Privacy Notice & Data Protection Policy for a Small Business (UK GDPR): What to Include

Draft my Document →

Privacy Notice & Policy — eLitigant

Last reviewed: June 2026 · For use in England & Wales · eLitigant is a Community Interest Company (No. 16566612), not a law firm and does not give legal advice.

In short

A privacy notice tells people whose personal data you handle who you are, what data you collect, why, your lawful basis, who you share it with, how long you keep it, their rights, and how to complain. A short internal data protection policy sets out how your business meets the UK GDPR and Data Protection Act 2018. Since 19 June 2026 every organisation must also offer a clear complaints route. eLitigant’s Chris drafts this for you — you check, sign and send.

What a privacy notice and data protection policy are

A privacy notice (sometimes called a privacy policy or fair processing notice) is the public-facing document that tells individuals — customers, website visitors, enquirers, employees — how your business uses their personal data. Under the UK GDPR (Articles 13 and 14) and the Data Protection Act 2018, you must give this information in a way that is concise, transparent, intelligible, easily accessible and written in plain language.

A data protection policy is an internal document. It is not strictly required for the smallest organisations, but the Information Commissioner’s Office (ICO) treats having one as good practice and evidence of accountability. It records how your business meets its obligations: who is responsible, how you keep data secure, how long you retain records, and how you handle individual rights requests and complaints.

The two work together. The privacy notice is what the public sees; the policy is how you actually deliver on it.

When and why you need them

If your business collects or holds any personal data — names, emails, phone numbers, payment details, addresses, even an enquiry form — you are a “controller” and the UK GDPR applies. There is no exemption for being small. You must provide privacy information at the time you collect data from someone directly (Article 13), or within a reasonable period, and at the latest one month, when you obtain it from another source (Article 14).

A clear privacy notice builds trust, satisfies the law, and reduces the risk of an ICO complaint or enforcement notice. The ICO has found that vague, boilerplate notices that fail to specify lawful bases, recipients, transfers and retention periods do not meet the transparency principle.

New duty from 19 June 2026: under section 103 of the Data (Use and Access) Act 2025 (DUAA), every organisation that processes personal data must have a clear process for handling data protection complaints. You must accept complaints however they reach you, acknowledge receipt within 30 days, and investigate without undue delay. Your privacy notice should signpost this route. The DUAA amends — it does not replace — the UK GDPR and the Data Protection Act 2018.

What to put in a privacy notice

Articles 13 and 14 of the UK GDPR set the minimum content. A compliant notice for a small business should cover:

  • Who you are — the controller’s name, trading name and contact details (and a data protection officer’s details if you have one; most small businesses do not need a DPO).
  • What data you collect — the categories of personal data (for example contact details, order history, payment information).
  • Why, and your lawful basis — the purpose of each use and which of the six lawful bases applies (consent, contract, legal obligation, vital interests, public task or legitimate interests). The DUAA added a seventh basis, “recognised legitimate interests.” If you rely on legitimate interests, state what they are.
  • Who you share it with — the recipients or categories of recipient (payment processors, couriers, accountants, IT providers).
  • International transfers — whether data leaves the UK and the safeguards used.
  • Retention — how long you keep data, or the criteria you use to decide.
  • Individual rights — access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent where consent is the basis.
  • How to complain — your internal complaints route, plus the right to complain to the ICO (ico.org.uk).
  • Whether providing data is required — for example to fulfil a contract, and what happens if it is not provided.
  • Automated decision-making — if you carry out solely automated decisions with significant effects, say so and explain the logic.

An internal data protection policy adds: who is accountable, your security measures, breach reporting (the ICO must usually be told within 72 hours of a notifiable breach), staff handling rules, and how you log and respond to rights requests and complaints.

Common mistakes and pitfalls

  • Copy-and-paste boilerplate. A generic notice that does not reflect what your business actually does fails the transparency test. Name your real recipients, purposes and retention periods.
  • No lawful basis stated. Saying “we process your data lawfully” is not enough — identify the specific basis for each purpose.
  • Treating consent as the default. Consent must be freely given, specific and withdrawable; for most ordinary business processing, contract or legitimate interests fit better.
  • Forgetting the new complaints route. From 19 June 2026 the notice should tell people how to complain to you, not only to the ICO.
  • Hiding the notice. It must be easy to find — typically linked in your website footer and given at the point of data collection.
  • Never reviewing it. Update the notice whenever you change what you collect, why, or who you share it with.

Frequently asked questions

Do I need to register with the ICO? Most organisations that process personal data must pay the ICO a data protection fee unless they qualify for an exemption. This is separate from having a privacy notice. Check your status on the ICO website.

Do I need a data protection officer (DPO)? Usually not. A DPO is mandatory only for public authorities or where your core activities involve large-scale or special-category monitoring or processing. Most small businesses simply name a responsible person.

Is a privacy notice the same as a cookie policy? No. Cookies and similar technologies are governed mainly by the Privacy and Electronic Communications Regulations (PECR). Many businesses keep a separate cookie policy and consent banner alongside the privacy notice.

This guide is information about the UK GDPR and the Data Protection Act 2018, not legal advice. eLitigant is not a law firm. We help you draft your own documents, which you check, sign and send.

Draft my Document →

eLitigant drafts it; you check, sign & send. Not a law firm; information, not advice.

See it done — what Chris drafts for you

A worked example, drafted to a professional standard from your details — ready for you to check, personalise and send. Fictional sample.

CHRIS DRAFTED 📋

PRIVACY NOTICE

Willowbrook Crafts Ltd
Last updated: 10 June 2026

1. Who we are

Willowbrook Crafts Ltd (“we”, “us”) is the data controller responsible for your personal data. We are a company registered in England and Wales (company no. 12345678), trading from 14 Mill Lane, Harborne, Birmingham B17 9XX. For any data protection query you can contact Priya Sharma at privacy@willowbrookcrafts.co.uk or on 0121 496 0000.

2. The personal data we collect

We collect: your name, delivery and billing address, email address and telephone number; details of orders you place; payment information (processed securely by our payment provider, not stored by us); and any messages you send us through our website contact form.

3. Why we use it, and our lawful basis

We use your data to fulfil and deliver your orders and provide customer support (lawful basis: performance of a contract); to keep accounting and tax records (lawful basis: legal obligation); and, where you have given consent, to send you occasional newsletters. We rely on our legitimate interests to prevent fraud and to improve our products and service.

4. Who we share it with

We share data only as needed with our delivery partner (Swiftline Couriers), our payment processor, our accountant, and our website and email providers. We do not sell your data. We do not transfer your data outside the UK.

5. How long we keep it

We keep order and accounting records for six years to meet HMRC requirements. Marketing contact details are kept until you unsubscribe. Enquiry messages are deleted after 12 months.

6. Your rights

You have the right to access your data, to have inaccurate data corrected, to request erasure or restriction, to object to certain processing, to data portability, and — where we rely on consent — to withdraw that consent at any time. To exercise any right, email privacy@willowbrookcrafts.co.uk and we will respond within one month.

7. How to complain

If you are unhappy with how we have handled your personal data, please contact Priya Sharma using the details above. We will acknowledge your complaint within 30 days and investigate it without undue delay. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.

This is a fictional worked example for illustration only. Names, figures and addresses are invented.

Ready to get yours drafted?

Chris drafts it from your details to a professional standard in minutes — you check, sign and send.

Draft my Document →

Related guides

Practical court-preparation tips — free to your inbox

Scroll to Top

Discover more from eLitigant

Subscribe now to keep reading and get access to the full archive.

Continue reading

Contains public sector information licensed under the Open Government Licence v3.0. Crown copyright forms and guidance are reproduced under that licence.