Privacy and Data Protection Law Editing and Proofreading Services
A privacy notice is one of the few legal documents graded on whether ordinary people can read it. Most legal writing is judged by other lawyers, and difficulty carries no penalty beyond irritation. Here a regulator can look at a paragraph, conclude that the person it was written for would not understand it, and treat that as a shortfall in the obligation rather than a matter of style. Clarity stops being a courtesy and becomes part of what the document has to do.
Privacy notices and consent language make up most of the work that reaches us in this field. Data processing agreements arrive with them, along with records of processing, impact assessments, and breach notifications addressed to regulators and to affected individuals. Cross-border transfer documentation, cookie and tracking disclosures, and internal handling procedures come through the same files.
Both of the regimes our clients write under say so directly. Information given to a person about their own data must be provided "in a concise, transparent, intelligible and easily accessible form, using clear and plain language",1 and disclosures to consumers "shall use plain, straightforward language and avoid technical or legal jargon."2 The California rules go on to require a format that is readable on smaller screens and notices that follow recognized accessibility standards.2 None of that describes a preference about tone. It describes a document that has to work when it is read once, on a phone, by somebody who did not want to read it.
The interesting difficulty is that plain language and accurate language pull apart under pressure. "We may share your information with service providers" is vague, and the instinct is to tighten it. But "we share your information with service providers" is a different statement, and "we may" was possibly load-bearing. Turning a nominalization into a verb usually helps; turning a hedge into a commitment changes what the business has promised. So the work runs in two directions at once: sentences carrying three obligations get broken into three, passive constructions that hide who is acting get an actor, and defined terms get used consistently instead of drifting into synonyms. Where making a sentence clearer would also make it say something new, it comes back as a question rather than as an edit.
Vagueness of a particular kind is worth naming because it is so common. A notice says information may be shared with third parties, and never says which, or why. It says data is kept for as long as necessary, without saying necessary for what. It says appropriate safeguards are in place. Each of these is grammatical, readable, and tells the reader nothing they can act on. An editor cannot supply the missing answer, because the answer is a fact about the business. What an editor can do is mark every place the document promises specificity and then withholds it, so somebody who knows can decide whether to fill it in.
Breach notifications ask for something different again. The regulator's copy is on a clock: notification is due "without undue delay and, where feasible, not later than 72 hours after having become aware of it", and where it is later than that, the notice must carry the reasons for the delay.3 The same article sets out what it must contain, including the nature of the breach with the categories and approximate numbers involved, a named contact point, the likely consequences, and the measures taken or proposed.3 Those four elements make a natural structure, and a draft that buries one of them inside a paragraph about something else is harder to check under time pressure than it needs to be.
The letter to the affected person is a separate act of writing. It must describe the breach "in clear and plain language",4 and it is read quickly, by someone who is worried, usually on a phone, and often before the organization has finished finding out what happened. It should say what occurred, what information was involved, what is being done, and what the reader should do now, in that order and without the hedging that reads as evasion. Sentences written to be legally unassailable frequently read as though something is being concealed, which is the opposite of what the letter is for. We do not remove qualifications that carry meaning. We do point out where a qualification has been added out of habit and is costing the document the reader's trust.
Consistency across the file matters as much as any single document. The retention period in the notice, the period in the processing agreement, and the period in the records of processing are three statements about one practice, and they are usually drafted at different times by different people. The same is true of the categories of data, the list of sub-processors, and the description of what a cookie banner does. We read these against each other and report the differences. Which version is correct is not ours to choose.
We do not assess legal sufficiency. Whether a lawful basis is made out, whether a transfer mechanism holds, whether a breach is notifiable, and whether a notice meets the standard in a given jurisdiction are decisions for counsel and the privacy team, and they reach us made. We do not add a purpose, narrow a disclosure, or resolve a contradiction between two documents by keeping the one that reads better.
Everything sent to us is treated as confidential, including live incident material, unpublished notices, and the internal procedures behind them.
References
- European Union, General Data Protection Regulation (Regulation (EU) 2016/679), Article 12(1), Transparent information, communication and modalities for the exercise of the rights of the data subject. EUR-Lex. https://eur-lex.europa.eu/eli/reg/2016/679/oj ↩
- California Privacy Protection Agency, California Consumer Privacy Act Regulations, 11 CCR section 7003, Requirements for Disclosures and Communications to Consumers, approved 29 March 2023. https://cppa.ca.gov/regulations/consumer_privacy_act.html ↩
- European Union, General Data Protection Regulation (Regulation (EU) 2016/679), Article 33, Notification of a personal data breach to the supervisory authority. EUR-Lex. https://eur-lex.europa.eu/eli/reg/2016/679/oj ↩
- European Union, General Data Protection Regulation (Regulation (EU) 2016/679), Article 34(2), Communication of a personal data breach to the data subject. EUR-Lex. https://eur-lex.europa.eu/eli/reg/2016/679/oj ↩
A worked example: Breach Notification to Affected Individuals
Data protection, notification letter to affected data subjects
This letter is read once, quickly, by somebody who has just learned that their information was exposed. The regulation asks that it describe the breach in clear and plain language, and the practical test is simpler than that: can the reader tell, in the first ten seconds, what happened to their data and what they are supposed to do about it. The draft below is accurate and answers neither question until the fourth sentence. It also opens by valuing the reader's privacy, which is the sentence every one of these letters opens with and which the circumstances make difficult to read straight. Every fact in the revision comes from the incident record reproduced in both panels, and the two points the record leaves open are put to the privacy team rather than settled by the editor.
Before
SPECIMEN, PREPARED BY EDITFAST FOR ILLUSTRATION. NOT A REAL NOTIFICATION.
Meridian Harbor Books (fictitious), notification to affected customers.
EXTRACT FROM THE INCIDENT RECORD (reproduced unchanged in both panels)
IR-1 A misconfigured storage bucket exposed order records between 4 and 19 May 2026.
IR-2 Exposed fields: name, email address, delivery address, order history.
IR-3 Payment card numbers were not stored in the affected system and were not exposed.
IR-4 Passwords were not stored in the affected system and were not exposed.
IR-5 The bucket was closed on 19 May 2026. Access logs are being reviewed and it is not yet established whether the data was downloaded by anyone.
IR-6 4,180 customers are affected.
IR-7 The supervisory authority was notified on 21 May 2026.
IR-8 The company has not decided whether to offer identity monitoring. The editor is not asked to advise.
IR-9 Counsel has not settled whether the letter should state that the data may have been downloaded. The editor is not asked to advise.
Dear Customer,
At Meridian Harbor Books we take the privacy and security of our customers' personal information extremely seriously, and we are committed to maintaining the trust you place in us. We are writing to inform you of an incident that may have affected certain information relating to your account with us. Following a routine review of our systems, we became aware that a storage resource utilized by our order management platform had been configured in such a manner that certain records may potentially have been accessible externally for a limited period. Upon becoming aware of this matter we took immediate steps to remediate the configuration and engaged in a comprehensive review. We wish to reassure you that we have no reason to believe that any of your information has been misused in any way. The categories of information potentially involved may have included certain details relating to your name, contact details and order history. We apologize for any inconvenience or concern this may cause and thank you for your continued patience and understanding.
After
SPECIMEN, PREPARED BY EDITFAST FOR ILLUSTRATION. NOT A REAL NOTIFICATION.
Meridian Harbor Books (fictitious), notification to affected customers.
EXTRACT FROM THE INCIDENT RECORD (reproduced unchanged in both panels)
IR-1 A misconfigured storage bucket exposed order records between 4 and 19 May 2026.
IR-2 Exposed fields: name, email address, delivery address, order history.
IR-3 Payment card numbers were not stored in the affected system and were not exposed.
IR-4 Passwords were not stored in the affected system and were not exposed.
IR-5 The bucket was closed on 19 May 2026. Access logs are being reviewed and it is not yet established whether the data was downloaded by anyone.
IR-6 4,180 customers are affected.
IR-7 The supervisory authority was notified on 21 May 2026.
IR-8 The company has not decided whether to offer identity monitoring. The editor is not asked to advise.
IR-9 Counsel has not settled whether the letter should state that the data may have been downloaded. The editor is not asked to advise.
Dear Customer,
Some of your information held by Meridian Harbor Books was exposed. We are writing to tell you what happened, what was involved, and what we suggest you do.
What happened. Between 4 and 19 May 2026, one of our storage systems was set up incorrectly and the order records it held could be reached from outside the company. We closed it on 19 May. We are reviewing the access logs to establish whether anyone actually took the data, and we will write to you again when we know.
What was involved. Your name, email address, delivery address, and order history. Payment card numbers and passwords were not held in this system and were not exposed.
What we have done. We closed the system on 19 May and notified the supervisory authority on 21 May. We are reviewing the access logs and have changed how storage of this kind is configured and checked.
What you can do. Be cautious about emails that appear to come from us, particularly any that ask you to confirm details or follow a link. We will never ask for your password. If you use the same password anywhere else, change it there.
If you have questions, contact [name and contact details of the data protection officer or other contact point].
[Two points for the privacy team before this goes out.
1. IR-5 records that whether the data was downloaded is not established, and IR-9 records that whether to say so is counsel's decision. The draft above says the logs are under review and does not state that the data may have been downloaded. Confirm that is the position you want, or give us the sentence you want used.
2. IR-8 records that identity monitoring has not been decided. There is no offer in this letter. If one is made, it belongs under "What you can do" and we will add it.]
What changed, and why
| Was | Now | Reason |
|---|---|---|
| At Meridian Harbor Books we take the privacy and security of our customers' personal information extremely seriously | Some of your information held by Meridian Harbor Books was exposed. | The letter exists because that sentence was not true of the storage bucket, and every reader knows it. Opening with the fact is what the reader came for and is the only opening that does not spend its first line on the company. |
| We are writing to inform you of an incident that may have affected certain information relating to your account | We are writing to tell you what happened, what was involved, and what we suggest you do. | The original announces that a letter is being sent. The revision tells the reader what the next four paragraphs contain, which is what lets them stop reading once they have what they need. |
| a storage resource utilized by our order management platform had been configured in such a manner that certain records may potentially have been accessible externally for a limited period | one of our storage systems was set up incorrectly and the order records it held could be reached from outside the company | Forty-one words to say what fourteen say, with the actor removed. IR-1 gives the dates, so a limited period becomes 4 to 19 May. |
| (no headings) | What happened. What was involved. What we have done. What you can do. | The four questions a reader has, in the order they occur, each answerable in isolation. A person scanning on a phone can find the one that concerns them. |
| The categories of information potentially involved may have included certain details relating to your name, contact details and order history. | Your name, email address, delivery address, and order history. Payment card numbers and passwords were not held in this system and were not exposed. | IR-2 lists the fields exactly, so may have included certain details relating to is three hedges around a known list. IR-3 and IR-4 record two significant exclusions the draft never mentions, and they are the first thing a reader wants to know. |
| we have no reason to believe that any of your information has been misused in any way | We are reviewing the access logs to establish whether anyone actually took the data, and we will write to you again when we know. | IR-5 records the question as open. No reason to believe reads as reassurance and is compatible with having no information either way, which is the actual position. Saying the position plainly, with a commitment to follow up, does not overstate what is known. |
| Upon becoming aware of this matter we took immediate steps to remediate the configuration and engaged in a comprehensive review. | We closed the system on 19 May and notified the supervisory authority on 21 May. We are reviewing the access logs and have changed how storage of this kind is configured and checked. | IR-5 and IR-7 give both dates. Immediate steps and comprehensive review describe effort; the dates describe what was done and can be checked. |
| (nothing for the reader to do) | Be cautious about emails that appear to come from us ... If you use the same password anywhere else, change it there. | IR-2 records that email and delivery addresses were exposed, which is what makes convincing phishing possible. A notification with no action for the reader leaves them with alarm and no outlet for it. |
| (no contact point) | contact details of the data protection officer or other contact point | A named contact is one of the elements the notification is required to carry, and it is missing from the draft entirely. |
| We apologize for any inconvenience or concern this may cause and thank you for your continued patience and understanding. | (removed) | Inconvenience is the wrong word for the event, and thanking the reader for patience they have not been asked for closes the letter on the company again. If an apology is wanted it belongs at the top, in the company's own words, and that is a decision for the privacy team rather than a line an editor supplies. |
Specimen prepared by EditFast for illustration only. Not a real document, record or filing. Any resemblance to an actual organization, person or record is unintended. Not legal, regulatory, clinical or professional advice.
Key Privacy and Data Protection Law vocabulary
- Personal information
- the California term for data that identifies or could reasonably be linked to a person or household. Broader than most drafters expect, and not interchangeable with the European term below.
- Personal data
- the European term for information relating to an identified or identifiable person. A document that uses both terms should say which regime each belongs to rather than treating them as synonyms.
- Data subject
- the person the data is about. In consumer-facing text this is simply "you", and a notice that says "data subject" to its own customers has slipped into the register of the regulation it is complying with.
- Data controller
- whoever decides why and how the data is processed. The role, not the size of the company, determines most of the obligations.
- Data processor
- whoever processes data on a controller's instructions. Getting this label wrong in a contract misassigns duties that follow the label.
- Lawful basis
- the ground relied on to process data at all, such as consent, contract or legitimate interests. One purpose, one basis; a notice listing several bases for one activity has not decided.
- Consent
- a freely given, specific and informed agreement to processing. It has to be as easy to withdraw as to give, which is a promise the notice makes and the interface has to keep.
- Legitimate interests
- a basis relying on the organization's own interests, weighed against the person's rights. The balancing has to be documented, and the notice should say what the interest actually is.
- Purpose limitation
- the principle that data collected for one purpose is not quietly used for another. Most notices are vulnerable here, because the purposes are written broadly enough to cover anything.
- Data minimization
- collecting only what the stated purpose needs. A form asking for a date of birth with no purpose that requires it is the everyday example.
- Retention period
- how long data is kept. "As long as necessary" is not a period, and this is the field most likely to be stated three different ways across a notice, a contract and a records register.
- Data processing agreement
- the contract between controller and processor setting out what may be done with the data. Its terms should match what the public notice says, and often do not.
- Sub-processor
- a processor engaged by a processor. The chain has to be disclosed and approved, and lists of sub-processors go stale faster than any other part of the file.
- Cross-border transfer
- moving personal data to another country. Permitted only through a recognized mechanism, which the documentation has to name rather than gesture at.
- Standard contractual clauses
- pre-approved contract terms used to legitimize a transfer. They are adopted as issued; text edited into the clauses themselves is a substantive change, not a stylistic one.
- Adequacy decision
- a formal finding that another country protects data well enough for transfers to proceed without extra safeguards.
- Privacy notice
- the public document telling people what is done with their data. The one legal document assessed partly on whether an ordinary reader can understand it.
- Privacy impact assessment
- a structured review of a processing activity's risks, carried out before it starts. Written for an internal reader and a regulator, so its register is quite different from the notice.
- Records of processing
- the internal register of what data is held, why, and for how long. Not published, but read against the notice by anyone auditing the file.
- Data breach
- the loss, exposure, alteration or unauthorized disclosure of personal data. Wider than a hacking incident; an email sent to the wrong recipient qualifies.
- Breach notification
- the formal report of a breach. The regulator's version runs on a 72-hour clock and has a required content list; the version sent to affected people is a different document with a different job.
- Right of access
- a person's right to obtain a copy of their data and information about how it is used. The response is a document too, and it is read closely.
- Right to erasure
- the right to have data deleted in defined circumstances. Not absolute, and a notice that describes it as absolute has overpromised.
- Data portability
- the right to receive your data in a structured, commonly used, machine-readable form and have it moved elsewhere.
- Anonymization
- stripping data of identifiers so thoroughly that no one can be identified from it. Once genuinely anonymous it falls outside the rules, which is why the word is claimed more often than it is earned.
- Pseudonymization
- replacing identifiers with a key held separately. A safeguard, not an exemption; the data is still personal data. The two words are routinely swapped in drafts, and they mean different things.
- Supervisory authority
- the regulator overseeing data protection in a jurisdiction, and the recipient of the breach notification.
Privacy and Data Protection Law Word Challenge
Even seasoned pros miss these — give it a shot.