Human resources at a click

GDPR Privacy Policies: Key requirements for organisations

people, office, desk, meeting, laptops

When an organisation is creating a website or app to reach users or potential customers drafting a Privacy Policy may be an afterthought. However, failure to write a Privacy Policy, which complies with the relevant legislation, can have serious consequences.

Legal requirements of a Privacy Policy

A Privacy Policy (otherwise known as a Privacy Notice) is a legal document that explains to users what an organisation is doing with their data. The Data Protection Act 2018 (DPA 2018) defines data as any information relating to an identified or identifiable living individual e.g. names, phone numbers, national insurance numbers. If an organisation holds personal data, which is generally all organisations, they will need a Privacy Policy.

The UK General Data Protection Regulation (GDPR) places a duty on organisations to inform individuals on what happens when their data is collected. Articles 13 and 14 of the GDPR state what must be included in a Privacy Policy:

  • Data controller’s identity
  • What personal data are collected
  • How personal data are collected
  • Why personal data are collected
  • When personal data are shared
  • What choices individuals have
  • How long personal data are kept
  • What rights individuals have, including the right to withdraw consent and complain

However, complying with these content requirements is not enough. The Privacy Policy must also be provided to individuals in a “concise, transparent, intelligible and easily accessible form, using clear and plain language”. Additionally, important information should not be buried in long, difficult to navigate text.

The consequences of having a poorly drafted Privacy Policy

A poorly drafted Privacy Policy can result in several financial and reputational consequences for an organisation.

Penalties for noncompliance:

The Information Commissioner’s Office, the UK’s data protection regulator, has the right to enforce various penalties for breaches of GDPR. These penalties include:

  • Substantial fines (up to £17.5 million, or up to 4 percent of the total worldwide annual turnover of the preceding financial year)
  • Enforcement action requiring an organisation to rectify their noncompliance

Legal action and compensation claims:

Under GDPR individuals can sue organisations for compensation if they believe their data protection rights have been violated.

Damages to customer trust and reputation risks:

If a Privacy Policy does not comply with GDPR customers may view an organisation as not respecting data privacy rights. Business partners and third parties may also reconsider their relationships with noncompliant organisations.

Overall, a well-drafted Privacy Policy will not just help your organisation comply with mandatory legal rules but will also help foster trust with individuals by demonstrating your commitment to good data-processing practices.

A poorly drafted Privacy Policy can result in several financial and reputational consequences for an organisation.

Practical steps to ensure compliance with GDPR

The following are some steps that your organisation can take to ensure compliance with data protection legislation:

  • Ensure your Privacy Policy complies with Articles 13 and 14 GDPR
  • Ensure your Privacy Policy is easily accessible when users visit your website (ideally a link to the policy should appear on every page, especially on the homepage)
  • Your Privacy Policy should not be too long, burying important information
  • Your Privacy Policy should not be vague or use ambiguous language
  • The Privacy Policy should allow users to withdraw their consent to their data being processed
  • If you already have a Privacy Policy on your website review it constantly to ensure it complies with any new legislation

Data protection is a legal obligation. So, every organisation, however small, needs a GDPR compliant Privacy Policy when processing people’s data.

How our data protection team can help

Our data protection team assist organisations with dealing with potential and actual data protection breaches and DSAR compliance including assisting organisations in updating their policies and training.  Please do not hesitate to get in contact with a member of the team.

Disclaimer This information is for guidance purposes only and should not be regarded as a substitute for taking professional and legal advice. Please refer to the full General Notices on our website.
Zahra Navarro
Zahra Navarro
Trainee Solicitor

Related Articles

When an organisation is creating a website or app to reach users or potential customers drafting a Privacy Policy may...

It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known,...

Artificial intelligence is changing the data protection landscape, but perhaps not in the way many organisations expected. Much of the...

Related Resources

Internet and email policy

Policy covering the use of the internet and email by employees. Purpose and scope This Policy covers the use of...

International transfers factsheet

International transfers factsheet provides and overview on data protection requirement for international transfers. Introduction The UK General Data Protection Regulation...

Request for access to personal data form

Employees should fill out this form if they want to request access to their personal data which the company may...

Human resources at a click