Included in the scan cycle
A privacy policy is a factual claim, and it expires quietly.
Yours says what your website collects, who it sends data to, and what a patient can ask you to do about it. It was true the day it was written. Then a plugin was updated, a chat widget went in, an agency added a pixel, and a new state law took effect — and nobody edited a word. A policy that has become false looks exactly like one that is still accurate. Every scan cycle, we check whether yours still describes the site you actually have.
Runs on the existing scan cycle · no action required for a flag to raise · last reviewed 27 July 2026
- Stale after
- 12Months without a revision, at which point the notice is flagged for review on every subsequent cycle.
- Tracked laws
- 20US states with a comprehensive consumer privacy law in effect, each with its own effective date.
- Real finding
- 5Third parties running on one live practice site that its current, in-date policy never mentions.
- Legal conclusions
- 0Drawn anywhere in the report. We record what is observable. What it means is your counsel's call.
01 — HOW A TRUE NOTICE BECOMES FALSE
The document stands still while everything it describes moves
There are only three ways a privacy notice goes out of date, and none of them involve anyone touching the notice. The site changes — a tool is added and starts collecting something the policy never mentioned. A vendor changes — an analytics platform is swapped and the named third party is now a company you no longer use. Or the ground changes — a state passes a law that takes effect, and it was not written into a document last revised two years earlier.
The third one is the least visible and it has been moving fast. A policy drafted in the middle of 2023 was written for a country where four states had a comprehensive privacy law. It is now twenty.
US states with a comprehensive consumer privacy law in effect
Cumulative count by effective date. Each step is a law that commenced, not a bill that passed.
Source: the effective-date table the scan cycle reads from, covering CA, VA, CO, CT, UT, OR, TX, FL, MT, DE, IA, NE, NH, NJ, TN, MN, MD, IN, KY and RI. This table is pending attorney review and drives a staleness observation only. It never asserts that a particular law applies to a particular practice — that determination belongs to your counsel, not to a scanner.
A stale policy and a current one are visually identical. The only way to tell them apart is to compare the document against what the website actually did.
02 — WHAT YOU ACTUALLY RECEIVE
A dated observation sheet, not a to-do list someone has to chase
On every cycle the scanner already loads the site and records what runs. The notice check reuses that same observation: it reads the policy page, extracts its revision date, and compares the third parties the document names against the third parties the browser loaded. Below is the real shape of that output, from a live scan of a practice website — the finding is genuine and it is more common than the obvious failure. The policy here is current. It is also incomplete.
Privacy notice observations
rhrli.com/privacy-policy
Cycle recorded 24 July 2026 · append-only, superseding nothing
- Policy located
- Found Discovered by crawl rather than by assuming a conventional path. An earlier build of this check searched only the pages already in the scan budget and reported an existing policy as absent — a false clean, found and fixed before it shipped.
- Age
- Current Last revision date parsed from the document itself. Flagged at twelve months.
- Third parties disclosed
- 1
- Google Analytics
- Third parties observed
- 6 — 5 undisclosed
- Google Analytics
- Meta Pixel
- Google Ads
- Google Tag Manager
- Microsoft Clarity
- LinkedIn Insight
- Disclosed but absent
- 0 The inverse failure: a named vendor that no longer runs on the site. It is reported at low severity, because describing collection you no longer perform is a different kind of inaccuracy from the one above.
- Laws effective since last revision
- Listed for review Every tracked state law that commenced after the policy's own revision date, named with its date. Listed as a fact about timing. No claim is made that any of them applies to this practice.
The obvious failure is a policy nobody has updated in three years. The common one is this: a policy that is current, well-written, and describes one of the six things the site is actually doing.
03 — THE LINE WE DO NOT CROSS
Observations are ours to make. Conclusions are not.
This distinction is written into the code, not just the marketing. "A law took effect after your policy was last updated, and the policy does not mention it" is a fact anyone can verify. "Your policy is non-compliant" is a legal determination, and we are not entitled to make it. Every string in the report has to stay on the factual side of that line, and the build fails if certain words appear in the output at all.
What the report says
Facts with a date attached
- What loaded. Named scripts, pixels and cookies observed on a real page load.
- What the document says. The third parties the policy names, and its stated revision date.
- Where those two disagree. Present but undisclosed, or disclosed but absent.
- What changed in the meantime. Tracked laws that commenced after the policy's own date.
What it will never say
Determinations that need a lawyer
- That you are compliant, or that any product makes you so.
- That a specific law applies to you. Scope depends on facts about your practice a scanner cannot see.
- What your policy should say. We will not draft the language; that is your counsel's work and their liability.
- That a finding is a violation. A gap between document and behaviour is a fact. Its consequence is a legal question.
Consential is a consent management platform. It is not a law firm and not an insurance provider, and use of it does not guarantee compliance with any regulation. That statement is in the footer of every page on this site for the same reason it is here. The full position is on the risk disclosure page.
04 — WHY IT SITS NEXT TO THE CONSENT RECORD
The question is not what your policy says. It is what it said that day.
If a patient's consent is ever questioned, the useful artifact is not the current policy. It is the version that was live at the moment they made the choice, tied to the record of that choice. Notice management keeps every version dated and superseded rather than overwritten, on the same append-only footing as the consent record itself, so the two can be read together instead of being reconciled after the fact.
Two third parties added to disclosure. Raised by the cycle report above; drafted and approved by the practice's counsel, not by us.
Three state laws commenced. Flagged as a timing observation on the first cycle after the date.
Analytics vendor swapped. The previous vendor stayed named in the policy for four months before anyone noticed.
Illustrative structure, not a customer's ledger. It shows the shape of what is retained: an effective date, a version, and a reason. Consent records themselves are held under stricter conditions described on the security page.
05 — WHAT IT COSTS
It rides a cycle you are already paying for, so it costs nothing extra
Monthly
Included at every level no add-on, no upsell
This check runs on the scan cycle that is already happening. It needs no new infrastructure, no additional access, and no extra work from you, so charging separately for it would be charging for the same visit twice. It is in the consent plan and in the bundle, at both the list and managed-client rates. Plan pricing is on the pricing page, where it appears as "script drift and policy staleness checks each cycle."
- Included
- Every cycle report, version retention, and the effective-date comparison.
- Also included
- Additional domains on the same practice, each watched on the same cycle.
- Not available at any price
- Drafting the policy language. That is your attorney's work, and deliberately so.
06 — WHAT THIS IS NOT
Four things it deliberately refuses to do
-
It does not write your privacy policyGenerated legal language that nobody qualified has read is worse than a stale policy, because it looks authoritative. We surface what changed; your counsel writes the words.
-
It is not a template generatorThere are cheap tools that assemble a policy from a questionnaire. They describe the site you told them about, which is the exact failure this check exists to catch.
-
It does not require anyone to act for a flag to raiseThe observation generates on schedule whether or not the practice reads it. A feature that only works if someone remembers to run it is a to-do list, not a monitor.
-
It does not read anything behind a loginOnly pages a visitor could reach are fetched. No patient area, no portal, and no patient data of any kind enters this process.
Find out whether your policy still describes your website.
The free scan reads what your site actually loads. Put that list next to your current privacy policy and the gap, if there is one, takes about a minute to see for yourself. Most practices are surprised by which vendors are on the page, not by the date on the document.
Related: consent mode implementation, state privacy laws, written up one by one, and what this product does not do.