Home › Blog › Data Ethics and Privacy
How to Write a Privacy Policy That Is Actually Compliant
How to write a privacy policy comes down to answering a fixed list of questions honestly: who you are, what personal data you collect, why, on what legal basis, who you share it with, how long you keep it and what people can do about it. In the UK that list is set by Articles 13 and 14 of the UK GDPR, and since 19 June 2026 the Data (Use and Access) Act 2025 has added a duty to run a complaints process that your notice should point to. This page sets out the sections a compliant policy needs, how to fill each one in, and the mistakes regulators see most.
Privacy policy or privacy notice?
The terms get used interchangeably, but the regulator draws a line. A privacy notice is the public-facing statement that tells people how you use their data; it is what goes in the footer of your website and on your forms. A privacy policy, in the stricter sense, is the internal document that tells staff how to handle personal data. Most small businesses need both, and this page is about the public one, because that is the one the law spells out in detail and the one customers, regulators and journalists read. Our UK GDPR explainer covers the wider framework.
The sections a compliant notice needs
Article 13 applies when you collect data from the person directly; Article 14 applies when you get it from someone else, such as a list broker, a referral partner or a public register. The contents overlap almost completely. Work through them in this order.
1. Who you are and how to contact you
Give the legal name of the organisation that decides how the data is used (the controller), a postal address and an email address that someone reads. If you have appointed a data protection officer, give their contact details. A trading name alone is not enough when the contracting entity is a limited company with a different name.
2. What data you collect, and where it comes from
List the categories, not every field: contact details, order history, payment information, website usage data, CCTV footage, job application details. If any of it is special category data, such as health information or biometric data, say so plainly. If you obtain data from other sources, Article 14 requires you to name the source or at least the type of source.
3. Why you use it and your lawful basis
This is the section most templates get wrong. For each purpose, state the lawful basis you rely on: contract, legal obligation, legitimate interests, consent, vital interests, public task, or, since the Data (Use and Access) Act changes took effect in February 2026, one of the new "recognised legitimate interests" such as crime prevention or safeguarding. Where you rely on ordinary legitimate interests, say what those interests are. A table works well here:
| What we do | Data used | Lawful basis |
|---|---|---|
| Process and deliver your order | Name, address, payment details | Contract |
| Keep tax and accounting records | Invoices and payment records | Legal obligation |
| Send marketing emails | Email address, purchase history | Consent, or the soft opt-in for existing customers |
| Prevent fraud | Order and device data | Legitimate interests |
Do not list consent for everything. If you would carry on processing when someone withdraws consent, consent was never your basis, and saying it was misleads people about their rights.
4. Who you share it with and transfers abroad
Name the categories of recipient: payment processors, couriers, hosting and email providers, accountants, insurers. If data leaves the UK, for example to a US software provider, say so and say what safeguard covers the transfer, such as a UK adequacy regulation, the UK Extension to the EU-US Data Privacy Framework, or the International Data Transfer Agreement.
5. How long you keep it
Give a period for each main category, or the criteria you use to set one. "As long as necessary" on its own is not enough. Six years for financial records, the length of a recruitment campaign plus six months for unsuccessful applicants, or 30 days for CCTV are the kind of concrete answers people expect.
6. People's rights, and how to complain
List the rights that apply: access, rectification, erasure, restriction, objection, data portability, and the right to withdraw consent at any time where you rely on it. Explain any automated decision-making that has legal or similarly significant effects. Then cover complaints in two steps. Since 19 June 2026, section 164A of the Data Protection Act 2018, inserted by section 103 of the Data (Use and Access) Act 2025, requires controllers to make it easy to complain to them, for example with a complaint form that can be completed electronically, and to acknowledge complaints within 30 days. Link to that process from the notice, and then tell people they can also complain to the Information Commissioner's Office.
Also say whether giving the data is a legal or contractual requirement and what happens if someone does not provide it, for example that you cannot process an order without a delivery address.
Writing it so people can read it
The UK GDPR requires the information to be concise, transparent, intelligible and easily accessible, in clear and plain language. In practice that means:
- Layer it. A short summary at the top, with headed sections or expandable panels below for detail.
- Write in the second person. "We use your email address to send your receipt" beats "the data subject's contact data may be processed".
- Put it where data is collected. Link it from every form, the checkout and the cookie banner, not only the footer.
- Date it. Show when it was last updated, and tell people about material changes before they take effect.
Cookies are a separate notice
Cookies and similar tracking are governed by the Privacy and Electronic Communications Regulations, not only by the UK GDPR. The Data (Use and Access) Act relaxed the consent rule for some low-risk uses, such as analytics that only improve your own site, provided people are told and given a simple way to object, but advertising and cross-site tracking still need consent. Keep the cookie detail in its own notice, linked from the privacy notice and the banner.
Mistakes to avoid
- Copying a competitor's notice. It describes their processing, not yours, and an inaccurate notice is a breach in itself.
- Listing every possible purpose "just in case". Vague catch-alls fail the transparency test.
- Forgetting staff and job applicants. They need their own notice, separate from the customer one. Our page on workplace surveillance ethics covers monitoring.
- Never reviewing it. A new CRM, a new payment provider or a move into AI tools changes your processing, and the notice must change with it. High-risk new processing may also need a data protection impact assessment.
A compliant notice is the legal minimum. Whether the processing behind it is fair is a wider question, which our guide to data ethics for business takes on. More on responsible business is on the e-Business Ethics home page.
Frequently Asked Questions
What must a privacy policy include in the UK?
Who you are and how to contact you, what data you collect and its source, the purposes and lawful basis for each, who you share it with and any transfers abroad, how long you keep it, people's rights, and how to complain to you and to the ICO. The list comes from UK GDPR Articles 13 and 14.
Is a privacy policy a legal requirement for a small business?
If you collect personal data, you must give people the privacy information in Articles 13 and 14 of the UK GDPR. For most businesses with a website or customer records, that means publishing a privacy notice.
Can I use a privacy policy template?
A template can give you the structure, but every section must describe your own processing. A notice copied from another business that does not match what you do is inaccurate, which is itself a breach of the transparency rules.
What changed in privacy notices under the Data (Use and Access) Act 2025?
Since 19 June 2026, controllers must make it easy to complain to them about data use and acknowledge complaints within 30 days, so the notice should link to that process. Changes from February 2026 also added recognised legitimate interests as a lawful basis and relaxed consent for some low-risk cookies.
How often should I update my privacy policy?
Whenever your processing changes, such as a new supplier, system or purpose, and at least once a year as a check. Date the notice and tell people about material changes before they take effect.
Sources
- UK GDPR Article 13, information to be provided
- UK GDPR Article 14, data not obtained from the data subject
- Data (Use and Access) Act 2025, section 103, complaints by data subjects
- ICO, the right to be informed
Checked on 3 October 2026.