Search

How can we help?

Icon

GDPR Privacy Policies: Key requirements for organisations

When an organisation is creating a website or app to reach users or potential customers drafting a Privacy Policy may be an afterthought. However, failure to write a Privacy Policy, which complies with the relevant legislation, can have serious consequences.

Legal requirements of a Privacy Policy

A Privacy Policy (otherwise known as a Privacy Notice) is a legal document that explains to users what an organisation is doing with their data. The Data Protection Act 2018 (DPA 2018) defines data as any information relating to an identified or identifiable living individual e.g. names, phone numbers, national insurance numbers. If an organisation holds personal data, which is generally all organisations, they will need a Privacy Policy.

The UK General Data Protection Regulation (GDPR) places a duty on organisations to inform individuals on what happens when their data is collected. Articles 13 and 14 of the GDPR state what must be included in a Privacy Policy:

  • Data controller’s identity
  • What personal data are collected
  • How personal data are collected
  • Why personal data are collected
  • When personal data are shared
  • What choices individuals have
  • How long personal data are kept
  • What rights individuals have, including the right to withdraw consent and complain

However, complying with these content requirements is not enough. The Privacy Policy must also be provided to individuals in a “concise, transparent, intelligible and easily accessible form, using clear and plain language”. Additionally, important information should not be buried in long, difficult to navigate text.

The consequences of having a poorly drafted Privacy Policy

A poorly drafted Privacy Policy can result in several financial and reputational consequences for an organisation.

Penalties for noncompliance:

The Information Commissioner’s Office, the UK’s data protection regulator, has the right to enforce various penalties for breaches of GDPR. These penalties include:

  • Substantial fines (up to £17.5 million, or up to 4 percent of the total worldwide annual turnover of the preceding financial year)
  • Enforcement action requiring an organisation to rectify their noncompliance

Legal action and compensation claims:

Under GDPR individuals can sue organisations for compensation if they believe their data protection rights have been violated.

Damages to customer trust and reputation risks:

If a Privacy Policy does not comply with GDPR customers may view an organisation as not respecting data privacy rights. Business partners and third parties may also reconsider their relationships with noncompliant organisations.

Overall, a well-drafted Privacy Policy will not just help your organisation comply with mandatory legal rules but will also help foster trust with individuals by demonstrating your commitment to good data-processing practices.

A poorly drafted Privacy Policy can result in several financial and reputational consequences for an organisation.

Practical steps to ensure compliance with GDPR

The following are some steps that your organisation can take to ensure compliance with data protection legislation:

  • Ensure your Privacy Policy complies with Articles 13 and 14 GDPR
  • Ensure your Privacy Policy is easily accessible when users visit your website (ideally a link to the policy should appear on every page, especially on the homepage)
  • Your Privacy Policy should not be too long, burying important information
  • Your Privacy Policy should not be vague or use ambiguous language
  • The Privacy Policy should allow users to withdraw their consent to their data being processed
  • If you already have a Privacy Policy on your website review it constantly to ensure it complies with any new legislation

Data protection is a legal obligation. So, every organisation, however small, needs a GDPR compliant Privacy Policy when processing people’s data.

How our data protection team can help

Our data protection team assist organisations with dealing with potential and actual data protection breaches and DSAR compliance including assisting organisations in updating their policies and training.  Please do not hesitate to get in contact with a member of the team.

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

Zahra Navarro

Trainee Solicitor

View profile

+44 20 7539 8050

About this article

Read, listen and watch our latest insights

Pub
  • 17 September 2026
  • Employment

Employment law changes in 2026: What you need to know

Stay ahead of the latest UK employment law changes. Watch our on demand webinar with Monica Atwal and Harry Berryman covering key HR developments and employment law updates for 2026.

art
  • 16 September 2026
  • Employment

Received an Employment Tribunal Claim? 6 Things Employers Should NOT Do

We are well and truly underway with implementation of the Employment Rights Act 2025 (“ERA 2025”) and October brings the next tranche of changes that employers will need to be ready for.

art
  • 14 September 2026
  • Corporate and M&A

Key provisions found in a Shareholders’ Agreement – SHA Series Part 2 of 5

Discover the key provisions in a shareholders’ agreement, including ownership, decision-making, share transfers, exits and leaver clauses.

art
  • 11 September 2026
  • Privacy and Data Protection

Data Protection Breaches – Personal Liability for Employees

It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known, is that employees can be held personally liable for certain actions amounting to criminal offences under the Act.

Pub
  • 07 September 2026
  • Corporate and M&A

Frequently Asked Questions About Shareholders’ Agreements – Episode 1

Join Emma Docking and Jonathan Hayes as they explore some of the most frequently asked questions about shareholders’ agreements, including what they are, how they work alongside articles of association, and the risks of operating without one.

art
  • 03 September 2026
  • Employment

Employment Rights Act – October Changes

We are well and truly underway with implementation of the Employment Rights Act 2025 (“ERA 2025”) and October brings the next tranche of changes that employers will need to be ready for.