Does the Applicant have written privacy policy reviewed by attorney and updated annually?
Your published privacy notice is a public promise. It is read by regulators and plaintiffs more carefully than by customers.
What the carrier is actually asking
The carrier is asking whether a written privacy policy exists, whether counsel reviewed it, and whether it is updated annually. It usually means the external-facing notice rather than internal handling procedures.
Why it is underwritten
Regulatory theories in privacy enforcement frequently rest on a mismatch between the published notice and actual practice, which is characterised as a deceptive practice independent of any breach. Carriers ask because that exposure exists without an incident, and because an accurate notice is evidence of a functioning privacy programme.
Where the answer lives in Microsoft 365, Entra ID, and Azure
The notice is a public document and the review is a legal engagement, so this is attested. Whether practice matches the notice is partly observable.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Website | The published privacy notice, its effective date, and version history | Current, dated, and covering the categories the applicable statutes require |
| Legal records | Attorney review engagement and date | A documented review by counsel familiar with the applicable regimes. Attested |
| Website | Cookie and tracking technology disclosures and consent mechanism | Consistency between what trackers actually run and what the notice and banner describe |
| Process | Data subject rights request handling | A working intake and fulfilment process, since the notice promises rights that someone has to deliver |
| Data map | Whether actual collection and sharing match the notice | Consistency, which is the exposure this question is really about |
Marketing adds a tracking pixel; the notice does not change. Enforcement and private litigation in this area have concentrated precisely there, particularly for analytics and advertising technology on sites handling sensitive categories. Auditing what actually runs on your site is the fastest way to check this answer.
What a defensible yes requires
- The notice is current, dated, and reviewed by counsel within the last year.
- It accurately describes what is collected, why, with whom it is shared, and for how long it is kept.
- Cookie and tracking disclosures match the technologies actually running.
- A rights request process exists and meets statutory deadlines.
- Material changes to collection practices trigger a notice update rather than an annual catch-up.
How this answer goes wrong
The notice was drafted years ago for a smaller company, has been reviewed nominally each year, and does not mention the analytics platform, the advertising pixels, or the customer data platform added since. Every one of those is a disclosure gap in a document the organisation published itself.
Frequently asked
Does a template privacy notice count?
Only once adapted to your actual practices. A template describing collection you do not perform, or omitting collection you do, is the mismatch the exposure rests on.
How often does it need updating?
Annually at minimum and whenever collection practices change materially. The second trigger is the one that gets missed.
Do we need separate notices per jurisdiction?
Often, or a single notice with jurisdiction-specific sections. Counsel should determine which regimes apply based on where your data subjects live.
Is this covered by cyber insurance?
Regulatory defence for privacy claims is commonly available and varies considerably by policy, particularly for tracking-technology claims. Worth reading the wording rather than assuming.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture