March 1, 2007

Ten Steps to Develop a Multilayered Privacy Notice

This paper creates a 10 step guide to creating a multilayered privacy notice. It argues that creating a privacy notice should not be viewed as an intimidating process. Developing a multilayered notice is no more difficult than a full legally compliant notice.

If an organization has already created a full legally compliant notice, they can skip the first 5 steps below and move directly to creating a condensed notice in step 6. Good practice principles would suggest a legal review before publishing any notice.

Our 10 steps to creating a multilayered notice:

  1. Determine what your company does with personal data
  2. Determine whether your company’s treatment of personal data is legally compliant
  3. Develop and test an internal privacy policy that reflects how your company treats personal data
  4. Use that internal policy to create the organization’s complete external privacy policy
  5. Test and revise the full privacy notice
  6. Create the condensed notice
  7. Harmonize the full and condensed notices together
  8. Create the short notice
  9. Review and test the multilayered notices
  10. Publish your new multilayered notice