Only 45% of Product Hunt privacy policies name a legal basis

Ulf Aslak Lai photo Ulf Aslak Lai Published 11 August 2026 Updated 11 August 2026 AI drafted 6 min read
Only 45% of Product Hunt privacy policies name a legal basis Product Hunt series

Over 30 days in July and August 2026 I scanned 458 products that launched on Product Hunt. 397 of them published a readable privacy policy. I searched every one of those for two things: a legal basis for processing, and any statement about whether data leaves the EEA.

217 named no legal basis. 258 said nothing about transfers. Those are the two items GDPR added to a privacy policy, and they are the two most often missing.

This is post two of four built on this Product Hunt launch scan. Post one was about the cookies. This one is about what the privacy policies leave out, post three is about the vendors those policies never mention, and post four about what separates the startups that get this right.

How I scanned the policies

I took the top of Product Hunt's daily leaderboard for 30 consecutive days, 12 July to 10 August 2026, followed each launch through to the product's own website, and read whatever legal pages the site served. 458 distinct domains went into the analysis, with median upvotes of 136, so these were launches that landed rather than launches nobody saw. The first post explains the full method.

Every check was a deterministic string test. No language model made a judgement anywhere in the dataset, and every finding carries the evidence string that produced it. These are machine-checkable observations about public pages. The words were there or they were not. They are not legal verdicts about anyone, and I am not naming the products, because the pattern is the point and the identities add nothing to it.

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, so your legal pages always match what you actually ship.

Try for free

What did the privacy policies leave out?

397 of the 458 sites, 86.7%, published a readable privacy policy, at a median length of 1,143 words. Publishing a document was not the hard part. Here is how often each of seven items was missing from those 397.

What the 397 published privacy policies left out
Data leaves the EEA65.0%258/397
A legal basis54.7%217/397
The reader's rights25.9%103/397
A retention period25.7%102/397
An effective date22.9%91/397
A contact route17.6%70/397
Who receives the data13.1%52/397
Share of the 397 sites that published a readable privacy policy.

The two items that survived best are the two a US privacy notice already has. A way to contact the company was present in 82.4% of these policies, and a section naming who else receives the data in 86.9%. US privacy practice is organised around notice and choice: here is what we collect, here is what we do with it, here is how you opt out. That structure has no slot for the ground on which you are permitted to process at all. So a document that follows the US shape faithfully still comes out with the field blank, and Article 13(1)(c) makes you publish "the purposes of the processing for which the personal data are intended as well as the legal basis for the processing" 1. Nobody skipped a step. The template never had the step.

Effort did not close the gap. The longest document with no legal basis anywhere in it ran 9,497 words, and reads like the work of people who do this properly. Another published 3,204 words with the same gap. Ten thousand words, and still no answer to the question Article 6 asks, because that answer lives in your product decisions rather than in the drafting.

Length does explain part of this. Every one of the seven checks tests for the presence of text, and among the 397, the median policy failing the legal-basis check ran 726 words against 2,076 for the ones passing it. But a pure length effect would push all seven rates in the same direction, and it does not: recipients is missing from 13.1% of exactly the corpus where legal basis is missing from 54.7%. Same documents, four times the failure rate on the item GDPR added.

55 of the 397 policies, 13.9%, ran under 400 words. One ran 259 words: no legal basis, no retention period, nothing about where data goes, on a product whose homepage sells an AI assistant. 259 words cannot carry the questions Article 13 asks. At the other end, one policy still carried an unfilled template placeholder, the literal string [company], inside an otherwise 3,985-word document. One out of 397. It proves nothing, it is just funny.

Sites marketing in the EU do better, but not by much. Most Product Hunt launches are American and sell to Americans, and a company genuinely offering nothing to anyone in the Union is not answering to Article 13 at all. So take the 160 sites carrying explicit evidence they market in the EU: prices in euro, an EU language option, or an EU country named on the page. Among those, 35.5% of published policies still state no legal basis and 50.7% still say nothing about data leaving the EEA. Better than 54.7% and 65.0%, and still around half the documents describing a European offer without the European parts.

What to search your own policy for

Open the privacy policy on your own domain, not the draft in your repository, and run two searches.

  • You get a hit. Read the sentence. Check whether it names a ground from Article 6(1) or only says the phrase.
  • You get nothing. Nobody has chosen a basis yet, and choosing one is the task. The document comes after.

For a typical B2B product the account runs on performance of a contract, the product analytics and abuse prevention run on legitimate interests, and the marketing email runs on consent. Writing down which purpose sits on which ground is work you do once, and it settles a good part of the security questionnaire your first enterprise buyer will send.

Search 2: "EEA", "outside the European", "third country", "standard contractual clauses"

If all four come back empty, your document takes no position on where your users' data goes. That is a strange thing to publish when your stack almost certainly moves it.

If both searches come back empty, the likeliest explanation is that your document was drafted for a different jurisdiction, and you inherited its blind spots along with its structure.

One thing the search cannot settle: a policy silent on transfers may be hiding a transfer the team knows about, or it may be a product where nobody has noticed the data moves at all. The two look identical in the text, and the only way to tell them apart is to watch what the site does on the wire. That is the next post: a script tag creates an international transfer your privacy policy never mentions.

FAQ

One of the six grounds in Article 6(1): consent, contract, legal obligation, vital interests, a public interest task, or legitimate interests. You pick one per purpose, and Article 13(1)(c) makes you publish which one you picked.
Where you intend to transfer data outside the EEA, Article 13(1)(f) makes you say so and name what makes it lawful, either an adequacy decision or the safeguard you rely on. The safeguards sit in Article 46(2), and the one most startups end up on is point (c), the standard data protection clauses adopted by the Commission, which everyone calls standard contractual clauses.
Length is not the signal. In my sample the longest document with no legal basis anywhere in it ran 9,497 words, and a 3,204-word policy on another product had the same gap.
Not automatically, and I did not make that judgement about anyone. These are text-presence checks on public pages. But if GDPR applies to you, the information in Article 13 has to reach the reader, and a missing legal basis usually means nobody chose one.
Article 3(2) reaches a controller outside the Union where the processing relates to offering goods or services to people in the Union, whether or not they pay. Selling to Europe is enough; having a European office is not required.

References

  1. Regulation (EU) 2016/679 (GDPR), including Articles 3, 6, 13 and 46 - accessed 11 Aug 2026

About the author

Ulf Aslak Lai

Ulf Aslak Lai

Co-founder, Chief Technology Officer

Ulf is Co-founder and CTO at Lawcel. He leads engineering architecture for connectors, analysis pipelines, and the safeguards needed when automation touches regulated customer content.

  • Platform architecture
  • Data governance
  • ML/AI systems
GDPR

Only 17% of Product Hunt launches ask when they set tracking cookies

I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026, loading each site from an EU location with an empty cookie jar. 292 stored tracking cookies, but only 50 of those (17%) did that after obtaining my consent. Filtering for EU based startups didn't improve this static significantly (26%).

Drift

60% of Product Hunt sites load a foreign vendor their policy never mentions

I scanned 458 products launched on Product Hunt over 30 days, loading each from inside the EU and reading its legal pages. 233 both publish a privacy policy and load a third-party service in the visitor's browser, but 139 of those (59.7%) say nothing at all about international transfers. The transfer starts when somebody pastes a snippet, not when somebody signs a contract.

Strategy

The most upvoted Product Hunt launches are no more compliant than the least

I scanned 458 products launched on Product Hunt over 30 days in 2026 and split them by upvotes. Across a range from 4 to 999 upvotes, the top and bottom quartiles came out 1.7 points apart on critical gaps. Splitting the same 458 on whether a site shows it markets in the EU moved everything: 5.0% published no policy against 17.8%.

GDPR

Remove "we may" or "possible" from your privacy policy. EU regulators call for plain language.

Search your own privacy policy for "we may". I did it to 336 published policies from Product Hunt launches and 231 of them had it. The EU data protection authorities' transparency guidance names that word, with "might", "some", "often" and "possible", as wording to avoid. Every hit is a claim about your product that somebody has to go and check.