Blog

GDPR Privacy Notices: What Businesses Need to Include

Under the UK GDPR, a privacy notice helps explain how an organisation collects, uses, shares, and protects personal data. Clear privacy information supports transparency, helps people understand their rights, and forms an important part of practical GDPR governance.

Estimated reading time: 6 minutesTopic: GovernanceRelated terms: Privacy notice and Transparency
Quick answer

What a GDPR privacy notice means in practice

A GDPR privacy notice explains how an organisation collects, uses, shares, stores, and protects personal data. Under the UK GDPR, privacy information should be clear, accessible, and specific enough for people to understand what is happening to their data and what rights they have.

Must explain

What data is collected, why it is used, and who it may be shared with

Must be

Clear, easy to find, and written in plain language

Must support

Transparency, accountability, and individual data rights

Section one

Why privacy notices matter under UK GDPR

Privacy notices are a key part of transparency under UK GDPR. They help people understand how their information is used before, or at the point, their data is collected. They also help businesses show that they have thought clearly about their processing activities.

Transparency

People need to know what is happening

A privacy notice should explain data use clearly enough that people can understand who is collecting their data, why it is being used, and what choices or rights they may have.

Trust

Clear information builds confidence

A vague or hidden privacy notice can make a business look disorganised or risky. A clear notice reassures people that data protection has been considered properly.

Accountability

It supports evidence of compliance

A privacy notice is not enough on its own, but it is an important part of demonstrating accountability and showing that processing is being explained properly.

Privacy notices sit alongside broader compliance work, including lawful basis decisions, data mapping, retention periods, supplier checks, and individual rights processes.

Section two

What a privacy notice should include

The exact wording depends on the organisation and the processing, but most privacy notices need to cover the same core areas. The aim is to give people meaningful information, not just legal wording.

What personal data is collected

It should explain the types of personal data used, such as contact details, account information, enquiry details, website data, payment data, or communication records.

Why the data is used

The notice should describe the purposes of processing and connect those purposes to the relevant lawful basis.

Who data may be shared with

People should be told about relevant categories of recipients, such as IT providers, payment processors, professional advisers, marketing platforms, or regulators.

Section three

When businesses need to provide privacy information

Privacy information should usually be provided when personal data is collected directly from the person, or within a reasonable period if the data is obtained from another source.

Direct collection

Tell people at the point their data is collected

This often applies to website forms, checkout pages, account sign-ups, enquiry forms, newsletter sign-ups, booking forms, and client onboarding documents.

Indirect collection

Explain data use when information comes from elsewhere

If data is received from another organisation, public source, referral partner, supplier, or lead source, the business may still need to give privacy information.

Marketing needs careful wording

If a business uses personal data for marketing, the privacy notice should explain how marketing data is used, what lawful basis applies, and how people can object or opt out. See Direct Marketing and GDPR and What is PECR? for related rules.

Section five

Examples of where privacy notices are needed

Privacy notices are not only for large organisations. Most businesses that collect customer, client, staff, supplier, website, or lead data need some form of clear privacy information.

Website enquiry forms

If people submit their name, email address, phone number, or message through a website, the business should explain how that information will be used.

Customer and client onboarding

When collecting client details, billing data, project information, or service records, a privacy notice helps explain how that data will be handled.

Marketing sign-ups

Newsletter forms, lead magnets, downloads, and marketing lists should explain how marketing data is used and how people can opt out or object.

Staff and recruitment data

Businesses should also explain how they use employee, contractor, applicant, and recruitment data, especially where records are kept after a role is filled.

Why this matters

If privacy information is missing, unclear, or inaccurate, the organisation may struggle to evidence transparency and accountability. It can also make complaints, subject access requests, and trust issues harder to manage.

Grounded in

What this article is grounded in

This article is based on ICO guidance on the right to be informed, privacy notices, and transparency under the UK GDPR, together with the legal requirements that explain what organisations must tell people when they collect or use personal data. It connects closely to wider duties around transparency, lawful basis, accountability, and individual rights such as subject access requests.

Next step

Keep building your understanding

Use the glossary for key terms, or download the checklist if you want a practical starting point for reviewing privacy notices, lawful basis wording, website forms, marketing sign-ups, supplier disclosures, retention wording, and individual rights information.

Future Implementation Support Waitlist