Customer Impact

Website & Development

Website Privacy Policy and Cookie Statement: What Must Be Included

Copy for AI

Creating a privacy policy for your website comes down to two separate documents: a privacy statement that explains which personal data you collect, why and for how long, and a cookie statement that describes which cookies and trackers you place. Many B2B companies lump the two together or paste a free generator text at the bottom of their site, exposing themselves to both a legal and a trust risk. In this article you will read what the difference is, what must be included in each document, and how to build an accurate version that fits your site.

A privacy statement covers all the personal data you process, while a cookie statement deals specifically with what is stored or read on your visitor’s device. These are two documents, each with its own legal basis, and confusing them is a common mistake.

The privacy statement falls under the GDPR (the General Data Protection Regulation). It governs every processing of personal data: a completed contact form, a newsletter sign-up, a quote request, job applications, your CRM. In it you explain who you are, what you do with that data and what rights someone has.

The cookie statement, on the other hand, falls under the ePrivacy rules, anchored in Belgium in the legislation on electronic communications. These are not only about personal data, but about placing and reading information on the visitor’s device. That is why you need prior consent for non-essential cookies, even if they contain little personal data in themselves. In short: one document describes what you do with data, the other describes what you place and on what basis.

What must your privacy statement contain?

Your privacy statement must be able to tell a visitor, in clear language, who you are, which data you process, why, on what legal basis and what they can do about it. The GDPR lists these information obligations concretely.

A complete privacy statement usually contains at least these elements:

  • Who the data controller is: your company name, company number and contact details, plus those of any data protection officer.
  • Which personal data you collect and through which channels (forms, email, analytics, customer management).
  • The purposes for which you use it, for example drawing up a quote, answering a question or invoicing.
  • The legal basis per processing activity: consent, performance of a contract, a legal obligation or a legitimate interest.
  • Who you share data with: processors such as your hosting, email tool, CRM or analytics provider, and whether data leaves the EU.
  • How long you retain it, or which criterion you apply for that.
  • The rights of the data subject: access, rectification, erasure, objection and the right to lodge a complaint with the supervisory authority.

That seems like a lot, but the point is that every element must match what your site actually does. If you have a quote form and a newsletter, both must be in it. If you do not have a webshop, payment information does not belong in it. A privacy statement is not a template you fill in, it is an honest description of your own data flows.

Your cookie statement must make clear, per cookie or category, which ones you place, what they are for, who places them and how long they stay, and your banner must ask for valid consent before anything non-essential is loaded. The Belgian Data Protection Authority has formulated clear expectations about this.

Concretely, that means among other things: no pre-ticked boxes, and a button to reject everything at the same level and just as visible as the button to accept everything. In the first layer of the banner, visitors must immediately understand what you are asking consent for, and they must be able to change their choice later. A banner that only shows “Accept”, or that only lets you through once you accept, does not comply.

Important in practice: essential cookies (for example for a shopping cart or to remember a logged-in session) may be placed without consent. For analytics, marketing pixels and embedded third-party content you do need prior consent. That has a direct technical consequence: your tracking scripts may only fire after the visitor has consented. If your consent banner is built in incorrectly, those scripts load anyway, and your consent is worthless. This is precisely a place where the build of your site and your legal text come together, and where things often go wrong.

Why is a copied generator text a risk?

A free generator gives you a generic text that suits an average website, not yours, and that is exactly the problem. The document reads professionally, but describes processing activities you may not carry out and misses ones you do.

The typical mistakes: there is a webshop paragraph while you process no payments, tools and processors are mentioned that you do not use, or precisely not the tools you actually use such as your specific CRM, your email marketing platform or your form software. Sometimes the text refers to foreign legislation instead of the Belgian framework. A privacy statement that does not correspond to reality is not only legally weak, it is also simply untrue towards your visitor.

And that is where the B2B cost lies. A business buyer about to request a quote sometimes does read the fine print. A sloppy or clearly copied privacy text sows doubt at exactly the moment you want to win trust. It undermines the same signal you build so carefully elsewhere on your site, such as on your about-us page or via the trust signals that make a B2B site credible. A generator is a fine starting point to see the structure, but never a finished product you publish unread.

How do you tackle a correct privacy policy in practice?

The most reliable approach is to work backwards: don’t start with the text, but with an inventory of what your site really does with data. Only once you have that mapped out do you write the two documents.

WORKABLE ORDER How to build an accurate privacy policy 01 Data flows Forms & tools 02 Processors Who gets data 03 Cookies & scripts Essential or not 04 Write the texts Tailored to your site 05 Legal review Lawyer or DPO Start with the inventory, not with the text.
Work backwards: first map out what your site does, only then write.

A workable order:

  1. Map out your data flows. Go through every form, every tool and every integration. Which fields do you ask on your contact page and in your conversion forms? Where does that data go?
  2. List your processors. Hosting, analytics, CRM, email tool, chat widget, form software. These are the parties you must name in your privacy statement.
  3. Inventory your cookies and scripts. Which ones load, who places them, and are they essential or not? This determines your cookie statement and the configuration of your consent banner.
  4. Write or adjust the texts on that basis, in clear language, aligned with the Belgian and European framework.
  5. Have it reviewed legally. For the final wording, a lawyer or DPO is the right person, certainly with sensitive processing activities.

Customer Impact is an agency, not a law firm: we do not give legal advice. What we do do is build your website so that the technology matches the text, so that your consent banner only fires trackers after consent, and so that your privacy and cookie statements are findable and readable on your site. That technical correctness belongs to the same foundation as accessibility and is too often treated as an afterthought. If you want to dive deeper into the broader build process, you will find it in our guide on having a B2B website built and with our web design agency.

The short summary

You need two documents: a privacy statement under the GDPR that honestly describes your data flows, and a cookie statement with a correctly working consent banner under the ePrivacy rules. The biggest pitfall is a generator text that does not correspond to what your site actually does: that is legally weak and costs you trust with precisely the business buyer you want to convince. So start with an inventory of your real data flows, tailor your texts to it, and make sure the technology of your site also keeps the legal promises. Don’t plan such an update as a standalone job, but as part of a broader approach: how to bundle loose fixes into a growth plan is something you read in drawing up a website roadmap.

Schedule your free intake

Free website scan

Enter your website and get an automatic scan within minutes, with concrete technical and SEO improvements. No sales pitch.

Where should we send your report?

We only use your details for your scan. No spam, unsubscribe anytime.