A UK GDPR-compliant privacy notice must tell users what personal data you collect, why you collect it, who you share it with, how long you keep it, and what rights they have. The ICO's plain language standard is demanding — privacy notices written in dense legalese are non-compliant even if they technically cover the required information.
What UK GDPR Requires in a Privacy Notice
UK GDPR Articles 13 and 14 specify the required content. The requirements are the same as EU GDPR. For data collected directly from individuals (Article 13):
- Identity and contact details of the controller
- Contact details of the Data Protection Officer (if applicable)
- Purposes of processing and the lawful bases
- Where legitimate interest is relied on: the legitimate interest pursued
- Recipients or categories of recipients of the personal data
- International transfers: third countries, transfer mechanism
- How long data will be stored (or the criteria for determining this)
- Data subject rights (access, rectification, erasure, restriction, portability, object)
- Right to withdraw consent (where processing is based on consent)
- Right to complain to the ICO
- Whether providing personal data is required and the consequences of not doing so
- Automated decision-making and profiling (if applicable)
UK-Specific Requirements
Beyond the standard Article 13 content, UK GDPR notices need:
ICO as supervisory authority: UK data subjects have the right to complain to the ICO. Your privacy notice must identify the ICO with their contact details.
UK representative (if applicable): If you are not established in the UK, include your UK representative's name and contact details as a point of contact for UK data subjects.
UK transfer mechanisms: If you transfer data to third countries, identify the UK-specific mechanisms (IDTA, UK Addendum, UK adequacy regulations) rather than referencing EU SCCs alone.
UK GDPR Privacy Notice Template
Privacy Notice
Last updated: [date]
1. Who we are
[Company name] is the data controller for the personal data described in this notice.
Contact: [email address]
[Address]
UK representative: [Name and contact details — if applicable]
Data Protection Officer: [Name and contact details — if applicable]
---
2. The personal data we collect and why
We process the following categories of personal data:
Account and registration data
What: Name, email address, company name, role
Why: To provide you with access to our service
Legal basis: Contract performance
Usage data
What: Log data, feature usage, session information
Why: To maintain and improve the service
Legal basis: Legitimate interests (improving service reliability and user experience)
Marketing communications
What: Email address, marketing preferences
Why: To send you product updates and relevant information
Legal basis: Consent (for new contacts) / Legitimate interests (for existing customers)
Payment data
What: Billing name, billing address, payment method (processed by our payment provider)
Why: To process payments for the service
Legal basis: Contract performance
---
3. Who we share your data with
We share personal data with the following categories of recipients:
Cloud hosting provider: [Provider name] — [Location]
Payment processor: [Provider name] — [Location]
Customer support: [Provider name] — [Location]
Analytics: [Provider name] — [Location]
---
4. International transfers
Some recipients are located outside the UK. For transfers to countries not recognised as adequate by the UK:
[Provider] ([Country]): We use [International Data Transfer Agreement / UK Addendum to EU SCCs / UK adequacy regulations] to ensure adequate protection.
[List each material transfer]
---
5. How long we keep your data
Account data: For the duration of your account plus [X] years following closure
Financial/billing records: [X] years (required by tax law)
Marketing data: Until you unsubscribe, plus a suppression list retained indefinitely
Usage logs: [X] months
---
6. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to legal retention requirements)
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Receive your data in a portable format (for data processed by automated means under consent or contract)
- Withdraw consent at any time (for processing based on consent)
To exercise any of these rights, contact: [email/link]
We will respond within one calendar month.
---
7. Automated decision-making
[Include if applicable: description of automated decisions, logic, and right to request human review]
[If not applicable: "We do not make automated decisions that have legal or similarly significant effects on you."]
---
8. Complaints
If you have concerns about how we handle your personal data, you have the right to complain to the Information Commissioner's Office (ICO):
ICO website: ico.org.uk
ICO helpline: 0303 123 1113
ICO address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would encourage you to contact us first at [email] so we can try to resolve your concern directly.
Common Privacy Notice Failures
Missing lawful bases: Listing processing activities without identifying the lawful basis for each.
No transfer information: Omitting the disclosure of US-vendor transfers (the most common ICO finding in SME reviews).
Generic retention language: "We keep your data as long as necessary" is not compliant. Specific periods or specific criteria are required.
Not updated after product changes: A notice describing features that no longer exist or missing new processing activities.