Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

How to Write a Privacy Notice for a Small Business

In short

A privacy notice tells people what you do with their personal data — and UK GDPR makes it a legal requirement, not an optional extra. It must cover who you are, why you process data, your lawful basis, who you share it with, how long you keep it, and people's rights. This guide gives you a plain-English structure and flags the gaps small businesses most often miss.

Start with what a privacy notice is for

A privacy notice (sometimes called a privacy policy) is simply how you tell people what you do with their personal data. Under the UK GDPR’s transparency principle, this isn’t optional — if you collect information about customers, staff, suppliers or website visitors, you have to explain what you’re doing in a way that’s concise, clear and easy to find.

A privacy notice is not a legal formality to bury in your website footer — it’s how you keep the promise the law makes on your customers’ behalf. Done well, it also builds trust and saves you time when someone asks a question.

If the underlying rules still feel hazy, our GDPR basics for UK small business guide is the place to start before you write a word.

What a privacy notice must cover

The UK GDPR (Articles 13 and 14) sets out the information you must give people. At a minimum, your notice needs to cover:

  • Who you are — your business name and contact details, and those of your data protection lead or DPO if you have one.
  • What data you collect — the categories of personal data, such as names, contact details, payment information or (if relevant) special category data.
  • Why you use it — the purposes for each type of processing, in plain terms.
  • Your lawful basis — the legal ground for each purpose (consent, contract, legal obligation, vital interests, public task or legitimate interests). If you rely on legitimate interests, say what they are.
  • Who you share it with — the recipients or categories of recipient, such as your accountant, payment provider or delivery courier.
  • International transfers — if you send data outside the UK, where it goes and what safeguard protects it.
  • How long you keep it — your retention periods, or how you decide them.
  • People’s rights — the rights to access, rectification, erasure, restriction, objection and portability, plus the right to withdraw consent where you rely on it.
  • The right to complain — that people can complain to the Information Commissioner’s Office (ICO).
  • Whether providing data is required — for example if it’s a statutory or contractual requirement, and what happens if they don’t provide it.
  • Any automated decision-making — including profiling that has a significant effect on people, and meaningful information about the logic involved.

If you obtain data from somewhere other than the individual — say you buy a marketing list or receive a referral — Article 14 also requires you to tell people where their data came from. This is one of the most commonly forgotten requirements.

A plain-English structure that works

You don’t need legal language. A clear, well-signposted notice usually flows like this:

  1. Who we are and how to contact us.
  2. The data we collect and where we get it from.
  3. How and why we use your data, with the lawful basis for each purpose.
  4. Who we share it with, and whether it leaves the UK.
  5. How long we keep it.
  6. Your rights, and how to exercise them.
  7. How to complain — to us, and to the ICO.
  8. Changes — when the notice was last updated.

For a website, a layered approach works well: a short summary up top with links or expandable sections for the detail. That keeps it readable without leaving anything out.

The gaps small businesses miss most often

Most privacy-notice problems aren’t outright omissions — they’re vagueness. Watch for these:

  • A generic template that doesn’t match reality. Copy-pasted notices often list processing you don’t do and miss things you do. It has to describe your business.
  • No retention periods. “We keep data for as long as necessary” on its own isn’t enough — give real timeframes or a clear method for setting them.
  • No lawful basis stated. Every purpose needs one, and you have to name it.
  • Vague sharing. “We may share your data with third parties” tells people nothing. Name the categories — payment processor, cloud provider, courier, accountant.
  • Ignoring Article 14. If you didn’t get the data directly from the person, you still have to tell them — and tell them the source.
  • Hard to find or out of date. A notice locked away, or last reviewed three years ago, undermines the whole point.
  • No mention of the ICO. People have the right to complain to the regulator, and your notice must say so.

Keep it findable and current

Publish your privacy notice where people actually give you data — your website footer, contact and checkout forms, and staff onboarding packs. Review it whenever you change how you handle personal data (a new CRM, a new supplier, a new marketing channel) and at least once a year. Date it so people can see it’s current.

Remember it works alongside your other obligations: if someone exercises their rights, you’ll need a process to respond — see our guide on how to handle a subject access request.

Getting help

A good privacy notice is honest, specific and readable — it reflects what you genuinely do, not what a template guessed. If you’d like a second pair of eyes on yours, or help mapping what personal data your business actually holds, get in touch and we’ll point you in the right direction.

Frequently asked questions

Is a privacy notice a legal requirement?

Yes. Under the UK GDPR's transparency principle, if you collect personal data about customers, staff, suppliers or website visitors you must tell them what you're doing with it, in a concise, clear and easily accessible way. A privacy notice is how you meet that duty.

What's the difference between a privacy notice and a privacy policy?

In practice they mean the same thing — how you explain your handling of personal data to the people it belongs to. 'Privacy notice' is the term the UK GDPR uses. Some businesses keep a separate internal 'privacy policy' for staff, but the public-facing document is what people need to see.

Do I need separate privacy notices for staff and customers?

Often, yes. You usually collect different data for different reasons from employees than from customers, so separate notices are clearer and more accurate than one document trying to cover everyone. The legal requirements are the same for each.

Can I just copy a privacy notice template?

A template is a useful starting structure, but copying one wholesale is risky. Generic notices frequently list processing you don't do and miss things you do. Your notice has to describe your business — your data, your purposes, your lawful bases and your retention periods.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.