A practical guide to drafting a privacy policy that meets your legal obligations under UK data protection law.
Introduction
If your website collects any personal data, and almost every website does, you are legally required to have a privacy policy. This is not a suggestion or a matter of best practice. It is a binding obligation under the UK General Data Protection Regulation and the Data Protection Act 2018. Failure to comply can result in enforcement action by the Information Commissioner’s Office, including fines of up to £17.5 million or four per cent of annual global turnover, whichever is higher.
Despite the severity of these consequences, many businesses treat privacy policies as an afterthought. They copy templates from other websites, use automated generators without reviewing the output, or draft vague statements that fail to meet the transparency requirements at the heart of UK data protection law. The result is a document that provides neither meaningful information to users nor genuine legal protection to the business.
This article explains what UK GDPR actually requires of your privacy policy, what information must be included, and how to ensure your policy is both legally compliant and genuinely useful.
The Legal Framework
The UK GDPR, which is the retained EU version of the General Data Protection Regulation as it applies in the United Kingdom following Brexit, together with the Data Protection Act 2018, forms the primary legal framework governing how organisations collect, use, store, and share personal data. The UK GDPR sets out seven key principles of data processing: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
Your privacy policy is the primary mechanism through which you demonstrate compliance with the transparency principle. Articles 13 and 14 of the UK GDPR set out specific information that must be provided to individuals when their personal data is collected. This information must be provided in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.
It is worth emphasising that the obligation to provide this information is not contingent on whether you think you process significant amounts of data. If you collect names, email addresses, IP addresses, cookie data, or any other information that identifies or could identify an individual, you are processing personal data and the UK GDPR applies to you.
What Your Privacy Policy Must Include
Identity and Contact Details of the Controller
Your privacy policy must identify who is responsible for the personal data you collect. This means providing the full legal name of your business, your registered address, and your contact details. If you have appointed a Data Protection Officer, which is mandatory for certain types of organisations, their contact details must also be provided.
The Personal Data You Collect
You must specify the categories of personal data you collect. This should be specific rather than generic. Rather than stating that you collect ‘personal information,’ you should identify exactly what you collect: names, email addresses, telephone numbers, postal addresses, payment details, IP addresses, browser information, location data, and so on. If you collect data through different means, such as contact forms, account registration, purchases, and cookies, you should explain what data is collected through each.
The Lawful Basis for Processing
Under Article 6 of the UK GDPR, every processing activity must have a lawful basis. The six lawful bases are consent, contract, legal obligation, vital interests, public task, and legitimate interests. Your privacy policy must identify the lawful basis you rely on for each type of processing. This is one of the most commonly neglected requirements. Simply stating that you process data ‘to provide our services’ is insufficient. You must explain, for each processing activity, which lawful basis applies and why.
Where you rely on legitimate interests, you must also describe what those interests are. Where you rely on consent, you must explain how consent can be withdrawn. Getting this right is essential because it determines the rights available to individuals and affects the legality of your processing.
How Data Is Used
Your policy must explain the purposes for which personal data is processed. This should be specific and exhaustive. Common purposes include fulfilling orders, managing accounts, responding to enquiries, sending marketing communications, improving the website, and complying with legal obligations. Each purpose should be linked to the relevant lawful basis.
Data Sharing and Third Parties
If you share personal data with third parties, your privacy policy must explain who those third parties are, or at least the categories of recipients, and why data is shared with them. This includes payment processors, hosting providers, email marketing platforms, analytics services, and any other third-party service providers. If data is transferred outside the United Kingdom, you must explain this and identify the safeguards in place to protect the data, such as adequacy decisions or standard contractual clauses.
Data Retention
The UK GDPR requires that personal data is not kept for longer than is necessary for the purposes for which it was collected. Your privacy policy should explain how long you retain different categories of data and the criteria used to determine retention periods. A blanket statement that data is retained ‘as long as necessary’ is unlikely to satisfy the ICO. You should specify actual timeframes where possible, such as retaining transaction records for six years to comply with tax obligations.
Individual Rights
Data subjects have a range of rights under the UK GDPR, and your privacy policy must inform them of these rights. They include the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and rights in relation to automated decision-making and profiling. You should explain each right in plain language and tell individuals how to exercise them, typically by contacting you at a specified email address.
The Right to Complain
Your privacy policy must inform individuals of their right to lodge a complaint with the ICO. You should provide the ICO’s contact details or a link to their website. This is a mandatory requirement and is frequently missing from privacy policies.
Common Pitfalls
The most common failing we encounter is a privacy policy that is either too vague or too long. A policy that runs to twenty pages of dense legal text fails the transparency test just as badly as one that provides no meaningful information at all. The ICO has been clear that privacy information should be layered, using a concise summary with links to more detailed information where necessary.
Another frequent issue is failing to update the privacy policy when processing activities change. If you start using a new analytics platform, engage a new marketing tool, or expand into new markets, your privacy policy needs to reflect this. A policy that was accurate when it was drafted but no longer reflects your actual processing is a compliance risk.
Using a privacy policy template from an American website is a particularly common mistake for UK businesses. US privacy law operates on a fundamentally different basis to UK GDPR, and a policy drafted for US compliance will not meet UK requirements. The concepts of lawful bases, data subject rights, and the accountability principle have no direct equivalents in most US privacy frameworks.
Finally, many businesses fail to distinguish between their privacy policy and their cookie policy. While cookies are addressed in our next article, it is important to note that cookie consent operates under separate legislation, specifically the Privacy and Electronic Communications Regulations 2003, and while your privacy policy should reference cookies, the detailed cookie information and consent mechanism should be addressed separately.
Practical Steps for Compliance
Achieving compliance begins with a data mapping exercise. You need to understand what personal data you collect, where it comes from, what you do with it, who you share it with, and how long you keep it. Without this foundational understanding, it is impossible to draft an accurate privacy policy.
Once your data map is complete, draft your privacy policy to address each of the mandatory information requirements under Articles 13 and 14. Use plain language, keep it as concise as possible without sacrificing completeness, and structure it clearly so that users can find the information they need. Consider using a layered approach, with a short-form summary at the top and detailed information below.
Review your privacy policy at least annually, and whenever you make significant changes to your data processing activities. Document your reviews as part of your accountability obligations. Ensure that your privacy policy is prominently linked from every page of your website, typically in the footer, and that it is accessible before any data collection takes place.
Conclusion
A compliant privacy policy is not just a legal document; it is a statement of trust. It tells your customers and website visitors that you take their data seriously, that you understand your obligations, and that you have systems in place to protect their information. In an era of increasing public awareness about data privacy, a clear and honest privacy policy can be a genuine competitive advantage.
Getting it wrong, however, carries real consequences. ICO enforcement is increasing, and individuals are more willing than ever to exercise their rights. Investing in a properly drafted privacy policy is not an expense; it is a safeguard against far greater costs down the line.
Need help with your privacy policy?
Lawdit Solicitor’s StayLegal compliance package includes a bespoke, UK GDPR-compliant privacy policy tailored to your business. Our specialist team will conduct a data mapping exercise and draft a policy that meets ICO expectations and protects your business. Visit staylegal.co.uk to learn more.


