GLOBAL BRIDGE LABS
← All posts/Website Development

What a UK website privacy policy must include

What a UK website privacy policy must include under UK GDPR: who you are, what you collect, why, your lawful basis, retention, sharing and people's rights.

By Hojitha Weerasinghe, Co-founder / DirectorPublished 8 min read
Website privacy policy UK: key takeaways infographic by Global Bridge Labs
Key takeaways from this article. Share it with the link and credit Global Bridge Labs.
On this page

Short answer

A UK website privacy policy, which UK GDPR calls a privacy notice, must tell people who you are, what personal data you collect, why, your lawful basis, who you share it with, how long you keep it, whether it leaves the UK, and what rights they have, including the right to complain to the ICO. It must be clear, accurate and easy to find.

  • You need one if your site collects any personal data, including via forms and analytics.
  • List each purpose with its lawful basis: contract, legitimate interests, consent.
  • Name the third parties and tools you share data with: hosting, CRM, analytics.
  • State retention periods and people's rights, including complaining to the ICO.
  • Link to it from every form and the footer; review it when your tools change.

Want your privacy notice checked against your actual forms and tools? Message us on WhatsApp.

Chat on WhatsApp →

What is a privacy policy?

A privacy policy, or privacy notice, is a public statement that explains how an organisation collects, uses, shares and protects personal data, and what rights individuals have over it, as required by the right to be informed under UK GDPR.

It is a legal document written for ordinary people. The ICO's guidance is explicit that privacy information must be concise, transparent, intelligible and in clear and plain language.

Why does a small business website need one?

Almost every business website collects personal data: contact forms, booking tools, newsletter sign-ups, analytics, chat widgets and WhatsApp messages. As soon as it does, UK GDPR requires you to tell people how it is used at the time you collect it.

Most organisations that process personal data must also pay the ICO an annual data protection fee unless they are exempt. The ICO's advice for small organisations has a self-assessment to check.

What must a UK privacy notice include?

The ICO's right to be informed guidance lists the required information. For a typical small business website, that means the following.

  • Your business name and contact details, and a data protection contact if you have one.
  • What personal data you collect, and from where.
  • Why you use it, with the lawful basis for each purpose.
  • Your legitimate interests, where that is the basis.
  • Who you share it with, by name or category.
  • Whether data is transferred outside the UK and the safeguards used.
  • How long you keep each type of data.
  • People's rights, including access, erasure and objection.
  • The right to withdraw consent, where consent is the basis.
  • The right to complain to the ICO.

Which lawful basis fits common website purposes?

Choose the basis that genuinely fits each purpose. The ICO warns against defaulting to consent when another basis fits better.

  • Replying to an enquiry or quote request: legitimate interests or steps before a contract.
  • Delivering a booking or order: contract.
  • Marketing emails to individuals: usually consent, under PECR.
  • Analytics and advertising cookies: consent where PECR requires it.
  • Keeping records for tax: legal obligation.

Want a data map of your forms and tools to base your notice on? Message us on WhatsApp.

Chat on WhatsApp →

Can you use a privacy policy template?

A template is a reasonable starting point, but only if you edit it to match what you actually do. A generic template that mentions tools you do not use, or omits the booking system and WhatsApp you do use, is inaccurate, and an inaccurate notice does not meet the right to be informed.

Start by listing every place your site collects data and every tool that receives it. Then write the notice from that list.

When do you need more than a standard notice?

You need more care if you handle special category data, such as health information in a clinic booking form, if you profile customers or make automated decisions, or if you transfer data to countries without UK adequacy. Health and financial businesses should take specific advice.

The trade-off is length against clarity. Use a layered approach: a short summary at the top, with detail underneath, so people can find what they need quickly.

What does this look like in practice?

A pattern we see repeatedly: a privacy policy copied from a template several years ago, mentioning a newsletter the business no longer sends, and saying nothing about the booking tool, live chat or analytics it now uses.

Rewriting it from a simple list of forms and tools, adding a link beside each form and dating it produces an accurate notice. It is quicker than most owners expect.

Privacy notice checklist

Review this whenever you add a form or tool.

  • List every point where the site collects data.
  • List every tool that receives the data.
  • Assign a lawful basis to each purpose.
  • State retention periods.
  • Explain people's rights and how to exercise them.
  • Include the right to complain to the ICO.
  • Link the notice from every form and the footer.
  • Date the notice and review it annually.

Next step

If your privacy policy was copied from a template and never updated, we will map your forms and tools with you in 30 minutes so the notice can reflect what you actually do.

Message us on WhatsApp for a privacy notice review, or book a 30-minute consultation.

Chat on WhatsApp →

Sources and further reading

Frequently asked questions

Do I need a privacy policy on my website in the UK?

Yes, if your website collects any personal data, which includes contact forms, bookings, newsletter sign-ups, analytics and chat tools. UK GDPR's right to be informed requires you to tell people how their data is used when you collect it, usually through a privacy notice linked from forms and the footer.

What should a UK privacy policy include?

Your identity and contact details, what data you collect, why, the lawful basis for each purpose, who you share it with, any international transfers, how long you keep it, people's rights, the right to withdraw consent and the right to complain to the ICO, all in clear, plain language.

Can I use a free privacy policy template?

Yes, as a starting point, but you must edit it to reflect exactly what your business does. A notice that mentions tools you do not use or omits those you do is inaccurate and does not meet UK GDPR's right to be informed. List your forms and tools first.

What is the difference between a privacy policy and a cookie policy?

A privacy policy explains how you handle personal data generally. A cookie policy explains which cookies and similar technologies your site uses and why, supporting consent under PECR. Many small businesses combine them into one page, provided both sets of information are clear and easy to find.

Written by

Hojitha Weerasinghe
Hojitha Weerasinghe
Co-founder / Director

Global Bridge Labs (GBL) is a UK–Sri Lanka partner for social media, websites and BPO. Everything here comes from client delivery, not theory.

Share this article

Reading is good.
Fixing is better.

30 minutes with our team and you'll leave knowing which of the three problems to fix first.

Book a 30-Minute Consultation →
Keep reading