Home › Blog › Data Ethics and Privacy

How to Write a Privacy Policy That Is Actually Compliant

How to write a privacy policy comes down to answering a fixed list of questions honestly: who you are, what personal data you collect, why, on what legal basis, who you share it with, how long you keep it and what people can do about it. In the UK that list is set by Articles 13 and 14 of the UK GDPR, and since 19 June 2026 the Data (Use and Access) Act 2025 has added a duty to run a complaints process that your notice should point to. This page sets out the sections a compliant policy needs, how to fill each one in, and the mistakes regulators see most.

What a UK privacy notice must cover The core of UK GDPR Articles 13 and 14 1. Who you areName, contact details, any DPO 2. What you collectCategories of data and the source 3. Why, and the lawful basisOne basis for each purpose 4. Who gets itRecipients and transfers abroad 5. How long you keep itA period, or how you set one 6. Rights and complaintsYour process, then the ICO Source: UK GDPR Articles 13 and 14; Data Protection Act 2018 s.164A Graphic by e-Business Ethics
The six blocks every UK privacy notice is built from. Graphic by e-Business Ethics.

Privacy policy or privacy notice?

The terms get used interchangeably, but the regulator draws a line. A privacy notice is the public-facing statement that tells people how you use their data; it is what goes in the footer of your website and on your forms. A privacy policy, in the stricter sense, is the internal document that tells staff how to handle personal data. Most small businesses need both, and this page is about the public one, because that is the one the law spells out in detail and the one customers, regulators and journalists read. Our UK GDPR explainer covers the wider framework.

The sections a compliant notice needs

Article 13 applies when you collect data from the person directly; Article 14 applies when you get it from someone else, such as a list broker, a referral partner or a public register. The contents overlap almost completely. Work through them in this order.

1. Who you are and how to contact you

Give the legal name of the organisation that decides how the data is used (the controller), a postal address and an email address that someone reads. If you have appointed a data protection officer, give their contact details. A trading name alone is not enough when the contracting entity is a limited company with a different name.

2. What data you collect, and where it comes from

List the categories, not every field: contact details, order history, payment information, website usage data, CCTV footage, job application details. If any of it is special category data, such as health information or biometric data, say so plainly. If you obtain data from other sources, Article 14 requires you to name the source or at least the type of source.

3. Why you use it and your lawful basis

This is the section most templates get wrong. For each purpose, state the lawful basis you rely on: contract, legal obligation, legitimate interests, consent, vital interests, public task, or, since the Data (Use and Access) Act changes took effect in February 2026, one of the new "recognised legitimate interests" such as crime prevention or safeguarding. Where you rely on ordinary legitimate interests, say what those interests are. A table works well here:

What we doData usedLawful basis
Process and deliver your orderName, address, payment detailsContract
Keep tax and accounting recordsInvoices and payment recordsLegal obligation
Send marketing emailsEmail address, purchase historyConsent, or the soft opt-in for existing customers
Prevent fraudOrder and device dataLegitimate interests

Do not list consent for everything. If you would carry on processing when someone withdraws consent, consent was never your basis, and saying it was misleads people about their rights.

4. Who you share it with and transfers abroad

Name the categories of recipient: payment processors, couriers, hosting and email providers, accountants, insurers. If data leaves the UK, for example to a US software provider, say so and say what safeguard covers the transfer, such as a UK adequacy regulation, the UK Extension to the EU-US Data Privacy Framework, or the International Data Transfer Agreement.

5. How long you keep it

Give a period for each main category, or the criteria you use to set one. "As long as necessary" on its own is not enough. Six years for financial records, the length of a recruitment campaign plus six months for unsuccessful applicants, or 30 days for CCTV are the kind of concrete answers people expect.

6. People's rights, and how to complain

List the rights that apply: access, rectification, erasure, restriction, objection, data portability, and the right to withdraw consent at any time where you rely on it. Explain any automated decision-making that has legal or similarly significant effects. Then cover complaints in two steps. Since 19 June 2026, section 164A of the Data Protection Act 2018, inserted by section 103 of the Data (Use and Access) Act 2025, requires controllers to make it easy to complain to them, for example with a complaint form that can be completed electronically, and to acknowledge complaints within 30 days. Link to that process from the notice, and then tell people they can also complain to the Information Commissioner's Office.

Also say whether giving the data is a legal or contractual requirement and what happens if someone does not provide it, for example that you cannot process an order without a delivery address.

Writing it so people can read it

The UK GDPR requires the information to be concise, transparent, intelligible and easily accessible, in clear and plain language. In practice that means:

  • Layer it. A short summary at the top, with headed sections or expandable panels below for detail.
  • Write in the second person. "We use your email address to send your receipt" beats "the data subject's contact data may be processed".
  • Put it where data is collected. Link it from every form, the checkout and the cookie banner, not only the footer.
  • Date it. Show when it was last updated, and tell people about material changes before they take effect.

Cookies are a separate notice

Cookies and similar tracking are governed by the Privacy and Electronic Communications Regulations, not only by the UK GDPR. The Data (Use and Access) Act relaxed the consent rule for some low-risk uses, such as analytics that only improve your own site, provided people are told and given a simple way to object, but advertising and cross-site tracking still need consent. Keep the cookie detail in its own notice, linked from the privacy notice and the banner.

Mistakes to avoid

  • Copying a competitor's notice. It describes their processing, not yours, and an inaccurate notice is a breach in itself.
  • Listing every possible purpose "just in case". Vague catch-alls fail the transparency test.
  • Forgetting staff and job applicants. They need their own notice, separate from the customer one. Our page on workplace surveillance ethics covers monitoring.
  • Never reviewing it. A new CRM, a new payment provider or a move into AI tools changes your processing, and the notice must change with it. High-risk new processing may also need a data protection impact assessment.

A compliant notice is the legal minimum. Whether the processing behind it is fair is a wider question, which our guide to data ethics for business takes on. More on responsible business is on the e-Business Ethics home page.

Frequently Asked Questions

What must a privacy policy include in the UK?

Who you are and how to contact you, what data you collect and its source, the purposes and lawful basis for each, who you share it with and any transfers abroad, how long you keep it, people's rights, and how to complain to you and to the ICO. The list comes from UK GDPR Articles 13 and 14.

Is a privacy policy a legal requirement for a small business?

If you collect personal data, you must give people the privacy information in Articles 13 and 14 of the UK GDPR. For most businesses with a website or customer records, that means publishing a privacy notice.

Can I use a privacy policy template?

A template can give you the structure, but every section must describe your own processing. A notice copied from another business that does not match what you do is inaccurate, which is itself a breach of the transparency rules.

What changed in privacy notices under the Data (Use and Access) Act 2025?

Since 19 June 2026, controllers must make it easy to complain to them about data use and acknowledge complaints within 30 days, so the notice should link to that process. Changes from February 2026 also added recognised legitimate interests as a lawful basis and relaxed consent for some low-risk cookies.

How often should I update my privacy policy?

Whenever your processing changes, such as a new supplier, system or purpose, and at least once a year as a check. Date the notice and tell people about material changes before they take effect.

Sources

Checked on 3 October 2026.