Privacy notice
The public-facing notice telling customers and website visitors what you do with their personal data, as Articles 13 and 14 of the UK GDPR require.
What's inside
- A processing table to complete from what you actually do
- Lawful bases, retention periods and sharing
- The individual rights and how someone exercises them
- International transfers and how to complain
Word document. Drafted by Lawyerly's commercial solicitors. Last updated September 2026.
Download your free copy
Tell us who you are and the file is yours straight away.
The privacy notice is the document your customers actually see
Articles 13 and 14 of the UK GDPR require you to tell people what you do with their personal data, at the point you collect it. The privacy notice is how that is done, and it is the only data protection document most of your customers will ever read. It is also the first thing a complainant sends to the Information Commissioner's Office, which is why a notice that does not match the business is worse than a short one that does.
It is not the same as a data protection policy
This notice faces outwards: it explains to customers and website visitors what happens to their information. A data protection policy faces inwards and tells your own people how to handle it. Businesses regularly publish one and believe they have both. You need each, and if you have staff you need a third, because workers and job applicants have to be given their own notice covering recruitment, monitoring, payroll and references.
The table at clause 4 is the work
It asks, for each thing you do with personal data, what you collect, why, the lawful basis, who you share it with and how long you keep it. Delete rows that do not apply, add anything missing, and check it against your record of processing activities. Completing it properly is the point of the exercise, because it surfaces the processing nobody had written down: the abandoned CRM, the spreadsheet of enquiries, the marketing tool holding contacts who never consented.
Retention is where most notices go vague. "As long as necessary" tells the reader nothing and tells a regulator less. A period tied to a reason, such as six years after the end of a contract for limitation purposes, is easier to justify and easier to operate.
Lawful basis, chosen rather than defaulted to
Consent has to be freely given and capable of being withdrawn, which makes it the wrong basis for processing you will carry on doing regardless. Performance of a contract and legitimate interests carry most ordinary business processing, and where legitimate interests is used the balancing assessment should exist somewhere you could produce it.
What sits alongside it
A cookie policy where the website sets cookies, which is almost every website, and the two have to agree with each other and with the banner. Where personal data leaves the UK the notice has to say so, and the transfer needs a mechanism behind it.
If you handle health or other sensitive data, children's data, or make automated decisions about people, the notice needs more than completion. Our UK GDPR and data protection solicitors build the set together.
You may also find these useful
Talk to a solicitor about your situation
A template gets you started. When the facts are yours, one of our commercial solicitors will tailor it, or tell you plainly that you need something else. The first conversation is free.
Book a complimentary consultation
Willem van der Merwe
Co-Founder
Read profile
Willem van der Merwe
Co-Founder
Willem co-founded Lawyerly after twenty years of running and advising businesses, most of which were spent as a client of law firms rather than a member of one. He had seen how legal advice tends to arrive: late, priced by the hour, and detached from the commercial decision that prompted it. Lawyerly grew out of a conviction that it could be done differently.
He read law and marketing at university and later completed MIT Sloan's executive programme in artificial intelligence and business strategy. His career before Lawyerly took in two advertising agencies, which he led through the industry's move to digital, several years in digital publishing, and a period in international development, working on programmes across South East Asia and Sub-Saharan Africa.
At Lawyerly he is responsible for growth and for the client experience, ensuring our clients receive the legal support they need.
Qualifications
BA Law; AI Business Strategy (MIT); Nomadic Marketing (UCT)