information, form submissions, device details, cookies, analytics data, and communications.
SECTION 4
Explain why data is used
Connect each important category of data to a clear business purpose, such as responding to enquiries, delivering a service, improving a website, or meeting legitimate operational obligations.
SECTION 5
Describe sharing and service providers
Explain when data may be shared with suppliers, hosting providers, analytics tools, payment partners, professional advisers, or authorities where applicable.
SECTION 6
Set out retention and security
Describe how long information is retained at a high level and explain that technical and organisational safeguards are used to protect it.
SECTION 7
Explain individual rights and contact routes
Tell people how to contact the organisation, ask questions, update information, or make a request relating to their personal data.
SECTION 8
Keep it current
Review the notice whenever your website, forms, marketing tools, suppliers, analytics, or processing activities change.
Common mistakes to avoid
- • Copying a generic notice that does not match the organisation’s real practices.
- • Listing purposes that are too broad or unclear.
- • Forgetting forms, cookies, analytics, marketing tools, and third-party services.
- • Providing no clear privacy contact route.
- • Failing to update the notice after changing systems or suppliers.
Practical readiness
Make privacy visible from the first interaction.
Use the free assessment to identify gaps in transparency, data governance, supplier management, and privacy operations.
Start free assessment →