Privacy Policy
A Privacy Policy is a legal document that explains how an organisation handles personal data. For a UK business, this must be transparent, concise, and easily accessible.
1. Controller Identity
You must clearly state who is responsible for the data.
- Company Name: Registered business name.
- Contact Details: Email address, phone number, and physical office address.
- Data Protection Officer (DPO): If the business is large or processes sensitive data on a large scale, contact details for the DPO must be included.
2. What Data is Collected
Categorise the data types you process:
- Identity Data: Names, usernames, titles.
- Contact Data: Billing addresses, delivery addresses, email addresses, phone numbers.
- Technical Data: IP addresses, login data, browser types, operating systems (often related to cookies).
- Financial Data: Bank account and payment card details.
3. Lawful Basis for Processing
Under UK GDPR, you must have a valid legal basis to process data. You should disclose which of these you rely on for different activities:
- Consent: The user has given clear consent.
- Contract: The data is necessary for a contract (e.g., fulfilling an order).
- Legal Obligation: You are required to process the data by law (e.g., tax records).
- Legitimate Interests: Processing is necessary for your legitimate interests (and these are not overridden by user rights).
4. How Data is Used
Explain the purpose of the collection in plain English (e.g., “to register you as a new customer,” “to process your order,” “to manage our relationship with you”).
5. Data Sharing (Third Parties)
You must disclose if you share data with:
- Service providers (e.g., payment processors like Stripe, email marketing tools like Mailchimp).
- Regulators or law enforcement if required by law.
- External third parties (explain why).
6. International Transfers
If you transfer data outside the UK (e.g., using a US-based cloud host), you must explain the safeguards in place to protect that data (e.g., Standard Contractual Clauses or UK-US Data Bridge).
7. Data Retention
State clearly how long you keep the data. You must not keep personal data for longer than is necessary for the purposes for which it was collected.
8. User Rights
Your policy must inform users of their rights under the UK GDPR:
- Right to Access: Request a copy of their personal data.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure (Right to be Forgotten): Request deletion of data.
- Right to Restrict Processing: Limit how you use their data.
- Right to Data Portability: Request a transfer of data to another service.
- Right to Object: Object to processing based on legitimate interests.
9. Cookies and Tracking
Even if you have a separate Cookie Policy, a summary or a link to it must be included within your Privacy Policy.
10. How to Complain
Users have the right to lodge a complaint with the Information Commissioner’s Office (ICO). Include a link to the ICO website.