Most privacy teams don’t have a writing problem, they have a drift problem.
The notice got published. Legal signed off, compliance checked the box, and then the business kept moving; new ad pixels, new vendors, new AI tools, new data flows, none of which made it back into the document sitting on your website footer.
That gap between what your privacy notice says and what your organization is actually doing is one of the most common and most costly risks in privacy management today. In a recent TrustArc webinar, privacy practitioners Ryan Boos and Berta Balanzategui broke down how the gap forms, where it tends to show up, and what privacy teams can do to close it before regulators do it for them.
The Business Moves. The Notice Doesn’t.
The scenario is familiar to anyone who’s worked in privacy operations. Legal drafts a notice that accurately reflects how data is collected and used at that moment. It gets approved, published, and largely forgotten. Meanwhile, marketing launches a campaign with a new tracking pixel. IT onboards a third-party analytics vendor. HR starts collecting biometric data for building access. None of it triggers a policy update, because privacy wasn’t in the room when the decisions were made.
“What usually happens is that policy is then posted, but the business keeps moving.”
Ryan Boos, Field Privacy Strategist, TrustArc
Over time, those small deviations compound. By the time a regulator looks, the notice bears little resemblance to operational reality, and that gap is exactly what enforcement actions are made of. California, the UK’s ICO, and EU data protection authorities have all demonstrated a clear pattern: companies that were found in violation weren’t necessarily doing something egregious. They just weren’t doing what they said they were doing.
Policy vs. Notice: It’s Not the Same Thing
One of the sharper insights from the webinar was Berta Balanzategui’s distinction between a privacy policy and a privacy notice, terms most organizations use interchangeably, but shouldn’t.
A privacy policy, in Balanzategui’s framing, is an internal governance document. It’s about controls, procedures, accountability frameworks, and regulatory compliance. The audience is the organization itself and, ultimately, regulators.
A privacy notice is something different. It’s a communication to the people whose data you hold; customers, website visitors, employees. Its purpose is transparency and trust.
The distinction matters because the two documents have different failure modes. A privacy policy that’s disconnected from operations creates legal and compliance risk. A privacy notice that doesn’t accurately reflect what the organization does erodes the consumer trust that privacy programs are built to protect.
“If none of them are embedded in the back-end operations, the privacy notice is going to be disconnected, incomplete, outdated, incorrect, and the company is going to be at risk.”
Berta Balanzategui, Deputy Chief Privacy Officer, General Electric
Where the Gaps Are Hiding
When asked where organizations most consistently underestimate their exposure, the webinar panelists pointed to four areas:
Consent and cookie tracking. Having a cookie banner isn’t the same as having a compliant one. Recent enforcement actions in California have targeted organizations whose cookies were firing before consent was collected, or continuing to fire after users opted out. The banner was there but the technical reality wasn’t.
Vendor and data sharing. Do you know what your vendors are doing with your data? Whether they’ve signed data processing agreements? Whether they’re selling data downstream or using it to train models? Third-party relationships are a significant source of notice drift, especially when procurement moves faster than privacy review.
Data retention. Balanzategui called this the most underestimated gap. Organizations tend to fear deleting data more than they fear keeping too much of it, but excessive retention is its own risk. If you hold data longer than your notice says you do, or longer than you need to, you’re exposed on both the compliance and breach sides.
AI and automated decision-making. Every organization is either deploying AI or fielding internal requests to do so. Privacy teams need visibility into where AI is being used, what data it’s touching, and whether that use is disclosed. If no one has come to you asking for a privacy impact assessment on an AI system, that’s not a good sign. It likely means AI is already in use and privacy just doesn’t know about it yet.
Getting Embedded Before the Gap Grows
The poll run during the webinar was telling: the number one blocker to keeping notices current was visibility; specifically, the disconnect between legal and compliance on one side, and the business operations that are constantly generating new data activities on the other.
The practical answer isn’t a committee. Both panelists were skeptical of steering committees as a fix for this problem. Committees, as Boos put it, are fashionable but not particularly effective. What actually works is embedding privacy into the operational processes where data decisions get made: vendor procurement, software development lifecycles, marketing campaign planning.
That means showing up before the pixel goes live, not after. It means regular touchpoints with marketing, IT, HR, and security; not annual policy reviews. It also means building repeatable processes and standard operating procedures so that the program doesn’t live in one person’s head.
Privacy champions (employees embedded in business units who can flag data activities before they become notice problems) came up repeatedly as a practical, scalable approach, particularly for smaller teams.
AI as Part of the Solution
There’s some symmetry in the fact that AI, one of the biggest sources of new notice obligations, is also becoming a meaningful tool for managing them.
TrustArc’s Ask Arc, grounded in the Nymity regulatory database, gives privacy teams a way to research regulatory requirements, surface relevant templates, and draft compliant notice language faster and with more confidence than a general-purpose search. As Boos described it, the difference is being able to point to a citable regulatory source rather than hoping what you found on a forum is accurate.
The technology doesn’t replace the privacy professional’s judgment. But for teams that are already stretched, it compresses the time between “what does this new law require?” and “here’s updated language for our notice.”
The Notice Is Never Final
The clearest takeaway from the webinar was the simplest: privacy is not a one-time task. A notice that was accurate when it was published will drift from reality if it isn’t actively maintained. The question isn’t whether drift will happen (it will) but whether your program is structured to catch it before it becomes a compliance gap, a regulatory finding, or a breach.
The organizations that manage this best are the ones where privacy is embedded early enough in business processes to stay current without heroic effort at the end of the year.
Interested in exploring how TrustArc helps organizations keep privacy notices accurate and audit-ready?
Visit our Privacy Program Management page