Most small business owners know that their website should have a privacy policy. However, knowing that you need one and knowing what it should actually say are two very different things.
It can be tempting to download a free privacy policy template, change the business name and add it to your website. Unfortunately, data protection compliance is rarely quite that simple.
Your privacy policy needs to accurately explain how your particular business collects, uses, stores and shares personal information. It must also reflect the latest data protection rules, including changes introduced by the Data (Use and Access) Act 2025, commonly known as the DUAA.
In this blog, we explain what a UK website privacy policy should include, why generic wording can create problems and what businesses need to know about the new requirement to deal properly with data protection complaints.
Does every UK business website need a privacy policy?
You are likely to need a privacy policy if your website collects any information that can identify an individual.
That may include information collected when somebody:
- completes your contact form;
- makes a purchase or booking;
- signs up to your mailing list;
- creates an online account;
- submits an enquiry;
- downloads a free resource;
- leaves a review;
- applies for a role; or
- accepts or manages cookies.
Personal information is not limited to particularly private or sensitive details. A person’s name, email address, telephone number, IP address or online identifier can all amount to personal data.
The UK GDPR requires businesses to be open and transparent about how they use personal information. A privacy policy, sometimes called a privacy notice, is one of the main ways of providing this information.
So even if you don’t have a website, current ICO guidance states that you should still have a privacy policy.
What should a website privacy policy template for a UK business include?
A suitable website privacy policy template UK businesses can rely on should provide information that is specific to the business using it.
Although the exact contents will vary, your privacy policy will usually need to explain:
Who is responsible for the personal information
Your policy should clearly identify the business acting as the data controller and provide appropriate contact details.
Using vague wording such as “we”, without first identifying the relevant legal entity or business owner, can cause unnecessary confusion.
What personal information you collect
You need to describe the types of information your business collects.
Depending on your activities, this might include:
- names and contact details;
- account and login information;
- payment and transaction details;
- information included within messages or enquiries;
- marketing preferences;
- technical and website usage information;
- photographs, recordings or uploaded content; and
- health information or other special category data.
Your policy should reflect what your business genuinely collects. There is no benefit in listing every possible type of personal information if you do not actually use it.
Equally, failing to mention information you regularly collect could mean that your privacy policy is incomplete.
How the information is collected
You should explain whether information is collected directly from the individual or obtained from another source.
For example, you may receive personal information:
- through your website;
- during the checkout or booking process;
- by email, telephone or social media;
- through an online platform;
- from an employer, client or referral partner;
- from publicly available sources; or
- through cookies and similar technologies.
Why you use personal information
Your policy must explain the purposes for which personal information is used.
This could include processing orders, providing services, responding to enquiries, managing customer accounts, sending marketing, maintaining business records, preventing fraud or complying with legal obligations.
Avoid broad wording that allows the business to use information for almost any purpose. The explanation should be clear enough for an ordinary customer or website visitor to understand what will happen to their information.
Your lawful bases
It is not enough to have a good business reason for using personal information. You must also have a lawful basis under UK data protection law.
The appropriate lawful basis may include:
- taking steps before entering into a contract;
- performing a contract;
- complying with a legal obligation;
- pursuing legitimate interests;
- obtaining consent; or
- protecting someone’s vital interests.
Different lawful bases may apply to different activities. Consent is not automatically the correct basis simply because someone has provided their information.
Where special category data is used, an additional legal condition will also be required.
Who receives the information
Your policy should explain the types of third parties with whom personal information may be shared.
These might include:
- website and IT providers;
- payment processors;
- booking or customer management platforms;
- professional advisers;
- delivery companies;
- marketing providers;
- subcontractors; and
- public bodies or regulators.
You do not necessarily need to list the name of every individual supplier, but the description should be meaningful and transparent.
Many commonly used software, cloud storage, email and marketing providers process information outside the UK.
Your privacy policy should explain whether personal information may be transferred internationally and, where required, what protections are used.
Simply stating that information is never transferred outside the UK may be inaccurate if your business uses international technology providers.
How long information is kept
The UK GDPR does not set one standard retention period for all personal information.
Your privacy policy should explain how long information will normally be retained or the criteria used to determine the relevant period.
“We keep your data for as long as necessary” is unlikely to be particularly helpful or reasonable. Your policy should give an indication of your retention periods which can be different depending on the circumstances.
Individual rights
Your policy should explain the rights people may have in relation to their personal information, including the rights to:
- access their information;
- correct inaccurate information;
- request erasure;
- restrict certain uses;
- object to certain processing;
- receive information in a portable format; and
- withdraw consent where processing is based on consent.
Not every right applies in every situation, but people should be told how to exercise their rights and who to contact.
How to complain
Your policy should explain how an individual can raise a concern directly with your business. It should also provide information about the right to complain to the Information Commissioner’s Office.
This section has become particularly important following the introduction of the DUAA which we explain about more below.
What is the Data (Use and Access) Act 2025?
The Data (Use and Access) Act 2025 amended parts of the UK GDPR, the Data Protection Act 2018 and the rules governing electronic communications and cookies.
It did not replace the UK GDPR. Businesses still need to follow the core data protection principles, including fairness, transparency, data minimisation, accuracy and security.
However, the DUAA has changed and clarified several areas of data protection law. This means businesses should not assume that an older GDPR privacy policy template remains fully up to date.
Most of the relevant data protection changes came into force on 5 February 2026. The new statutory complaints requirements came into force on 19 June 2026.
The new data protection complaints requirements
All organisations must now provide people with a clear way to make a complaint about how their personal information has been handled.
This applies to businesses of all sizes. It is not limited to large organisations or businesses that have appointed a Data Protection Officer.
Under the new requirements, your business must:
- take appropriate steps to help people make a data protection complaint;
- provide a suitable way for them to submit the complaint;
- acknowledge the complaint within 30 days;
- make appropriate enquiries into the complaint;
- respond without undue delay;
- keep the complainant appropriately informed; and
- tell them the outcome of the complaint without undue delay.
Providing an electronic complaints form is one way of making the process accessible, although businesses should remain alert to complaints received through other channels. Calling something an “enquiry” rather than a “complaint” will not necessarily prevent it from being treated as one if the person is expressing dissatisfaction about the use of their personal information.
The ICO has indicated that businesses should keep appropriate records of complaints and have a procedure that enables anyone dealing with them to understand what needs to happen.
Does the complaints process need to appear in your privacy policy?
Your full internal complaints procedure does not necessarily have to be copied into your website privacy policy.
However, the policy should clearly tell people:
- that they can complain directly to you;
- how they can submit a complaint;
- how long you will take to deal with a complaint;
- what contact details or form they should use; and
- that they may also complain to the ICO.
It is also sensible to ensure that your internal process explains who will deal with complaints, how they will be recorded, how they will be investigated and how the outcome will be communicated.
Your privacy policy, complaints form and internal complaints process should all work together. Having a complaints paragraph in your privacy policy is unlikely to be enough if nobody within the business knows what to do when a complaint arrives.
What other changes has the DUAA introduced?
The complaints process is not the only change businesses should know about.
Recognised legitimate interests
The DUAA introduced a new concept known as “recognised legitimate interests”.
For a limited number of specified purposes, an organisation may rely on this lawful basis without carrying out the usual balancing test. These purposes include certain disclosures relating to public security, safeguarding vulnerable individuals and responding to emergencies.
This is not a general shortcut that allows a business to rely on legitimate interests for everything. In many ordinary commercial situations, businesses will still need to consider whether the processing is necessary and balance their interests against the individual’s rights and freedoms.
Where your business relies on legitimate interests or recognised legitimate interests, your privacy policy should explain this accurately.
Subject access requests
The law now clarifies that organisations only need to carry out searches that are “reasonable and proportionate” when responding to certain data subject requests.
It also clarifies when the response period can be paused while a business seeks information that is reasonably required to identify the information being requested.
This does not mean a business can avoid dealing with a subject access request simply because searching for the information may take time. Appropriate systems and records are still essential.
Automated decision-making
The DUAA has changed the rules surrounding certain automated decisions.
There is now greater flexibility to use automated decision-making in some circumstances, provided appropriate safeguards are followed. More restrictive rules continue to apply where decisions are based on special category information.
Businesses using artificial intelligence, profiling tools, automated recruitment systems or automated eligibility and pricing processes should review whether their privacy policy properly explains this activity.
Cookies
The DUAA allows certain limited types of cookies and similar technologies to be used without consent, including some cookies used for statistical purposes and certain functions requested by the user.
This does not mean that cookie banners are no longer needed. Many advertising, tracking and non-essential cookies will still require consent.
Your privacy and cookie policy template should accurately distinguish between cookies that are strictly necessary, cookies that may fall within a new exemption and cookies that require consent.
Charity marketing
The Act has extended a form of the existing electronic marketing “soft opt-in” to certain charitable organisations.
This change is specific and subject to conditions. It does not provide all businesses with a new right to send marketing emails without consent.
Businesses should therefore avoid removing consent wording or changing their marketing practices without first checking which rules apply to them.
Can you use a free UK privacy policy template?
Searching for a free UK privacy policy template may produce hundreds of results. Some may provide a helpful starting point, but a generic policy cannot know:
- what information your business collects;
- what software and platforms you use;
- which lawful bases apply;
- whether you process special category information;
- whether you send marketing;
- where your service providers are located;
- whether you use automated systems; or
- how long you retain different records.
A template designed for an online shop may not work for a consultant, membership business, tutor, healthcare provider or service-based business.
There is also a risk that a free template may have been written for another country, may refer to the EU GDPR rather than the UK GDPR or may not reflect the latest DUAA changes.
A small business privacy policy template should still be tailored to the small business using it. Being a small business may affect the complexity of your processes, but it does not remove the requirement to provide accurate and transparent information.
Is your existing privacy policy still suitable?
You should review your policy whenever your business changes how it uses personal information or when the law changes.
It may be time for an update if:
your policy has not been reviewed since the DUAA changes;
it does not explain how to make a data protection complaint;
you have introduced new software or online platforms;
you have added a mailing list or changed your marketing practices;
you now use AI or automated tools;
you have started collecting different types of information;
your cookie banner does not match the cookies used by your website;
your policy refers to providers you no longer use; or
the wording was copied from another business.
Your privacy policy should describe what your business does now, not what it did when the website was first launched.
Make data protection complaints easier to manage
A complaint may never arise, but it is far easier to deal with one when you already have a suitable form and a straightforward process in place.
Our low-cost Data Protection Complaint Form and Guide has been created to help small businesses collect the information needed to understand and investigate a complaint.
It includes a practical form for the complainant to complete together with guidance to help your business manage the complaint and respond appropriately.
It does not need to become another complicated compliance exercise. A simple, clear process can help you meet your obligations, deal with concerns promptly and demonstrate that your business takes personal information seriously.
Looking for a privacy policy template for a small business in the UK?
Our Privacy and Cookies Policy Template is designed for UK small businesses and can be tailored to reflect how your business collects and uses personal information.
Unlike a random policy copied from the internet, you download a questionnaire and we prepare the policy for you. This ensures it is correct and includes the most up to date rules and regulations.
We also provide practical and clear advice on data protection compliance for your business. So if you’re unsure what you should be doing you can speak to us.
