The compliant footer: privacy policy, terms, and what actually has to be on the page
Updated 2026-08-02
The footer is the least interesting part of a landing page and one of the most common reasons a perfectly good one gets disapproved. It is also where data protection obligations land: the moment a page has a lead form, it is collecting personal data, and that brings requirements that exist independently of any ad platform. This covers what has to be there and what it has to say.
What has to be on the page
Ad platforms and data protection law want overlapping but not identical things. The union of the two is short.
| Element | Why | Common failure |
|---|---|---|
| Privacy policy | Required by platforms and by law once you collect data | Link exists but 404s, or opens a modal with placeholder text |
| Terms of service | Platform requirement; sets expectations | Copied from an ecommerce template and mentions orders you do not take |
| Who you are | Transparency; feeds landing page experience | No legal entity, no address, no way to reach a human |
| Contact route | Required for transparency and for data requests | Only a form — no email for someone exercising a data right |
| Consent, where required | Law, not platform policy | Pre-ticked box, or bundled consent for unrelated purposes |
What a lead-gen privacy policy actually has to say
Most privacy policies on landing pages are copied from an ecommerce template and describe processing that never happens. That is worse than useless: it is inaccurate, which is itself the problem the requirement exists to prevent.
- 1
What you collect, in plain terms
Name, contact details, whatever the form asks for — plus anything collected automatically such as analytics identifiers and pixel data.
- 2
Why, and on what basis
To respond to the enquiry is the obvious purpose. If you also intend to market to them later, say so — that is a separate purpose and often a separate legal basis.
- 3
Who else sees it
Your CRM, your email provider, your ad platforms if you send conversion data back. Naming categories of recipients is normally sufficient.
- 4
How long you keep it, and how to get it deleted
A retention period you actually apply, and a working route to exercise access and deletion rights.
- 5
Where it goes
If your tools process data in another country, that transfer needs mentioning — this is where cross-border lead gen picks up an obligation many advertisers miss.
Where consent is actually required
Consent is over-applied in some places and missing in others. The distinction that matters is between the data someone hands you deliberately and the tracking that happens to them.
- Submitting a form is not itself consent to marketing — if you plan to send campaigns later, ask separately and unbundled
- Non-essential cookies and tracking pixels generally require prior consent in the EU and UK, which means before the pixel fires, not after
- A pre-ticked box is not consent anywhere that requires consent
- Consent must be as easy to withdraw as to give, and you have to honour it in the tools that actually hold the data
The practical consequence for advertisers: a consent banner that loads the pixel before the visitor answers is both a compliance problem and an attribution problem, because the events it fires may not be lawfully collected in those markets.
If your page is lead-gen, do not use an ecommerce footer
This sounds pedantic and it is a genuine source of disapprovals. A footer copied from a store template promises refunds, shipping, and order handling that your page has no mechanism for — which is a mismatch between what the page says and what it does.
- Remove refund, shipping, returns, and order-cancellation language if the page takes no orders
- Terms should describe an enquiry relationship: what happens when someone submits, what you will do, what you are not promising
- For regulated professions, add the disclosures your regulator requires — and state plainly that submitting the form creates no client relationship
- Keep the copyright line accurate; a stale year is a small signal that nobody maintains the page
Common questions
- Do I need a privacy policy if the page only links to WhatsApp?
- If the page carries analytics or an ad pixel, it is processing personal data regardless of where the conversion happens, so yes. The chat itself is then governed by the messaging platform's terms and by whatever you do with the conversation afterwards.
- Can I use a generated privacy policy?
- As a starting point, provided you then edit it to describe what you actually do. A generated policy describing processing you do not perform is inaccurate, and accuracy is the entire point — for anything regulated or high-risk, have it reviewed properly.
- Does GDPR apply if I am not in Europe?
- It can. It follows the people, not the company — offering services to or monitoring people in the EU or UK can bring you in scope regardless of where you are based. Several other markets have their own regimes with their own triggers.
- Where should the links go — footer or near the form?
- Both. The footer satisfies the platform requirement; a short line beside the submit button telling the visitor what happens to their details is what actually raises form completion. Those two jobs are different and both worth doing.
References
The rules and explanations in this article follow the official sources below. Always defer to the latest official documentation.