A privacy policy is the public-facing document that tells users how a business collects, uses, shares, and protects their personal data. Under GDPR Articles 13 and 14, it must disclose the controller's identity, purposes, lawful basis, recipients, retention periods, and data subject rights. Under CCPA/CPRA ยง1798.130, it must also list categories of PI collected, sold/shared, and California residents' opt-out mechanisms. It should link from every page footer and the cookie banner, and be updated whenever processing materially changes. A privacy policy is distinct from a privacy notice (just-in-time at collection) and terms of service (a contract).