Your Privacy Policy is (Probably) Out of Date.
And you (probably) don’t even know it.
Every time you install a new plugin, delete an old one, add a subdomain, embed a form, switch email providers, or connect a new tool — your privacy policy needs updating. Not eventually. Immediately.
Most people write theirs once, pat themselves on the back for being GDPR-compliant, and never look at it again. Meanwhile their site quietly accumulates new data processors, third-party cookies, and tracking tools that aren’t documented anywhere.
That’s not compliance. That’s a ticking clock.
Here’s how to defuse it.
What Actually Triggers an Update
Your privacy policy isn’t a one-and-done document — it’s a live inventory of everything on your site that touches user data. That inventory changes more often than most people think. If any of the following has happened since you last opened your policy, it’s already out of date:
- New plugins. Even a “harmless” one — a related-posts widget, a form validator, a speed optimiser — can set cookies or ping third-party servers you haven’t declared.
- Deleted plugins. People forget this one constantly. If you remove a tool, the policy still lists it as an active processor. That’s not a small error — it’s you telling regulators you’re using something you’re not, or worse, failing to mention what replaced it.
- New subdomains. A blog on a subdomain, a shop on another, a booking system on a third — each one can run its own tracking stack, separate from your main site.
- Embedded forms. Typeform, Tally, a Calendly widget, a newsletter signup box — every embed is a third party quietly collecting data on your behalf, under their own terms, not yours.
- Switching email providers. Moving from Mailchimp to ConvertKit isn’t just a workflow change. It’s a new data processor, a new server location, potentially a new legal basis for storage.
- Connecting new tools. Analytics, chatbots, CRMs, payment processors, heatmap trackers — anything that talks to your site is a party your policy needs to name.
The pattern: if it collects, stores, or transmits data — and you added, removed, or swapped it — your policy is stale until you say otherwise.
How to Audit
What’s Actually on Your Site Right Now
Don’t trust your memory. Audit it properly.
- Open DevTools. Chrome or Firefox, Network tab, reload the page. Watch what fires. You’ll see third-party domains you forgot existed — old analytics scripts, abandoned A/B testing tools, a chat widget nobody uses anymore.
- Run a cookie scanner. Tools like Cookiebot, GDPR Cookie Consent Scanner, or even a manual check via document.cookie in the console will show you every cookie being set, first and third party.
- Check your plugin/app list against your policy, line by line. Not skim — line by line. If something’s installed but unlisted, or listed but uninstalled, that’s your gap.
- List every embed separately. Forms, videos, maps, payment buttons — anything pulling from an external domain counts, even if it feels like part of your site.
Do this quarterly at minimum. Twice a year if your site genuinely doesn’t change much. Anything less and you’re compliant on paper only.
Using AI to Reduce and Rewrite Accurately
This is where it gets useful, not just tedious. Once you’ve got your audit list, feed it to an AI model with your existing policy and ask it to reconcile the two — flag what’s missing, what’s outdated, what needs to go.
Here’s a real example from doing exactly that on my own site.
Before:
“We may use cookies and similar technologies to enhance your experience. We may also share information with trusted third parties for analytics and marketing purposes.”
That’s the sentence most policies still run on. It names nothing, commits to nothing, and wouldn’t survive a serious GDPR review — because “trusted third parties” isn’t a disclosure, it’s a placeholder someone forgot to finish.
After — the actual output once the audit was fed back in:
- A live cookie table, one row per cookie, naming the provider, the exact function, and the expiry — _ga and _ga_Z02D4LBVQ3 (Google Analytics 4, anonymised session tracking, 1 year), _gcl_au (conversion linking, 3 months), and the AddToAny sharing cookie (session-based).
- A named list of every active processor and why it’s there — SiteGround and Wordfence for security, Kit for newsletter sign-ups, Akismet for spam filtering, Contact Form 7 for direct enquiries — instead of a blanket “we use plugins to run our site.”
- A plain statement that the admin/design tools (SEO, redirects, editor) touch zero visitor data, so readers aren’t left guessing which entries on the list actually matter to them.
Same site, same actual practices — but now every claim is checkable against something real, instead of resting on the word “trusted.”
The AI didn’t invent compliance. It forced precision — it took a plugin list and an audit and turned them into a table a regulator (or a nosy user) can actually verify. That’s the entire difference between a policy that protects you and one that just performs the idea of protecting you.
Set a Review Schedule
So It Never Gets This Far Behind Again
A policy audit shouldn’t be a crisis response. Build it into your calendar:
- Quarterly: quick pass — new plugins, new embeds, anything installed/removed in the last three months.
- On every tool change: the moment you switch providers or add integrations, that’s the trigger, not “whenever I remember.”
- Annually: full audit — DevTools, cookie scanner, plugin list, the works.
Put it in your calendar with an actual date, not a vague intention. “Sometime” is how you end up here in the first place.
The Privacy Policy Practical Takeaway
Updating Your Cookie Policy
Here’s the process, start to finish:
- Run your DevTools + cookie scanner audit.
- List every cookie by name, purpose, and category (necessary, functional, analytics, marketing).
- Cross-check against your consent banner — if a cookie fires before consent is given, that’s a compliance issue on its own.
- Update your cookie policy table with the current list — remove anything no longer in use.
- Reissue consent if the categories have changed (most consent management platforms handle this automatically, but check).
- Date-stamp the update. Future-you will need to know when this was last touched.
Bookmark this. Run it quarterly. Your privacy policy isn’t a document you write once — it’s infrastructure. Treat it like you’d treat anything else that breaks quietly if left alone.
Alternatively, contact me if you want it done for you.
Images and Video for Your Privacy Policy is (Probably) Out of Date using Gemini/Nano Banana
→ Tech VA series
