FillTrust

How to answer

Is your privacy notice publicly available? Please provide the URL.

The easiest row on the questionnaire, and one people still lose points on, because the notice is public and gets read against everything else you claimed.

A model answerConfirmed in your documents

Yes. Our privacy notice is published at [URL] and was last reviewed on [date]. It covers the personal data we process, the purposes, our retention periods and our subprocessors.

Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.

Answered from
The notice itself. This is a URL question, and the only way to get it wrong is to leave it blank or to link to something that contradicts your other answers.
Evidence to attach
The published notice, and the date it was last reviewed.
Where it is asked
CAIQ v4.0 · DSP-01SIG LiteBespoke vendor questionnaires

This row asks for a link. It takes ten seconds and it is worth taking seriously anyway, because a privacy notice is the only document in a vendor review that the reviewer can read without asking your permission. Everything else in the file, the SOC 2, the pen test, the policies, arrives under NDA and after a delay. The notice is already public, so it is the first thing checked and the easiest place to be caught contradicting yourself.

Give the URL, the review date and the scope in one line. Reviewers are ticking rows, and an answer that anticipates the next two questions saves a round trip. If your product notice and your website notice are separate documents, say which is which; questionnaires increasingly ask for the product one specifically and a marketing-site privacy policy is not it.

Read your notice against your own questionnaire answers before you send either. The two that reliably drift apart are retention and subprocessors. The questionnaire says you delete customer data 30 days after termination; the notice, written two years ago by someone else, says 90. Both are published statements by your company and now one of them is false. The same goes for the subprocessor list: if the notice names a vendor you dropped last year, or omits one you added last month, the reviewer has found a documentation gap without leaving their desk.

A cookie policy is not a privacy notice. One explains what you set in a browser and how consent is withdrawn. The other explains what personal data you process, why, on what lawful basis, who you share it with, how long you keep it and what rights people have. Some companies publish only the first and answer this question with it. It is an obvious substitution and it invites a closer read of everything else.

Date it, and mean the date. "Last reviewed" is a claim about a review having happened. Put the notice on the same annual cycle as your policies so the date stays true, and record who reviewed it. When a reviewer asks how you keep it current, that cycle is the answer.

If your notice is thin or out of date, fix it before you answer rather than linking it and hoping. It is a public page, it is cheap to correct, and it is the one piece of evidence in the whole review you fully control.

How this one goes wrong

Specific to this question, not general advice.

  • A notice that disagrees with the rest of the questionnaire. Retention periods and subprocessor lists are the two that diverge, and the reviewer is reading both documents in the same sitting.
  • Linking a cookie banner policy and calling it a privacy notice. They answer different questions and a reviewer notices immediately.
  • A notice last updated three years ago, listing tools you no longer use. It is a public document, so this is the one inconsistency a reviewer can check without asking you anything.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.