top of page

Writing a privacy notice people can read and you can honour

  • Aug 29
  • 3 min read

Updated: 2 days ago

Introduction


A privacy notice is copied from another website, the company name is changed, and it goes live. It mentions data transfers the business does not make, a data protection officer it does not have, and retention periods nobody follows.

It is simultaneously a legal requirement, a public statement about what you do, and a description of a business other than yours. If somebody ever compares what it says with what actually happens, the gap is the problem rather than the absence of a notice would have been. Writing one that is accurate takes an afternoon. And it produces a document that is both compliant and actually true.


1. Writing a privacy notice people can read starts with what you actually do


Not with a template.

The notice describes your processing, so the inventory of what you hold and why comes first. A notice written before that exercise is necessarily fiction, however professionally it reads.


2. Cover what most regimes require


A reasonably consistent list.

Who you are and how to contact you, what data you collect, why, your lawful basis, who you share it with, how long you keep it, whether it goes abroad, and what rights people have including how to complain. Check the specifics for your jurisdiction.


3. Write it in ordinary language


Both a requirement and the point.

Most frameworks require notices to be concise, transparent and intelligible. A page of legal construction satisfies neither the regulator nor the reader, and the reader is who it is for.


4. Be specific about who you share data with


The section most often vague.

Categories of recipient, or better still the actual services: your accounting software, your email provider, your delivery company, your payment processor. Vagueness here is what makes a notice look copied.


5. State retention periods you will actually honour


A commitment, not an aspiration.

Saying you keep data only as long as necessary means nothing. Stating periods for each category, and then applying them, is what makes the notice true and gives you a basis for deleting things.


6. Explain rights and how to exercise them


Practical rather than theoretical.

What people can ask for, how to ask, and what happens next. A named contact or an address monitored by somebody is more useful than a legal formulation of the rights themselves.


7. Have separate notices where the audiences differ


Customers, staff and applicants.

An employee privacy notice covers quite different processing from a customer one, and job applicants different again. One notice attempting to cover all three usually serves none of them properly.


8. Make it findable and present it at the right moment


Not only in the footer.

Linked at the point data is collected — on the form, at checkout, on the enquiry page — as well as being permanently available. Collecting data without pointing to the notice defeats the purpose.


9. Keep it current


It describes a moving business.

New systems, a new supplier, a new marketing platform or a change in what you collect all affect it. An annual review, plus an update whenever something changes, keeps the document honest.

Read it as a customer would before publishing. If it does not tell somebody plainly what happens to their information, it has failed its actual purpose regardless of whether it satisfies a checklist, and the version that reads clearly is generally the version that is also accurate.


Conclusion


Describe your own processing rather than adapting somebody else's notice.

Complete your data inventory first because the notice depends on it, cover the elements your jurisdiction requires, write in plain language because that is both the rule and the point, name the actual services you share data with, state retention periods you will genuinely apply, explain rights and give a real route to exercise them, produce separate notices for customers, staff and applicants, link it at the point of collection rather than only in the footer, and review it annually and on change.


Related reading


 
 
 

Comments


bottom of page