Privacy Policy Template

(UK GDPR)

Create your privacy policy with data collection notices, lawful basis statements, individual rights, and cookie disclosures.

Professionally drafted — structured following UK GDPR and Data Protection Act 2018 requirements for England and Wales.

One-time payment: £20
✓ Lifetime access • ✓ Lifetime updates • ✓ Fully editable • ✓ Based on UK law • ✓ Instant download
✅ 30-day money-back guarantee*
Build your policy first — preview every section before purchase. Only pay when you're happy.
Interview and editor — both included with your purchase.
📖 Need help?

Choose your method below to get started.

🎯 Two creation methods — same professional document

Whether you prefer step-by-step guidance or a traditional form, both methods produce the identical professionally-formatted privacy policy. Choose the style that suits you.

Recommended

Smart Interview

One screen at a time — less overwhelming, nothing missed.

Completion Time
~10 min
📋

Classic Form

Everything on one page — faster if you know what you need.

Completion Time
~7 min

🔒 Your data never leaves your device — saved locally in your browser only

♻️ Unlimited use — generate privacy policies for every website and project

📦 Save 40%: Get all 5 Legal & Compliance templates for £60

View Bundles →

Download a professionally drafted privacy policy template for UK websites and businesses. Also known as a data protection notice, privacy notice, or GDPR privacy statement. Covers data collection purposes, lawful basis for processing, individual rights, data retention periods, third-party sharing, international transfers, cookie disclosures, and data breach procedures. Structured following UK GDPR and the Data Protection Act 2018 requirements for England and Wales.

Who Needs a Privacy Policy?

Required by UK GDPR for any organisation collecting personal data — websites, apps, and businesses of all sizes.

🌐
Website Owners
Contact forms • Analytics • Email sign-ups
🛒
E-commerce Stores
Customer data • Payment info • Order history
📱
App Developers
User accounts • Device data • Usage analytics
💼
Service Businesses
Client records • Enquiries • Marketing lists
🏢
SMEs & Startups
Employee data • Supplier info • CRM systems
🎨
Freelancers
Portfolio sites • Client enquiries • Project files
📝
Bloggers & Creators
Newsletter subscribers • Comments • Affiliates
🏥
Healthcare Providers
Patient records • Appointments • Medical data
UK GDPR

Privacy Policy Requirements

What UK law requires you to tell people about their data

📋

What You Collect

Clearly explain what personal data you collect — names, emails, payment details, device information, and any other data.

🎯

Why You Collect It

State your lawful basis for processing — consent, contract, legal obligation, legitimate interests, or vital interests.

⚖️

Individual Rights

Explain how people can access, correct, delete, or port their data, and how to complain to the ICO.

UK GDPR and the Data Protection Act 2018 require every business collecting personal data to publish a privacy policy covering lawful basis for processing, data subjects' rights, retention periods, and third-party disclosures — failure to comply risks ICO fines of up to £17.5 million.▼ Tap below to read more

📋

What Must a Privacy Policy Include?

UK GDPR (Article 13 & 14) specifies what information you must provide to individuals when collecting their data.

Required Information:

  • Your identity: Business name, address, and contact details
  • Data Protection Officer: Contact details if you have one
  • What data you collect: Categories of personal data
  • Purpose of processing: Why you need each type of data
  • Lawful basis: Legal grounds for processing (consent, contract, etc.)
  • Recipients: Who you share data with (third parties, processors)
  • International transfers: If data leaves the UK
  • Retention periods: How long you keep data
  • Individual rights: Access, rectification, erasure, portability, objection
  • Right to withdraw consent: How to withdraw if consent is the basis
  • Right to complain: How to complain to the ICO
  • Automated decisions: If you use profiling or automated decision-making

Our template covers all required sections with clear, plain-English explanations.

The ICO can issue fines of up to £17.5 million or 4% of annual global turnover for serious UK GDPR breaches — common enforcement triggers include missing privacy policies, unlawful data sharing, and failure to respond to subject access requests within one month.▼ Tap below to read more

⚠️

Penalties for Non-Compliance

ICO Enforcement Powers:

  • Higher tier fines: Up to £17.5 million or 4% of annual global turnover (whichever is higher) for serious violations
  • Lower tier fines: Up to £8.7 million or 2% of annual turnover for less serious breaches
  • Enforcement notices: Orders to stop processing or change practices
  • Assessment notices: Compulsory audits of your data practices
  • Criminal prosecution: For certain offences like unlawfully obtaining data

Real ICO Fines (UK Examples):

  • British Airways: £20 million (reduced from £183m) — inadequate security
  • Marriott: £18.4 million — data breach affecting millions
  • Clearview AI: £7.5 million — collecting UK citizens' images without consent
  • Various SMEs: £1,000-£500,000 — marketing violations, inadequate policies

A proper privacy policy is your first line of defence against regulatory action.

This privacy policy template covers data collection purposes, lawful basis statements, individual rights sections, data retention schedules, third-party sharing disclosures, international transfer safeguards, cookie information, complaint procedures, and Data Protection Officer contact details.▼ Tap below to read more

🎯

What's Included in Our Template

Comprehensive Privacy Policy Coverage:

  • ✓ Organisation identity and contact details
  • ✓ Data Protection Officer information (if applicable)
  • ✓ Types of data collected
  • ✓ How data is collected (forms, cookies, third parties)
  • ✓ Purposes of processing
  • ✓ Lawful basis for each purpose
  • ✓ Third-party data sharing
  • ✓ International data transfers
  • ✓ Data retention periods
  • ✓ Individual rights (access, deletion, etc.)
  • ✓ How to exercise rights
  • ✓ Cookie information
  • ✓ Marketing communications
  • ✓ Security measures
  • ✓ Children's data (if applicable)
  • ✓ Policy updates notification
  • ✓ ICO complaint procedure

Related documents: Websites typically also need Cookie Policy, Terms & Conditions, and Data Processing Agreement.

Common privacy policy mistakes include copying American privacy notices that do not meet UK GDPR requirements, failing to specify a lawful basis for each processing purpose, omitting data retention periods, and not explaining how individuals can exercise their rights.▼ Tap below to read more

Common Privacy Policy Mistakes

Mistakes That Put You at Risk:

  • Copy-pasting from other sites: Generic policies often don't reflect your actual data practices — the ICO expects accuracy
  • Using US templates: American privacy laws differ significantly — "California residents" sections are irrelevant for UK businesses
  • Missing lawful basis: Every processing activity needs a legal ground — "we need your data" isn't sufficient
  • Vague retention periods: "As long as necessary" isn't specific enough — state actual timeframes
  • Forgetting third parties: Not disclosing analytics, payment processors, or marketing tools
  • No individual rights section: People have rights to access, delete, and port their data — explain how
  • Hiding the policy: Must be easily accessible — typically footer link on every page
  • Never updating: Policies must reflect current practices — update when data use changes

Our template guides you through each section with clear prompts to avoid these issues.

Frequently Asked Questions

Is a privacy policy legally required in the UK?

Yes. Under UK GDPR and the Data Protection Act 2018, any organisation that collects personal data must provide clear information about how that data is used.

This applies to websites, apps, and any business collecting customer information — even small businesses and sole traders.

What must a UK GDPR privacy policy include?

UK GDPR requires specific information: your identity and contact details, what data you collect, why you collect it (lawful basis), how long you keep it, who you share it with, individual rights (access, deletion, portability), how to withdraw consent, and how to complain to the ICO.

Our template covers all required sections.

Do I need a privacy policy for a small website?

Yes. Even small websites typically collect personal data through contact forms, email sign-ups, analytics (like Google Analytics), or cookies.

If you collect any personal data — even just names and email addresses — you need a privacy policy regardless of business size.

What's the penalty for not having a privacy policy?

The ICO can issue fines up to £17.5 million or 4% of annual global turnover for serious GDPR breaches. For smaller violations, fines up to £8.7 million or 2% of turnover apply.

Beyond fines, you risk reputational damage and loss of customer trust.

Do I need separate privacy and cookie policies?

You can combine them or keep them separate. Many businesses include cookie information within their privacy policy.

However, a separate cookie policy can be clearer for users and easier to update when you change cookies. Our privacy policy template includes cookie sections, but we also offer a dedicated cookie policy template.

What if UK GDPR changes after I purchase?

You receive free lifetime updates — no subscription required, no monthly fees, ever.

We monitor ICO guidance and UK data protection law changes. When we release an updated version, it appears free in your My Templates page. No extra charges. No recurring fees.

Is this really £20 one-time, or will I be charged monthly?

£20 one-time. That's it. No subscriptions, no recurring fees, no "free trial" traps.

Here's what we don't do: Other sites advertise "free templates" — you spend 15 minutes filling one in, then they demand your card for a "free trial" that charges £35–£42/month when you forget to cancel. Worse, many are US-based and don't cover UK GDPR requirements. (Read about the scam)

We're different: £20 upfront for the document you actually need. Build it, preview it, pay only when you're happy. Own it forever with free lifetime updates. Based on UK GDPR. No subscription fatigue.

Not sure where to start?

30-Day Money-Back Guarantee

We stand behind every template we sell. If something's technically wrong, we'll make it right.

You're Covered If:

  • File is corrupted or won't open
  • Missing content described on product page
  • Technical errors prevent use as described
  • File format incompatibility that prevents editing

Why you probably won't need this: You can preview the full template with watermark before purchase – so you'll know exactly what you're getting.


Bought the Wrong Template?

Mistakes happen – we get it. Within 30 days, here's how we can help:

Template Swap: We'll cancel your original and issue a different template of equal or lesser value.

Store Credit: Full purchase amount to use on any template. Never expires.

Offered at our discretion for genuine mistakes – we reserve the right to decline repeat or unreasonable requests.


How to Request:

Email [email protected] within 30 days with your order number.

We aim to respond within 2 business days. Approved refunds processed within 5 business days.