How to draft and publish a website privacy policy
A clear Privacy Policy ensures your business stays on the right side of UK law while building essential trust with your visitors.
The bottom line: To comply with UK GDPR, you must provide a clear, easy-to-read Privacy Policy on your website that explains exactly what personal information you collect, why you need it, and how you keep it safe. Once drafted, a link to this policy must be visible on every page of your site—typically in the footer—so users can access it at any time.
Why do you need a Privacy Policy?
If your website collects any data—even something as simple as an email address for a newsletter or a name via a contact form—you are legally a 'data controller'. In the UK, the Data Protection Act 2018 and UK GDPR require you to be transparent about your data habits. Beyond the law, a clear policy builds trust; it shows your audience that you value their privacy and handle their information professionally.
What to include in your policy
You don't need a law degree to write this, but you do need to be thorough. Your policy should cover these key areas:
- Who you are: Provide your business name and contact details so people know who to reach out to regarding their data.
- What data you collect: Be specific. Do you collect names, email addresses, IP addresses (via cookies), or physical addresses for shipping?
- Why you collect it: Explain the purpose. For example, "We collect your email to send you our weekly newsletter."
- How you store and protect it: Mention that you use secure servers or encrypted services to keep their data safe from unauthorised access.
- Cookie information: Explain what cookies your site uses (e.g., for Google Analytics or to remember a shopping basket) and how users can opt out.
- User rights: Remind users they have the right to see the data you hold on them, the right to be 'forgotten' (deleted), and the right to correct any errors.
- The right to complain: You must state that users have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if they aren't happy with how you handle their data.
Steps to draft and publish
- Use a template: You don't have to start from scratch. The ICO website provides a free "Privacy notice template" specifically designed for small businesses and sole traders.
- Customise it: Ensure the language matches your business. Avoid "legalese"—the UK GDPR specifically requires that privacy notices are written in plain, easy-to-understand English.
- Add a Cookie Banner: If your website uses non-essential cookies (like tracking or marketing cookies), you should have a pop-up that asks for consent when a user first lands on your site.
- Publish in the footer: Create a dedicated page on your website (e.g., yourbusiness.co.uk/privacy-policy). Add a link to this page in your website’s footer menu so it is accessible from every single page.
Top Tip: Most small businesses in the UK that process personal data are also required to pay a data protection fee to the ICO. It usually costs about £35–£40 per year for a small business and is a separate requirement from having the policy itself.
Best practices
Keep it simple and keep it updated.
Don't just "set it and forget it." If you start using a new tool—for example, if you add a new email marketing platform or a Facebook tracking pixel—you must update your Privacy Policy to reflect that. Reviewing your policy once a year is a great habit to stay compliant and keep your customers' trust.
Created by hatch. • Updated on April 30, 2026