...

Over 20 Years of Legal Expertise – Trusted by UK Businesses. Secure Your Peace of Mind Today!

Privacy Policies and UK GDPR Compliance: What the Law Actually Requires

This guide provides a practical approach to drafting a privacy policy that satisfies your legal obligations under UK data protection law.

Introduction

If your website collects any personal data, and almost every website does, you are legally required to have a privacy policy. This is not a suggestion or a matter of best practice. It is a binding obligation under the UK General Data Protection Regulation and the Data Protection Act 2018. Failure to comply can result in enforcement action by the Information Commissioner’s Office, including fines of up to £17.5 million or four per cent of annual global turnover, whichever is higher.

Despite the seriousness of these consequences, many businesses tend to overlook privacy policies. They copy templates from other websites, use automated generators without reviewing the output, or draft vague statements that fail to meet the transparency requirements at the heart of UK data protection law. The result is a document that provides neither meaningful information to users nor genuine legal protection to the business.

This article explains what UK GDPR actually requires of your privacy policy, what information must be included, and how to ensure your policy is both legally compliant and genuinely useful.

The Legal Framework

The UK GDPR, which is the retained EU version of the General Data Protection Regulation as it applies in the United Kingdom following Brexit, together with the Data Protection Act 2018, forms the primary legal framework governing how organisations collect, use, store, and share personal data. The UK GDPR sets out seven key principles of data processing: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

Your privacy policy is the primary mechanism through which you demonstrate compliance with the transparency principle. Articles 13 and 14 of the UK GDPR set out specific information that must be provided to individuals when their personal data is collected. This information must be provided in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.

It is worth emphasising that the obligation to provide this information is not contingent on whether you think you processed significant amounts of data. If you collect names, email addresses, IP addresses, cookie data, or any other information that identifies or could identify an individual, you are processing personal data, and the UK GDPR applies to you.

What Your Privacy Policy Must Include

Identity and Contact Details of the Controller

Your privacy policy must identify who is responsible for the personal data you collect. This means providing the full legal name of your business, your registered address, and your contact details. If certain types of organisations mandate the appointment of a Data Protection Officer, you must also provide their contact details.

The Personal Data You Collect

You must specify the categories of personal data you collect. This should be specific rather than generic. Rather than stating that you collect ‘personal information’, you should identify exactly what you collect: names, email addresses, telephone numbers, postal addresses, payment details, IP addresses, browser information, location data, and so on. If you collect data through different means, such as contact forms, account registration, purchases, and cookies, you should explain what data is collected through each.

The Lawful Basis for Processing

Under Article 6 of the UK GDPR, every processing activity must have a lawful basis. The six lawful bases are consent, contract, legal obligation, vital interests, public tasks, and legitimate interests. Your privacy policy must identify the lawful basis you rely on for each type of processing. This feature is one of the most commonly neglected requirements. Simply stating that you process data ‘to provide our services’ is insufficient. You must explain, for each processing activity, which lawful basis applies and why.

Where you rely on legitimate interests, you must also describe what those interests are. Where you rely on consent, you must explain how it can be withdrawn. Getting this right is essential because it determines the rights available to individuals and affects the legality of your processing.

How Data Is Used

Your policy must explain the purposes for which personal data is processed. This should be specific and exhaustive. Common purposes include fulfilling orders, managing accounts, responding to enquiries, sending marketing communications, improving the website, and complying with legal obligations. Each purpose should be linked to the relevant lawful basis.

Data Sharing and Third Parties

If you share personal data with third parties, your privacy policy must explain who those third parties are, or at least the categories of recipients, and why the data is shared with them. This includes payment processors, hosting providers, email marketing platforms, analytics services, and any other third-party service providers. If data is transferred outside the United Kingdom, you must explain the process and identify the safeguards in place to protect the data, such as adequacy decisions or standard contractual clauses.

Data Retention

The UK GDPR requires that personal data not be kept for longer than is necessary for the purposes for which it was collected. Your privacy policy should explain how long you retain different categories of data and the criteria used to determine retention periods. The ICO is unlikely to be satisfied with a blanket statement that retains data ‘as long as necessary’. You should specify actual timeframes where possible, such as retaining transaction records for six years to comply with tax obligations.

Individual Rights

Data subjects have a range of rights under the UK GDPR, and your privacy policy must inform them of these rights. They include the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and rights in relation to automated decision-making and profiling. You should explain each right in plain language and tell individuals how to exercise them, typically by contacting you at a specified email address.

The Right to Complain

Your privacy policy must inform individuals of their right to lodge a complaint with the ICO. You should provide the ICO’s contact details or a link to their website. This is a mandatory requirement that is frequently missing from privacy policies.

Common Pitfalls

The most common failing we encounter is a privacy policy that is either too vague or too long. A policy that exceeds twenty pages in dense legal text is just as likely to fail the transparency test as one that provides no meaningful information at all. The ICO (Information Commissioner’s Office) has been clear that privacy information should be layered, using a concise summary with links to more detailed information where necessary.

Another frequent issue is failing to update the privacy policy when processing activities change. If you start using a new analytics platform, engage a new marketing tool, or expand into new markets, your privacy policy needs to reflect this. An accurate policy when it was drafted but no longer reflects your actual processing is a compliance risk.

Using a privacy policy template from an American website is a particularly common mistake for UK businesses. US privacy law operates on a fundamentally different basis from UK GDPR, and a policy drafted for US compliance will not meet UK requirements. The concepts of lawful bases, data subject rights, and the accountability principle have no direct equivalents in most US privacy frameworks.

Finally, many businesses fail to distinguish between their privacy policy and their cookie policy. While cookies are addressed in our next article, it is important to note that cookie consent operates under separate legislation, specifically the Privacy and Electronic Communications Regulations 2003, and while your privacy policy should reference cookies, the detailed cookie information and consent mechanism should be addressed separately.

Practical Steps for Compliance

Achieving compliance begins with a data mapping exercise. You must know what personal data you collect, where it comes from, what you do with it, who you share it with, and how long you keep it. Without this foundational understanding, it is impossible to draft an accurate privacy policy.

Once your data map is complete, draft your privacy policy to address each of the mandatory information requirements under Articles 13 and 14. Use plain language, keep it as concise as possible without sacrificing completeness, and structure it clearly so that users can find the information they need. Consider using a layered approach, with a short-form summary at the top and detailed information below.

Review your privacy policy at least annually, and whenever you make significant changes to your data processing activities. Document your reviews as part of your accountability obligations. Ensure that your privacy policy is prominently linked from every page of your website, typically in the footer, and that it is accessible before any data collection takes place.

Conclusion

A compliant privacy policy is not just a legal document; it is a statement of trust. It shows clients and site visitors that you value their data, know your duties, and have systems to protect it. A clear and honest privacy policy can provide a genuine competitive advantage in an era of increasing public awareness about data privacy.

Getting it wrong, however, carries real consequences. ICO enforcement is increasing, and individuals are more willing than ever to exercise their rights. Investing in a properly drafted privacy policy is not an expense; it is a safeguard against far greater costs down the line.

Need help with your privacy policy?

Lawdit Solicitors’ The StayLegal compliance package includes a bespoke, UK GDPR-compliant privacy policy tailored to your business. Our specialist team will conduct a data mapping exercise and draft a policy that meets ICO expectations and protects your business. Visit staylegal.co.uk to learn more.

More From Stay Legal

Share this with your network