Template guide

Privacy Policy Template (UK) — GDPR-Ready, In Plain English

If your website collects so much as an email address, UK GDPR requires you to tell people what you collect, why, on what legal basis, who you share it with, how long you keep it, and what their rights are. Most small-business privacy policies are either copied from a US site (wrong law), generated by a form-filler (describes a business that isn't yours), or missing entirely. This template is the fourth option: a plain-English UK policy you adapt honestly to what your business actually does, with guidance notes explaining every decision.

Get the Privacy Policy template

Buy the individual template, or start with the free Starter Pack — no card required.

When you need one

Effectively always: a contact form, a newsletter signup, an order checkout, or analytics cookies each trigger the transparency duties. The obligations scale with what you do — a policy for a site that collects newsletter emails is short; one for a business taking payments and running analytics has more to say — which is why this template is modular: keep the sections that describe your reality, delete the rest.

What's in this template

Twelve sections covering the full UK GDPR disclosure list: who you are as controller, the categories of data you collect, a purposes-and-lawful-bases table (the heart of the document — each use of data matched to contract, consent, legal obligation or legitimate interests), marketing rules including the "soft opt-in" for existing customers, who you share data with, international transfers and their safeguards, retention periods, cookies, security, the full set of individual rights with how to exercise them, children's data, and how changes are communicated. Amber guidance notes explain the judgment calls — when analytics cookies need a real consent banner, when the soft opt-in applies, why claiming more than you do is worse than saying less.

The one rule that matters

A privacy policy must describe reality. Publishing a beautiful policy that says you don't share data while your site quietly runs advertising pixels is worse than no policy at all — every inaccuracy converts routine processing into a broken promise, and it's the first thing a complainant or the ICO will check. That's why this template is built for deletion: it's faster to cut sections that don't apply than to discover, mid-complaint, that your policy describes someone else's business.

Common mistakes to avoid

Copying a US privacy policy (CCPA language, no lawful bases, wrong regulator); listing data you don't actually collect "to be safe"; running analytics or ad cookies with a banner that doesn't actually block them until consent; forgetting the ICO's data protection fee — a separate legal duty most UK data-processing businesses owe annually; and never updating the policy when the business changes tools. If you'd like a second pair of eyes before you publish, our Contract Confidence Check covers policies as well as contracts.

Frequently asked questions

HarbourDesk templates are practical starting points, not legal advice. See our Terms of Service.

Get the Privacy Policy template

Buy the individual template, or start with the free Starter Pack — no card required.

Related templates