Templates/GDPR Privacy Policy
GDPR · Free template

GDPR Privacy Policy template

A free, editable UK GDPR privacy policy — the actual document structure, not just an explanation of what one should contain. Copy it, fill in the brackets, and adapt it to what your business actually does.

This is a generic starting point, not legal advice. It doesn't reflect your actual data, systems, or risk profile — every bracketed section needs to be filled in accurately before you publish it, and a real policy should be reviewed against what your business actually does.

What a GDPR privacy policy needs to cover

UK GDPR's "right to be informed" (Articles 13–14) sets out specific information you must give people about how you use their data. At minimum, that's: who you are, what data you collect, why you collect it and your lawful basis for each purpose, who you share it with, how long you keep it, and what rights people have over their own data.

The template below is structured around exactly those requirements, in the order the ICO expects to see them.

The template

Privacy Policy — [Company Name]

1. Who we are

[Company Name] ("we", "us", "our") is the data controller for the personal data described in this policy. Our registered address is [Company Address], and our company registration number is [Company Number].

If you have any questions about this policy or how we handle your personal data, contact us at [Contact Email] or [Contact Address]. [If you have a Data Protection Officer: Our Data Protection Officer is [DPO Name], reachable at [DPO Email].]

2. What personal data we collect

We collect the following categories of personal data: [list categories — e.g. name, email address, phone number, billing address, payment details, account activity, device and usage data].

We collect this data [directly from you when you register or use our services / from third parties such as — list any — / automatically via cookies and similar technologies, see our Cookie Policy].

3. How we use your data and our lawful basis

We use your personal data for the following purposes, and rely on the lawful basis stated for each:

• To provide and manage your account — Contract (necessary to perform our contract with you)

• To process payments — Contract / Legal obligation

• To send service updates and respond to support requests — Legitimate interests (running our business) or Contract

• To send marketing communications — Consent (you can withdraw this at any time)

• To comply with legal and regulatory obligations — Legal obligation

[Add or remove rows so this table matches your actual processing activities — every purpose needs its own lawful basis.]

4. Who we share your data with

We share personal data with: [list categories of recipients — e.g. cloud hosting providers, payment processors, email/CRM platforms, professional advisers, regulators where required by law].

Each third party that processes personal data on our behalf does so under a written data processing agreement, and only for the purposes we specify.

5. International transfers

[If applicable:] Some of the third parties listed above are located outside the UK/EEA. Where this is the case, we ensure an appropriate safeguard is in place — such as an adequacy decision, Standard Contractual Clauses, or the UK International Data Transfer Addendum — before any transfer takes place.

[If not applicable, remove this section or state: We do not transfer personal data outside the UK.]

6. How long we keep your data

We keep personal data only for as long as necessary for the purposes it was collected, or as required by law. [State your actual retention periods per data category here — e.g. account data for the duration of the relationship plus 6 years; marketing data until consent is withdrawn.]

See our Data Retention Policy for the full breakdown by data category.

7. Your rights

Under UK GDPR, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure in certain circumstances; restrict or object to certain processing; request a copy of your data in a portable format; and withdraw consent at any time where consent is the basis for processing.

To exercise any of these rights, contact us at [Contact Email]. We will respond within one month. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (ico.org.uk).

8. Cookies

Our website uses cookies and similar technologies. [Link to a separate Cookie Policy, or summarise your cookie categories and consent mechanism here.]

9. Changes to this policy

We may update this policy from time to time. [State how you will notify users of material changes — e.g. by posting the updated policy on this page with a new effective date, or emailing registered users.] This policy was last updated on [Date].

Common questions

Is a privacy policy legally required under UK GDPR?

Yes. Article 13 and 14 of UK GDPR require you to give individuals specific information — who you are, what you collect, why, your lawful basis, and their rights — at the point you collect their data. A published privacy policy is the standard way to meet this "right to be informed."

Is this template enough to be compliant on its own?

No — it's a structural starting point. A compliant policy needs to accurately describe what your business actually does: your real data categories, real lawful bases, real retention periods, and real third parties. Publishing a generic policy that doesn't match your actual processing is itself a compliance gap.

What's the difference between a Privacy Policy and a Data Protection Policy?

A Privacy Policy is the external, customer-facing document explaining how you handle personal data. A Data Protection Policy is typically an internal document setting out how staff must handle personal data day-to-day. Most organisations need both.

Do I need a separate Cookie Policy?

You need to disclose your cookie use and obtain consent for non-essential cookies under PECR (the Privacy and Electronic Communications Regulations), alongside your GDPR privacy policy. Many organisations combine this into one document; some keep it separate.

Want this written for your actual business?

Fortify's Policy Engine generates a Privacy Policy tailored to your real data, systems, and regulation scope — then flags it automatically when ICO guidance changes, and takes it through review and approval before it's published. No more manually re-checking a static document.