← All posts

Why your privacy policy is failing your community

Most nonprofit privacy policies are written for lawyers, not the people they serve. Here's what a plain-language alternative looks like — and why it matters for trust.

Your privacy policy exists. You may have even had a lawyer review it. But if the people you serve can’t read it, understand it, or find the information they actually need — it isn’t doing its job.

For community organizations serving vulnerable populations, a privacy policy isn’t just a legal document. It’s a trust signal. And most of them are failing that test.

What most privacy policies get wrong

The average nonprofit privacy policy runs 1,200–2,000 words of dense legal prose, often copied from a generic template. It mentions “third-party service providers” without naming them. It says data is “used to improve services” without specifying how. It lists rights under GDPR or CCPA without explaining how to exercise them.

For someone seeking reproductive healthcare, domestic violence support, or immigration legal aid — someone who has very good reasons to wonder who might see their information — this kind of document doesn’t reassure. It obscures.

What plain-language looks like in practice

A plain-language privacy policy answers three questions clearly:

  1. What information do you collect, and why? Be specific. “We collect your name, phone number, and the date of your appointment” is better than “contact information and service utilization data.”

  2. Who can see it? Name your actual vendors — your scheduling software, your email platform, your analytics provider. If you use Google Analytics, say so.

  3. What can people do about it? Tell them how to request deletion, how to opt out of communications, and who to contact with questions. Give a real name or email, not just “contact us.”

There’s a related problem that often goes unaddressed: consent at the point of collection. A plain privacy policy is necessary but not sufficient. People also need clear, contextual notice at the moment they’re sharing information — not buried in a footer link.

If someone is filling out an intake form and you’re asking for their immigration status, their history of abuse, or their HIV status — that’s the moment to explain, in plain language, exactly who will see that information and why you need it.

Consent design is the practice of making those moments clear, specific, and genuinely informed. It’s different from legal compliance. It’s about respect.

Where to start

You don’t need to rewrite everything at once. Start with your intake form. Look at every field you’re collecting and ask: do we actually use this? Who sees it? How long do we keep it?

Then look at your privacy policy through the eyes of someone who is afraid. What questions would they have? Are those questions answered?

If you’d like a structured way to work through this, the Digital Integrity & Safety Audit is a free self-assessment designed for exactly this kind of review.