A privacy notice explains how an organisation uses personal information. It should be based on the business's actual activities, not a copied list of every possible purpose. Start by identifying the people whose information you hold and the processes through which you collect and use it.
Separate customer, applicant and employee information where their circumstances differ. Check the notice against forms, marketing systems and supplier contracts. If a statement is inaccurate, correct the process or the explanation rather than leaving a polished policy that staff cannot follow.
Build the notice from a real customer journey
Take one recent enquiry and trace what happened after submission. For a small consultancy, the enquiry might reach an inbox, become a contact record and enter a proposal system. Write down which organisation makes decisions at each stage. A trading name alone may leave readers uncertain about the legal entity responsible. Include a contact route that somebody actually monitors, and explain how a person can raise a data protection concern without first becoming a paying client.
Create a short purpose list before drafting prose: answering enquiries, providing the agreed service, issuing invoices and maintaining necessary business records. For each purpose, identify the information used and the applicable lawful basis. Avoid presenting several bases as interchangeable possibilities. Readers should be able to connect a particular use to its explanation. Where a purpose involves especially sensitive information, the assessment needs more than a general statement about legitimate interests.
Decide what readers need at collection
The ICO's transparency checklist covers identity, purposes, legal bases, recipients, retention, relevant rights and other information depending on the circumstances. Check the full list against your collection method, including information obtained from another source. [1] A short form notice can highlight the immediate use and link to fuller information. It should not conceal an unexpected onward disclosure behind a vague phrase about trusted partners.
Give the designer concrete instructions. Place the relevant link beside the form, use readable text and make the full notice accessible without registration. Check the mobile version and the confirmation message as well as the desktop footer. Save a copy of what was displayed when a new collection process launched. This helps answer later questions about the explanation a customer actually received, rather than the explanation currently on the website.
Make retention and sharing descriptions useful
Ask the finance and operations teams how they distinguish an abandoned enquiry from a completed engagement. If different records have different retention triggers, explain those categories instead of promising that everything disappears immediately when a customer leaves. Avoid publishing an exact period before confirming that the systems can apply it. A defensible criterion can be more accurate than a convenient number copied from another firm's notice.
Describe meaningful recipient categories and explain relevant overseas processing. Do not confuse a supplier's security certificate with the legal basis for disclosure. Keep detailed supplier checks in the internal file; the public notice should give understandable information about actual use. The related guide to Creating a personal data retention schedule helps turn retention descriptions into an operational schedule, while Collecting information through website forms addresses the collection point where customers first encounter the wording.
Run a notice change through the business
Before approving a revision, ask the person handling enquiries to test it against three questions: where does an unanswered enquiry go, who sees an attachment, and what happens after the person objects to marketing? Any uncertain answer needs an operational decision. Then nominate an owner for changes in suppliers, purposes or collection fields. A dated review is useful only if somebody knows which business changes should trigger it.
For a review through Business privacy notice review, prepare the proposed notice, screenshots of collection points and a concise list of actual processing activities. State which statements remain unverified. The review should produce specific wording and process corrections, with responsibilities for implementation. Publishing a polished document while leaving contradictory automation running will not solve the underlying transparency problem.
Check the notice against a complaint
Imagine a former prospect asks why their details appeared in a new campaign. Retrieve the notice supplied at the original enquiry, the purpose recorded at that time and the later marketing decision. If these records tell different stories, correct the underlying process before publishing another version. A current notice cannot establish what the person was told several months earlier.
Keep a small version register showing effective dates, changed activities and the person who confirmed each factual statement. Include notices embedded in booking software or supplied on paper. This makes a correction manageable when one business uses several collection channels, and helps staff provide the appropriate explanation when a customer queries an older interaction.
Illustrative scenario
A consultancy's website says it only uses enquiry details to respond, but every enquiry is automatically added to a newsletter. The review identifies a mismatch between the notice and marketing workflow. The business assesses the marketing position and changes the process and wording together, rather than adding an unexplained blanket permission.
Preparation checklist
- List the people, data categories and purposes covered.
- Confirm the organisation’s identity and contact route.
- Check recipients, retention and relevant rights information.
- Keep a dated notice version and review it when processes change.
Frequently asked questions
Does every form need the whole privacy notice?
Usually a clear contextual explanation and an accessible link to the full notice work better than repeating a long document. The information provided must still match the collection and its timing.
Who should approve the factual descriptions?
The people responsible for the relevant systems and activities should confirm them. Legal drafting alone cannot establish whether an export, integration or retention setting is described accurately.
Should the notice name every software feature?
It should explain relevant processing intelligibly. Keep a detailed internal inventory, then decide which provider information or recipient categories the public explanation needs for that particular activity.
When should we revise an existing notice?
Review it when purposes, recipients, collection methods or other material facts change. Assess the underlying activity before editing the wording and keep evidence of the version supplied.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction