Copying a generic privacy policy template from another website and swapping in a company name is a common shortcut, and a genuinely risky one. A privacy policy is a legal document that needs to reflect exactly what your specific business does with personal data, and a mismatch between the policy and actual practice is itself a compliance failure, not just a drafting inconvenience.
This guide covers how to write a privacy policy for a website that genuinely meets UK GDPR and Data Protection Act 2018 requirements.
Why Nearly Every Website Needs One
A Privacy Policy is legally required for any website that collects personal data from visitors, whether that is through contact forms, account creation, cookies, or analytics tools such as Google Analytics. This applies regardless of business size or website type, covering e-commerce stores, blogs and simple brochure sites alike, if any personal information is gathered, a policy is compulsory.
Start With Data Mapping, Not Drafting
Before writing a single word, carefully review and map out how your business actually collects, uses and shares personal data, since your policy needs to reflect reality rather than a generic assumption of what a typical website does. This connects directly to the audit process covered in our GDPR compliance guide, and skipping it is the single most common reason privacy policies end up inaccurate.
What a UK Privacy Policy Must Include
Who You Are
State your business name, address, and contact details clearly, identifying your business as the data controller, the entity that decides how and why personal data is processed, so visitors know exactly who they are dealing with.
What Data You Collect and Why
List the categories of personal data you gather, names, email addresses, payment details, IP addresses, and explain clearly why each is collected and how it is used, whether that is processing orders, improving services, or personalising content.
Your Lawful Basis for Processing
Reference the specific lawful basis under UK GDPR for each processing activity, such as consent, contract necessity, or legal obligation, rather than a vague, blanket justification covering everything at once.
How You Protect and Retain Data
Describe the security measures in place to protect personal data, and specify how long different types of data are retained before being deleted or anonymised.
Third-Party Sharing
Disclose whether data is shared with third parties, such as advertising partners, payment processors, or analytics tools, and briefly explain the purpose of each sharing arrangement.
User Rights
Explain clearly how individuals can access, correct, or request deletion of their data, and how to contact both your business and the Information Commissioner’s Office if they have concerns.
Cookies
If your website uses cookies or tracking tools, note this clearly and either summarise or link to a separate, more detailed cookie policy covering the specific categories in use.
Writing in Plain, Accessible Language
UK GDPR specifically requires privacy notices to be concise, transparent, intelligible and written in clear, plain language, avoiding unnecessary legal jargon that leaves visitors unable to genuinely understand how their data is handled.
Where and How to Publish It
Your privacy policy should be published on your website under a clearly labelled heading, accessible via a direct link from every page, not buried inside lengthy terms and conditions. Where data collection happens on a specific page, such as a contact form, the policy or a direct link to it should be visible on that same page.
Special Considerations for Children’s Data
If your website contains content aimed at children, or knowingly collects data from users under 16, additional requirements apply, including obtaining appropriate parental consent and ensuring the policy itself is written in a way children and their parents can genuinely understand.
Comparing Privacy Policy Sections and Their Legal Basis
| Section | What It Covers | UK Legal Reference |
|---|---|---|
| Controller identity | Business name, contact details | Article 13, UK GDPR |
| Lawful basis | Justification for each processing activity | Article 6, UK GDPR |
| Data retention | How long data is kept | Storage limitation principle |
| User rights | Access, correction, deletion requests | Data Protection Act 2018 |
| Cookies | Tracking and analytics tools disclosure | PECR, alongside UK GDPR |
Common Mistakes to Avoid
- Copying a generic template without adapting it to reflect your actual data practices
- Burying the policy inside lengthy terms and conditions instead of making it easy to find
- Writing in dense legal language rather than clear, plain English
- Failing to update the policy as new tools, such as analytics or marketing platforms, are added
- Omitting a clear lawful basis for each specific type of data processing
Frequently Asked Questions
Do small websites and blogs need a privacy policy?
Yes, if they collect any personal data at all, including through contact forms, comments, newsletter sign-ups, or analytics tools. Website type and business size do not exempt a site from this requirement.
Is a privacy policy the same as a cookie policy?
Not exactly. A privacy policy covers all personal data handling broadly, while a cookie policy specifically details tracking technologies used on the site. Many businesses cover cookies briefly within the privacy policy and link out to a more detailed cookie policy.
How often should a privacy policy be updated?
It should be reviewed and updated whenever your data practices genuinely change, such as adding a new analytics tool or payment processor, rather than left static indefinitely once published.
Can I use a free privacy policy generator?
Generators can provide a useful starting structure, but the output still needs to be reviewed and adapted to accurately reflect your specific business’s actual data practices rather than published as-is.
Final Thoughts
A genuinely compliant privacy policy is less about legal phrasing and more about accuracy: it needs to reflect exactly what your website does with personal data, written clearly enough that an ordinary visitor can actually understand it. Mapping your real data practices before drafting, and revisiting the policy as those practices evolve, is what separates a policy that protects your business from one that merely exists.
