Data handling and policy

Does the Applicant have written privacy policy reviewed by attorney and updated annually?

Your published privacy notice is a public promise. It is read by regulators and plaintiffs more carefully than by customers.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether a written privacy policy exists, whether counsel reviewed it, and whether it is updated annually. It usually means the external-facing notice rather than internal handling procedures.

Why it is underwritten

Regulatory theories in privacy enforcement frequently rest on a mismatch between the published notice and actual practice, which is characterised as a deceptive practice independent of any breach. Carriers ask because that exposure exists without an incident, and because an accurate notice is evidence of a functioning privacy programme.

Where the answer lives in Microsoft 365, Entra ID, and Azure

The notice is a public document and the review is a legal engagement, so this is attested. Whether practice matches the notice is partly observable.

PlatformWhere the setting livesWhat has to be true
WebsiteThe published privacy notice, its effective date, and version historyCurrent, dated, and covering the categories the applicable statutes require
Legal recordsAttorney review engagement and dateA documented review by counsel familiar with the applicable regimes. Attested
WebsiteCookie and tracking technology disclosures and consent mechanismConsistency between what trackers actually run and what the notice and banner describe
ProcessData subject rights request handlingA working intake and fulfilment process, since the notice promises rights that someone has to deliver
Data mapWhether actual collection and sharing match the noticeConsistency, which is the exposure this question is really about
Trackers outrun the notice

Marketing adds a tracking pixel; the notice does not change. Enforcement and private litigation in this area have concentrated precisely there, particularly for analytics and advertising technology on sites handling sensitive categories. Auditing what actually runs on your site is the fastest way to check this answer.

What a defensible yes requires

  • The notice is current, dated, and reviewed by counsel within the last year.
  • It accurately describes what is collected, why, with whom it is shared, and for how long it is kept.
  • Cookie and tracking disclosures match the technologies actually running.
  • A rights request process exists and meets statutory deadlines.
  • Material changes to collection practices trigger a notice update rather than an annual catch-up.

How this answer goes wrong

The notice was drafted years ago for a smaller company, has been reviewed nominally each year, and does not mention the analytics platform, the advertising pixels, or the customer data platform added since. Every one of those is a disclosure gap in a document the organisation published itself.

Frequently asked

Does a template privacy notice count?

Only once adapted to your actual practices. A template describing collection you do not perform, or omitting collection you do, is the mismatch the exposure rests on.

How often does it need updating?

Annually at minimum and whenever collection practices change materially. The second trigger is the one that gets missed.

Do we need separate notices per jurisdiction?

Often, or a single notice with jurisdiction-specific sections. Counsel should determine which regimes apply based on where your data subjects live.

Is this covered by cyber insurance?

Regulatory defence for privacy claims is commonly available and varies considerably by policy, particularly for tracking-technology claims. Worth reading the wording rather than assuming.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture