The main issue is that a privacy policy isn’t a generic disclaimer. It must describe how a website ACTUALLY handles personal data. And that is not defined by IPS. It’s defined by how the owner acts in regards to personal data, which settings they chose in the ACP (e.g. regarding IP storage), which of the many possible 3rd-party services one uses (Google Analytics, Cloudflare, Zapier connections …), how the hosting company stores data and so on. None of that can be covered in a “standard privacy policy”. It’s all highly specific to a certain website. As a result, it’s probably better to not even have a standard privacy policy. It might do more harm than good by giving users the false impression it could be enough.
And by the way: describing how personal data can be deleted is not a new issue nor a Facebook issue. With GDPR it has been required for years.