Skip to content
The Cost of War

Analysis

Privacy Policy

Minimum data collection, privacy-conscious analytics and data-deletion contact instructions.

Replace with jurisdiction-reviewed privacy text before launch.

Researched evidence

What the current sources show

These cards summarize official or primary sources. Open each source for publication dates, limitations and what the source does not prove.

Analysis

Minimum data is the privacy baseline

High confidence

The GDPR and ICO guidance point to the same operational rule: collect only data that is needed for a stated purpose, review it, and delete what is no longer needed. For this site, that means contact, newsletter and advocacy tools should not ask for phone numbers, addresses, political details or sensitive war-related testimony unless a specific published workflow requires them.

Analysis

Privacy information has to be specific, not generic

High confidence

ICO transparency guidance says people should be told who collects the data, why it is collected, how long it is kept, who receives it and what rights they have. A launch-ready privacy page therefore needs named operator details, the exact form fields in use, retention periods, mailing-list provider details, hosting or analytics vendors, and a working contact route for privacy requests.

Analysis

Analytics must be narrow and documented

High confidence

ICO cookie guidance distinguishes strictly necessary technologies from analytics, advertising and other non-essential storage or device access. The safer editorial position is to avoid advertising trackers, document every cookie or local-storage purpose, and add consent controls before any non-essential analytics or third-party tracking is enabled.

Analysis

Deletion and security need an actual workflow

High confidence

The sources do not support a vague promise to respect privacy. They require practical controls: know what data exists, limit access, keep it only while needed, dispose of it securely, and give readers a clear route to request correction, deletion or review. Until submissions are enabled, the page should state that the MVP does not store form submissions.

Sections

Analysis

Data minimisation

High confidence

The site should collect the least information needed for a specific user-facing purpose. In the current MVP, newsletter and letter tools run in the browser; they should not ask for phone numbers, addresses, political affiliation, identity documents or war-related testimony unless a separately published workflow explains why those details are necessary.

Any future collection should name the purpose at the point of entry, keep fields optional unless they are required, and review retained records on a schedule. Data that is no longer needed should be deleted, not kept because it might be useful later.

Key points

  • Ask only for fields needed to complete the visible action.
  • Keep sensitive war-related testimony out of ordinary forms.
  • Review stored records and delete data that no longer has a purpose.
  • Update this page before connecting new forms, vendors or mailing lists.

Analysis

Analytics

High confidence

The MVP should avoid advertising trackers and cross-site profiling. The current interface uses local browser storage for preferences such as cookie-notice acceptance, selected language and reduced-motion choice; those settings should stay on the device unless a future feature clearly explains otherwise.

If analytics is enabled later, the page should list the provider, what is measured, whether cookies or similar storage are used, the retention period, any sharing and the consent controls for non-essential tracking. Aggregate traffic counts are different from individual profiling and should be described separately.

Key points

  • Do not add advertising trackers or cross-site profiling by default.
  • Document each cookie, local-storage key or similar browser setting.
  • Add consent controls before non-essential analytics or third-party tracking.
  • Publish analytics provider, purpose, retention and sharing details before launch.

Analysis

Forms

High confidence

Forms should let a reader participate without giving unnecessary personal details. The current newsletter demo validates an email address, preferred language and consent in the browser; the letter generator produces editable text locally and does not send messages automatically.

When a real submission endpoint is added, the form should say who receives the record, what fields are required, how long data is kept, whether a processor handles it and how a person can withdraw, correct or delete their data. Contact and advocacy forms should not invite confidential testimony through ordinary email.

Key points

  • Mark required and optional fields clearly.
  • Treat generated letters as local drafts, not automatic submissions.
  • Name any future form processor, retention period and purpose.
  • Do not collect sensitive personal data through ordinary public forms.

Analysis

Deletion requests

High confidence

A deletion request needs a practical route and enough context to find the record without collecting more personal data than needed. Until persistent submissions are enabled, the page should state that the MVP does not store contact-form entries, generated letters or newsletter signups on the server.

Privacy questions can be sent to admin@thecostofwar.net with a clear subject line and the interaction, subscription, message or published item involved. If future systems store newsletter records, messages or analytics identifiers, the site should explain correction, deletion and review requests, expected handling, identity checks and any legal or editorial retention limits.

Key points

  • Provide a working privacy contact route.
  • Collect the minimum details needed to locate the record.
  • Explain identity checks and response expectations before data is stored.
  • Document when legal, security or editorial reasons may limit deletion.

Features

  • No invasive advertising trackers
  • Accessible spam protection
  • Secure headers
  • Contact route