Evidence review
What to inspect before changing anything
Start with the delivered website and the real user journey. Record the current state so the team can distinguish an observed problem from an assumption and compare the same surface after deployment.
- 01Inventory required notices and jurisdictions
- 02Compare policy claims with product behavior
- 03Check entity names, contacts and effective dates
Implementation
A practical improvement plan
Make the smallest coherent change that solves the observed problem. Keep normal code review, accessibility, security and product checks in the loop instead of optimizing for the scan alone.
- 01Use qualified legal review for the actual business
- 02Connect policies to product choices and consent
- 03Maintain ownership and a change process
Verification
How to verify the result
Verification should test the intended outcome and the most likely regression. Use the production delivery path whenever headers, caching, rendering or third-party services affect the result.
- 01Follow every policy link from the product
- 02Exercise data and cancellation rights operationally
- 03Review after material feature or vendor changes
Common pitfall
A shortcut to avoid
Publishing a generic policy may create obligations or claims that do not match how the product actually operates.
Further reading
Primary guidance and references
These sources provide standards, security guidance or the interpretation framework used to keep this guide bounded. Product-specific implementation still requires review in the actual codebase.