GDPR Privacy Policies: Key requirements for organisations
- 23 September 2026
- Corporate and M&A
When an organisation is creating a website or app to reach users or potential customers drafting a Privacy Policy may be an afterthought. However, failure to write a Privacy Policy, which complies with the relevant legislation, can have serious consequences.
A Privacy Policy (otherwise known as a Privacy Notice) is a legal document that explains to users what an organisation is doing with their data. The Data Protection Act 2018 (DPA 2018) defines data as any information relating to an identified or identifiable living individual e.g. names, phone numbers, national insurance numbers. If an organisation holds personal data, which is generally all organisations, they will need a Privacy Policy.
The UK General Data Protection Regulation (GDPR) places a duty on organisations to inform individuals on what happens when their data is collected. Articles 13 and 14 of the GDPR state what must be included in a Privacy Policy:
However, complying with these content requirements is not enough. The Privacy Policy must also be provided to individuals in a “concise, transparent, intelligible and easily accessible form, using clear and plain language”. Additionally, important information should not be buried in long, difficult to navigate text.
A poorly drafted Privacy Policy can result in several financial and reputational consequences for an organisation.
Penalties for noncompliance:
The Information Commissioner’s Office, the UK’s data protection regulator, has the right to enforce various penalties for breaches of GDPR. These penalties include:
Legal action and compensation claims:
Under GDPR individuals can sue organisations for compensation if they believe their data protection rights have been violated.
Damages to customer trust and reputation risks:
If a Privacy Policy does not comply with GDPR customers may view an organisation as not respecting data privacy rights. Business partners and third parties may also reconsider their relationships with noncompliant organisations.
Overall, a well-drafted Privacy Policy will not just help your organisation comply with mandatory legal rules but will also help foster trust with individuals by demonstrating your commitment to good data-processing practices.
A poorly drafted Privacy Policy can result in several financial and reputational consequences for an organisation.
The following are some steps that your organisation can take to ensure compliance with data protection legislation:
Data protection is a legal obligation. So, every organisation, however small, needs a GDPR compliant Privacy Policy when processing people’s data.
Our data protection team assist organisations with dealing with potential and actual data protection breaches and DSAR compliance including assisting organisations in updating their policies and training. Please do not hesitate to get in contact with a member of the team.
Keep up to date with the latest tips, analysis and upcoming events by our legal experts, direct to your inbox.
Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.