A mailing list is the smallest possible piece of personal data processing and it still owes a privacy policy. The good news is that the policy is genuinely short: six lines cover it, and the failures are almost always omissions rather than errors.
What you collect, including what you did not ask for
The email address, obviously. Also the name if the form asks, the source of the sign-up, and the behavioural data your mailing tool collects by default: opens, clicks, and frequently the IP address and rough location behind them. That last group is the one policies forget, because nobody chose to collect it.
Why, in purposes rather than in general
To send the newsletter is a purpose. To send offers is a second one. To segment the list by what people clicked is a third, and it is the one people object to when they discover it, so it is the one worth stating plainly.
Who else receives it
The mailing platform, and anything connected to it: an analytics tool, a CRM sync, an advertising audience upload. The audience upload is the one that can turn an ordinary list into sharing under California law, and it is usually switched on by a marketer rather than decided by anybody.
How long you keep it
For as long as somebody is subscribed, plus a stated period afterwards for the suppression list. Say that the suppression list exists: people who unsubscribe and then hear that you still hold their address react much better when the policy told them in advance.
How to leave
The unsubscribe link, and a human route as well. Under 16 CFR Part 316 an opt-out must be honoured within 10 business days and must not require anything beyond an email address or a visit to a single page.
How to reach you
An address a person can write to and get an answer from. Not a form that emails nobody, and not a support queue that closes privacy questions as out of scope. This is the cheapest line in the whole policy and the one that most often converts an irritated subscriber into a two-email conversation instead of a complaint.
Questions people ask about email list privacy policy
Does a personal newsletter need one?
If you collect email addresses, yes in substance, whether or not any particular statute reaches you. Six lines on a page is not a burden and it is the difference between a professional operation and one that looks careless.
Can we link to our main privacy policy instead?
Yes, provided the main policy actually covers the list, including the opens and clicks. Many do not, because they were written for the product and never revisited when marketing arrived.
What if we bought the list?
Then the policy is the least of it. A purchased list has no lawful basis under the GDPR and is a CAN-SPAM problem waiting to happen in the US. The honest answer is not to send to it.