---
# === IDENTITY ===
id: compliance/startup-legal/terms-of-service-privacy-policy-requirements/2026
canonical_question: "What must ToS and privacy policies include by jurisdiction — common mistakes, template requirements?"
aliases:
  - "Terms of service and privacy policy requirements for startups"
  - "What to include in startup ToS and privacy policy by jurisdiction"
  - "Privacy policy template requirements for GDPR, CCPA, and global compliance"
entity_type: execution_recipe
domain: compliance > startup-legal > terms of service privacy policy requirements
region: global
jurisdiction: global
temporal_scope: 2024-2026

# === VERIFICATION ===
last_verified: 2026-03-11
confidence: 0.88
version: 1.0
first_published: 2026-03-11

# === TEMPORAL VALIDITY ===
temporal_validity:
  status: evolving
  last_breaking_change: null
  next_review: 2026-09-07
  change_sensitivity: high

# === CONSTRAINTS ===
constraints:
  - "Privacy policies are legally required in most jurisdictions if collecting any personal data"
  - "GDPR Articles 13/14 mandate specific disclosures — omitting any is a violation"
  - "Terms of Service enforceability depends on proper notice and acceptance mechanisms"
  - "Jurisdiction-specific requirements cannot be addressed with a single generic template"
  - "Must be updated whenever data practices change — stale policies are compliance violations"

# === SKIP CONDITIONS ===
skip_this_unit_if:
  - condition: "Need to determine which privacy laws apply first"
    use_instead: "compliance/startup-legal/data-privacy-compliance-decision-tree/2026"
  - condition: "Need industry-specific compliance (HIPAA, COPPA, etc.)"
    use_instead: "compliance/startup-legal/industry-specific-regulatory-map/2026"

# === AGENT HINTS ===
inputs_needed:
  - key: jurisdictions
    question: "Which jurisdictions must your policies cover?"
    type: choice
    options: ["US only", "US + EU", "US + EU + UK", "Global", "EU only"]
  - key: business_type
    question: "What type of product/service?"
    type: choice
    options: ["SaaS/Web App", "Mobile App", "E-commerce", "Marketplace", "API/Developer Tool"]
  - key: data_practices
    question: "Do you share or sell user data to third parties?"
    type: choice
    options: ["No — internal use only", "Yes — analytics partners", "Yes — advertising partners", "Yes — data is the product"]

# === EXECUTION METADATA ===
execution:
  required_inputs:
    - name: "Privacy regulation applicability matrix"
      source: "compliance/startup-legal/data-privacy-compliance-decision-tree/2026"
      format: "List of applicable privacy laws"
    - name: "Data inventory"
      source: "Product/engineering team"
      format: "What data is collected, how it's used, who it's shared with"
    - name: "Business model details"
      source: "Founder input"
      format: "Revenue model, data processing purposes, third-party relationships"
  outputs:
    - name: "Privacy policy"
      format: "HTML page"
      description: "Jurisdiction-compliant privacy policy covering all applicable laws"
    - name: "Terms of Service"
      format: "HTML page"
      description: "Enforceable ToS with jurisdiction-specific provisions"
    - name: "Cookie policy"
      format: "HTML page or privacy policy section"
      description: "Cookie disclosure and consent mechanism (required for EU/UK)"
  tools_required:
    - name: "Privacy policy generator"
      purpose: "Generate base privacy policy"
      tier: paid
      cost: "$10-$50/mo"
      alternatives: ["Termly ($10/mo)", "Iubenda ($29/yr)", "GetTerms ($49 one-time)", "Attorney ($2K-$5K)"]
    - name: "ToS generator"
      purpose: "Generate base terms of service"
      tier: paid
      cost: "$10-$50/mo"
      alternatives: ["Termly ($10/mo)", "TermsFeed ($49+)", "Attorney ($2K-$5K)"]
  credentials_needed: []
  estimated_duration: "2-4 hours for initial drafting; 1-2 weeks with attorney review"
  estimated_cost: "$0-$100 (generator); $2,000-$10,000 (attorney)"

# === DISTRIBUTION ===
canonical_source: "https://knowledgelib.io/compliance/startup-legal/terms-of-service-privacy-policy-requirements/2026"
suggested_citation: "Source: knowledgelib.io — AI Knowledge Library (verified 2026-03-11)"

# === RELATED UNITS ===
related_kos:
  depends_on:
    - id: "compliance/startup-legal/data-privacy-compliance-decision-tree/2026"
      label: "Data privacy compliance decision tree"
    - id: "compliance/startup-legal/startup-legal-checklist-by-jurisdiction/2026"
      label: "Entity formation checklist"
  feeds_into: []
  related_to:
    - id: "compliance/startup-legal/industry-specific-regulatory-map/2026"
      label: "Industry-specific regulatory map"
  alternative_to: []

# === SOURCES ===
sources:
  - id: src1
    title: "Writing a GDPR-Compliant Privacy Notice"
    author: GDPR.eu
    url: https://gdpr.eu/privacy-notice/
    type: official_docs
    published: 2025-01-01
    reliability: authoritative
  - id: src2
    title: "Right to Be Informed — ICO"
    author: UK ICO
    url: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-be-informed/
    type: official_docs
    published: 2025-01-01
    reliability: authoritative
  - id: src3
    title: "CCPA Requirements 2026: Complete Compliance Guide"
    author: Secure Privacy
    url: https://secureprivacy.ai/blog/ccpa-requirements-2026-complete-compliance-guide
    type: technical_blog
    published: 2025-12-01
    reliability: high
  - id: src4
    title: "GDPR Privacy Policy Disclosure Requirements"
    author: Termageddon
    url: https://termageddon.com/gdpr-privacy-policy-disclosure/
    type: technical_blog
    published: 2025-06-01
    reliability: high
  - id: src5
    title: "Five Privacy Checkpoints to Start 2026"
    author: Wiley
    url: https://www.wiley.law/alert-Five-Privacy-Checkpoints-to-Start-2026
    type: industry_report
    published: 2025-12-15
    reliability: high
  - id: src6
    title: "Data Privacy Laws & Regulations Guide for 2026"
    author: Termly
    url: https://termly.io/resources/articles/data-privacy-regulations-guide/
    type: technical_blog
    published: 2025-11-01
    reliability: high
  - id: src7
    title: "Navigating the 2026 Privacy Landscape for Startups"
    author: Lloyd & Mousilli
    url: https://www.lloydmousilli.com/articles/navigating-the-2026-privacy-landscape-what-startups-ai-companies-and-all-u-s-businesses-need-to-know
    type: technical_blog
    published: 2025-12-01
    reliability: high
---

# Terms of Service & Privacy Policy Requirements

## Purpose

This recipe produces jurisdiction-compliant Terms of Service (ToS) and Privacy Policy documents for a startup, covering mandatory disclosures by regulation (GDPR, CCPA, PIPEDA, etc.), common legal mistakes that invalidate enforceability, and platform-specific requirements (web, mobile, marketplace). The output is a deployable set of legal pages that meets disclosure requirements across all applicable jurisdictions.

## Prerequisites

- [ ] **Privacy regulation matrix** — completed from [Data Privacy Compliance Decision Tree](/compliance/startup-legal/data-privacy-compliance-decision-tree/2026)
- [ ] **Data inventory** — complete list of data collected, processing purposes, and third-party sharing
- [ ] **Business model details** — revenue model, user types, payment processing, content ownership
- [ ] **Entity details** — legal name, registered address, contact information
- [ ] **Third-party service list** — all vendors processing user data (analytics, hosting, payments, email)

## Constraints

- GDPR Articles 13 and 14 mandate specific disclosures. Omitting any required element is itself a violation, regardless of other compliance efforts. [src1]
- Privacy policies must be provided in concise, transparent, intelligible, and easily accessible form, using clear and plain language. [src2]
- Terms of Service are only enforceable if users had reasonable notice and opportunity to review before acceptance. Buried links and passive acceptance may not hold up in court. [src5]
- CCPA requires a specific "Do Not Sell or Share My Personal Information" link, separate from the privacy policy. [src3]
- Both documents must be updated whenever data practices change. A stale privacy policy that doesn't reflect current practices is a compliance violation. [src4]
- California, Virginia, Colorado, and other states have specific privacy policy content requirements beyond federal law. [src7]

## Tool Selection Decision

```
What level of legal protection?
├── Pre-revenue startup, minimal budget
│   └── PATH A: Policy generator — $10-$50/mo
├── Funded startup, moderate complexity
│   └── PATH B: Generator + attorney review — $500-$2,000
├── Regulated industry or complex data practices
│   └── PATH C: Full attorney draft — $2,000-$10,000
└── Enterprise, multiple jurisdictions, data-heavy
    └── PATH D: Specialized privacy law firm — $10,000+
```

| Path | Method | Cost | Quality | Turnaround |
|------|--------|------|---------|-----------|
| A: Generator | Termly/Iubenda | $10-$50/mo | Baseline compliant | 1-2 hours |
| B: Generator + Review | Generator + attorney | $500-$2,000 | Good | 1-2 weeks |
| C: Attorney Draft | Privacy attorney | $2K-$10K | High | 2-4 weeks |
| D: Specialized Firm | Privacy law firm | $10K+ | Excellent | 4-8 weeks |

## Execution Flow

### Step 1: Draft Privacy Policy — Mandatory Disclosures

**Duration**: 1-2 hours
**Tool**: Policy generator or manual draft

Every privacy policy must include these elements. Check each against applicable regulations:

**Universal requirements (all jurisdictions):**
- Identity and contact details of the data controller/business
- Types of personal data collected
- Purposes for processing personal data
- Legal basis for processing (GDPR-specific, but good practice globally)
- Data retention periods or criteria
- Third parties data is shared with (by category or name)
- User rights and how to exercise them
- Contact method for privacy inquiries
- Date of last update

**GDPR-specific disclosures (Articles 13/14):**
- Contact details of Data Protection Officer (if applicable)
- Legal basis for each processing activity (consent, contract, legitimate interest, etc.)
- Legitimate interest details (if that's the legal basis)
- International transfer safeguards (Standard Contractual Clauses, adequacy decisions)
- Right to lodge a complaint with supervisory authority
- Whether data provision is contractual/statutory requirement
- Automated decision-making and profiling details (if applicable)
- Source of data (if not collected directly from the individual — Art. 14)

**CCPA/CPRA-specific disclosures:**
- Categories of personal information collected in prior 12 months
- Categories of sources
- Business or commercial purpose for collection
- Categories of third parties shared with
- Whether personal information is sold or shared (and opt-out mechanism)
- Retention periods per data category
- Right to know, delete, correct, opt-out, limit sensitive data
- Non-discrimination statement
- Financial incentive descriptions (if applicable)
- Link to "Do Not Sell or Share" mechanism

**PIPEDA-specific:**
- Accountability: identify individual responsible for compliance
- Identifying purposes at or before collection
- Consent mechanisms (express for sensitive, implied for less sensitive)
- Challenging compliance process
- Access and correction procedures

**Verify**: All mandatory disclosures for each applicable regulation included. No placeholder text.
**If failed**: Use disclosure checklist from GDPR.eu, ICO.org.uk, or state AG guidance documents.

### Step 2: Draft Terms of Service — Key Provisions

**Duration**: 1-2 hours
**Tool**: ToS generator or attorney template

Terms of Service establish the legal relationship between the business and users. Key provisions:

**Essential sections:**
- Acceptance mechanism (clickwrap is strongest: "I agree" checkbox)
- Service description and scope
- User obligations and acceptable use policy
- Account registration and security responsibilities
- Intellectual property ownership (company IP and user-generated content)
- Payment terms and refund policy (if applicable)
- Termination and suspension rights
- Disclaimer of warranties (to extent permitted by law)
- Limitation of liability (capped at fees paid, if enforceable)
- Indemnification clause
- Dispute resolution (arbitration, jurisdiction, governing law)
- Modification clause (how changes are communicated)
- Severability clause

**Jurisdiction-specific provisions:**
- **US**: Arbitration clause with class action waiver (enforceable under FAA). Must provide opt-out mechanism for CCPA users.
- **EU**: Cannot disclaim statutory consumer rights. Unfair Terms Directive limits what can be imposed. GDPR rights cannot be waived.
- **UK**: Consumer Rights Act 2015 limits unfair terms. Must be in plain language.
- **Australia**: Consumer guarantees under ACL cannot be excluded.

**For SaaS/API products, additionally include:**
- Service Level Agreement (SLA) or uptime commitment
- Data processing terms or DPA reference
- API usage limits and fair use policy
- Data portability on termination

**Verify**: All essential sections included. Acceptance mechanism is clickwrap (not just browsewrap). Jurisdiction-specific provisions match applicable laws.
**If failed**: Browsewrap ("by using this site you agree") is weaker than clickwrap. Always implement active acceptance for critical terms.

### Step 3: Create Cookie Policy (EU/UK Requirement)

**Duration**: 30-60 minutes
**Tool**: Cookie scanner + policy generator

If GDPR or UK GDPR applies, you need:

- Complete cookie audit (scan site for all cookies and trackers)
- Cookie categories: strictly necessary (no consent needed), analytics, functional, advertising
- Cookie consent banner that blocks non-essential cookies until user consents
- Cookie policy listing every cookie: name, provider, purpose, type, expiration
- Option to withdraw consent as easily as it was given

Tools for cookie scanning: Cookiebot, OneTrust, CookieYes (free tier for small sites).

**Verify**: No non-essential cookies fire before consent. Cookie policy lists all active cookies. Consent preference is saveable and changeable.
**If failed**: Test in incognito mode. Use browser developer tools Network tab to verify no tracking requests before consent.

### Step 4: Implement Proper Placement and Notice

**Duration**: 30 minutes
**Tool**: Website/app

Placement requirements:
- Privacy policy link on every page (footer) and at every data collection point (forms, checkout)
- ToS link at every acceptance point (signup, checkout, account creation)
- Cookie banner on first visit for EU/UK users (before any non-essential cookies)
- "Do Not Sell or Share" link in footer (CCPA requirement — separate from privacy policy)
- Mobile app: privacy policy link in app store listing AND in-app settings

Acceptance mechanisms:
- **Strongest (clickwrap)**: Checkbox + "I agree to the [Terms of Service] and [Privacy Policy]" — links must be functional
- **Medium (sign-in-wrap)**: "By creating an account, you agree to our [Terms]" — above the sign-up button
- **Weakest (browsewrap)**: Footer link only — often unenforceable in court

**Verify**: Links work from every page. Clickwrap implemented at signup. Mobile app links in store listing.
**If failed**: Broken links or missing policy pages are immediate compliance failures. Test all paths.

### Step 5: Review, Publish, and Set Update Schedule

**Duration**: 30 minutes
**Tool**: Version control, notification system

Final review checklist:
- [ ] All mandatory disclosures present for each applicable regulation
- [ ] Plain language used (Flesch reading score > 60 recommended)
- [ ] No conflicting statements between ToS and privacy policy
- [ ] "Last updated" date is accurate and displayed
- [ ] Version history maintained
- [ ] Notification mechanism for material changes (email for existing users)

Set update triggers:
- New data collection added → update privacy policy
- New third-party vendor added → update privacy policy
- New jurisdiction with users → update both documents
- Product/pricing changes → update ToS
- Legal/regulatory changes → review and update both
- Minimum: annual review regardless of changes

**Verify**: Both documents published. Links functional. Update schedule in compliance calendar.
**If failed**: Missing "last updated" date is itself a red flag for regulators. Add date before publishing.

## Output Schema

```json
{
  "output_type": "legal_document_set",
  "format": "HTML pages",
  "documents": [
    {"name": "privacy_policy", "path": "/privacy", "required": true, "sections": ["identity", "data_collected", "purposes", "legal_basis", "retention", "sharing", "rights", "contact", "updates"]},
    {"name": "terms_of_service", "path": "/terms", "required": true, "sections": ["acceptance", "service_description", "user_obligations", "ip_ownership", "payment", "termination", "liability", "dispute_resolution"]},
    {"name": "cookie_policy", "path": "/cookies", "required": "EU/UK only", "sections": ["cookie_audit", "categories", "consent_mechanism", "how_to_manage"]}
  ],
  "acceptance_mechanism": "clickwrap",
  "update_schedule": "trigger-based + annual review"
}
```

## Quality Benchmarks

| Quality Metric | Minimum Acceptable | Good | Excellent |
|---------------|-------------------|------|-----------|
| Disclosure completeness | All mandatory elements | Jurisdiction-specific sections | Attorney-reviewed |
| Readability | Plain language attempt | Flesch score > 50 | Flesch score > 60 |
| Acceptance mechanism | Sign-in-wrap | Clickwrap at signup | Clickwrap + re-consent on changes |
| Update currency | Within 6 months | Within 3 months | Updated with every change |
| Cookie compliance | Banner exists | Blocks non-essential cookies | Preference center + audit |

**If below minimum**: Use Termly or Iubenda for automated generation. Engage privacy attorney for regulated industries.

## Error Handling

| Error | Likely Cause | Recovery Action |
|-------|-------------|----------------|
| Regulator notice about incomplete disclosures | Missing mandatory GDPR/CCPA elements | Update immediately, respond to regulator within deadline |
| ToS ruled unenforceable | Browsewrap only, no active consent | Implement clickwrap, require re-acceptance from all users |
| User complaint about data practices | Privacy policy doesn't match actual practices | Audit data practices, update policy to match reality, remediate gaps |
| Cookie banner not blocking cookies | Technical implementation error | Audit with browser tools, fix consent mechanism, re-scan site |
| App store rejection for missing policy | Privacy policy link missing from listing | Add link to app store listing and in-app settings |

## Cost Breakdown

| Component | Generator | Generator + Review | Full Attorney |
|-----------|-----------|-------------------|---------------|
| Privacy policy | $10-$50/mo | $10/mo + $500 review | $2K-$5K |
| Terms of service | $10-$50/mo | $10/mo + $500 review | $2K-$5K |
| Cookie policy | Free-$12/mo | Free-$12/mo + $300 review | $500-$1K |
| DPA/data processing terms | Template ($0) | $300-$500 review | $1K-$3K |
| Annual updates | Included | $200-$500/update | $1K-$3K/update |
| **Total Year 1** | **$120-$600** | **$700-$2,500** | **$5K-$14K** |

## Anti-Patterns

### Wrong: Copying another company's privacy policy
Every company's data practices differ. Copying creates a policy that doesn't match your actual practices — which is itself a violation. Regulators specifically target inaccurate policies. [src5]

### Correct: Draft from your actual data inventory
Start with what data you collect, why, and who you share it with. Build the policy around your actual practices, not another company's template.

### Wrong: Using browsewrap-only acceptance for Terms of Service
Courts regularly refuse to enforce terms when users had no actual notice or opportunity to consent. A footer link to terms is often insufficient to create a binding agreement. [src7]

### Correct: Implement clickwrap acceptance
Require users to actively check a box or click "I agree" next to linked terms before account creation. This creates the strongest evidence of acceptance.

## When This Matters

Use this recipe after completing the data privacy decision tree and before launching any product. Privacy policies and ToS are legally required before collecting any personal data, and non-compliance is among the most easily detected violations — regulators can spot it by visiting your website.

## Related Units

- [Data Privacy Compliance Decision Tree](/compliance/startup-legal/data-privacy-compliance-decision-tree/2026)
- [Startup Legal Checklist by Jurisdiction](/compliance/startup-legal/startup-legal-checklist-by-jurisdiction/2026)
- [Industry-Specific Regulatory Map](/compliance/startup-legal/industry-specific-regulatory-map/2026)
