Templates are provided by Net Lawman. We may receive a commission at no extra cost to you.
If you run a website that collects any information about visitors, even something as simple as an email sign-up form or a contact enquiry, you need a privacy policy. It is not optional. UK data protection law requires you to tell people what you do with their personal information, and a privacy policy is how you meet that duty in a form visitors can actually read.
This page walks through what a website privacy policy is for, what it should cover, and the legal backdrop that shapes it in England and Wales. Whether you run a small blog, an online shop, or a professional services firm, the same core principles apply.
I have also included a set of common questions I get asked by founders and small business owners who are trying to get this right without hiring a full legal team.
What this document is
A website privacy policy is a public-facing notice that sets out how your site handles personal information belonging to visitors, customers, and anyone else whose data you process. It sits alongside your terms of use and cookie notice as one of the core legal documents every site should have.
Under the UK GDPR and the Data Protection Act 2018, anyone acting as a 'data controller' has to give individuals clear information about how their data is used, who it is shared with, how long it is kept, and what rights they have. A privacy policy is the standard way of doing this.
It is usually linked from the footer of every page so it is accessible wherever personal data might be collected, for instance on a checkout page, a newsletter form, or a contact form. The document is not just a legal box-tick.
It tells visitors what to expect and signals that you take their privacy seriously, which matters for trust and for conversion. A well-drafted policy is specific to how your particular site actually works, rather than a generic block of text copied from somewhere else.
How to use this document
Map the personal data you actually collect. Before you write a word, list every point on your site where personal data is gathered. This includes obvious things like contact forms and account sign-ups, but also analytics cookies, chat widgets, payment processors, and anything else that touches user information. You cannot describe your practices accurately if you do not know what they are.
Identify your lawful basis for each use. The UK GDPR requires you to rely on one of six lawful bases when processing personal data, such as consent, contract, or legitimate interests. Different activities on your site may rely on different bases. Marketing emails, for example, usually depend on consent, whereas fulfilling an order relies on contract. Your policy should reflect this accurately.
List your third parties and international transfers. If you use tools like Google Analytics, Mailchimp, Stripe, or any hosted service, personal data is being shared with those providers. Some of them transfer data outside the UK. Your privacy policy needs to name the categories of recipient and address any international transfers, including the safeguards in place.
Set out individual rights and how to exercise them. Visitors have rights including access, rectification, erasure, restriction, objection, and data portability. Your policy must explain these rights in plain language and tell people how to contact you to use them. Include a dedicated email address or postal contact for data protection queries.
Publish, link, and keep it current. Put the policy somewhere easy to find, typically the site footer, and link to it from every form that collects data. Review it whenever you add a new tool, change a supplier, or start processing data for a new purpose. A privacy policy is a living document, not something you set once and forget.
Template · England & Wales
Put your website privacy policy in place
This is a 'boilerplate' privacy policy template that can be easily edited for any UK hosted website. We provide this document for download and use completely free of charge.
Templates are provided by Net Lawman. We may receive a commission at no extra cost to you.
Common questions
Q Do I legally need a privacy policy for my website in the UK?
Yes, if your site collects any personal data from visitors, and almost every site does. The UK GDPR and the Data Protection Act 2018 require you to give individuals specific information about how their data is handled. A privacy policy is the standard way to provide this. Even a simple contact form or analytics tool triggers the obligation, so the practical answer for most websites is that a policy is required.
Q What happens if I do not have a privacy policy?
You may be in breach of UK data protection law, and the Information Commissioner's Office can take enforcement action ranging from warnings to financial penalties depending on the circumstances. You also expose yourself to complaints from visitors and customers. Beyond the legal risk, missing or inadequate privacy information damages trust and can affect relationships with payment providers and advertising platforms that require compliant policies.
Q Can I copy a privacy policy from another website?
It is a bad idea for two reasons. First, the policy will almost certainly not match how your site actually operates, which means it will be inaccurate and potentially unlawful. Second, the text may be protected by copyright. Your policy needs to reflect your own data practices, your own third parties, and your own contact details. A generic copy-paste job usually creates more risk than it solves.
Q How is a privacy policy different from a cookie notice?
They overlap but are not the same. A cookie notice, often delivered through a consent banner, deals specifically with cookies and similar tracking technologies and the choices users have about them. A privacy policy is broader and covers all personal data processing on the site. Many sites have both, with the privacy policy referencing the cookie notice for detail on tracking.
Q How often should I update my privacy policy?
Review it at least once a year and whenever something material changes, such as adding a new analytics tool, switching email provider, starting to sell internationally, or launching a new feature that collects different data. When you make significant changes, it is good practice to note the date of the latest update at the top of the policy and, for important changes, notify existing users directly.
Q Do I need to register with the ICO as well?
Most UK organisations that process personal data need to pay a data protection fee to the Information Commissioner's Office unless an exemption applies. This is separate from having a privacy policy. You can check whether you need to pay and what the current fee is on the ICO's website. Registration and the policy work together as part of your overall compliance.
Q Does my privacy policy need to mention children?
If your site is likely to be accessed by children, or you knowingly collect data from them, yes. The UK has specific protections for children's data, including the Age Appropriate Design Code. Your policy should explain how you handle children's data, what age verification you use if any, and how you obtain parental consent where that is required by law.
Brad is on the roll of solicitors of England & Wales but does not hold a practising certificate and does not provide legal advice. LegalDocuments.co.uk is not a law firm and does not provide regulated legal advice.
This article is for general information only. It is a tool to help you find your way — not legal advice, and not a substitute for speaking to a qualified adviser about your situation.