Entrepreneur Legal UK · Insight
Is a Privacy Policy Mandatory in the UK?
By Gabriel C. Mbanefo — Solicitor of the Senior Courts of England and Wales; Director & CEO, Entrepreneur Legal UK.
What “mandatory” really means
The legal duty is to provide the privacy information required by the UK GDPR where the relevant transparency provisions apply; the law does not prescribe one page title called “Privacy Policy”. For most websites and apps, a clearly accessible privacy notice or policy is the practical way to deliver that information. The content, timing and any exception depend on the actual processing. The Data (Use and Access) Act 2025 has amended parts of the UK GDPR and PECR and is now in force, so current analysis should use the amended statutory framework. This article gives general UK information and does not cover every sector-specific regime or complex international-data issue.
At a glance: when is privacy information required?
| Question | Practical answer |
|---|---|
| Who needs to consider this? | Controllers collecting or obtaining personal data where UK GDPR transparency duties apply. In practice, most online businesses process at least some personal data. |
| Is a page titled “Privacy Policy” legally mandatory? | No. The legal requirement is generally to provide specified privacy information. A Privacy Policy or Privacy Notice is the usual practical delivery method for a website or app. |
| When should information be provided? | For data collected directly, generally when it is obtained. For data obtained indirectly, Article 14 has its own timetable, subject to statutory exceptions. |
| Routine drafting route | Where the business has mapped its processing and the position is reasonably standard, create a Privacy Policy through StartWise. |
| Get specialist advice first when | Processing involves children, special-category or biometric data, extensive profiling, complex advertising technology, international transfers, regulated sectors, or difficult controller/processor questions. |
| Situation | Privacy information needed? | What to do |
|---|---|---|
| Simple brochure site, including basic server/security logs | Potentially. IP addresses and log data may be personal data; assess the actual logs, hosting/security vendors and contact routes. | Map the processing before assuming privacy information is unnecessary or only minimal. |
| Contact form, newsletter, account or customer data | Yes, UK GDPR transparency duties will usually apply. | Provide clear privacy information reflecting the real processing. |
| Analytics/advertising technologies processing personal data | Yes, plus PECR analysis for storage/access technologies. | Coordinate Privacy Policy with Cookie Policy/consent controls. |
| Children, health/biometric/special-category data or extensive profiling | Yes, with higher-risk analysis. | Seek specialist privacy advice where appropriate. |
| Data obtained from third parties rather than directly from the person | Generally yes, subject to Article 14 timing requirements and statutory exceptions. | Provide required information within the applicable timeframe. |
The founder problem: “we only collect email addresses” is rarely the whole data map
A startup founder thinks the website only collects names and emails through a contact form. In reality, the hosting provider logs IP addresses, analytics runs on each visit, a CRM receives lead details, an email platform tracks opens, payment processors handle customer data and support tools store conversation history. The privacy notice has to describe the real processing, not the founder’s first mental model of it.
1. The legal obligation is transparency, not a particular page title
The statutory starting point is UK GDPR Articles 13 and 14, which specify minimum privacy information where personal data is collected directly from an individual or obtained from another source. The ICO describes the right to be informed as a key transparency requirement. The Data (Use and Access) Act 2025 has made targeted amendments to this framework, including defined exceptions in particular circumstances; those changes do not remove the ordinary transparency duties that apply to routine commercial processing. The notice should accurately explain matters such as purposes, retention and recipients, alongside the other information required in the circumstances.
For an online business, a clearly accessible Privacy Policy or Privacy Notice is usually the practical way to deliver that information. Calling the page “Privacy Policy” does not make it compliant if the content is incomplete or inaccurate.
2. Build the notice from a data inventory
Map what data is collected, where it comes from, the purpose, lawful basis, recipients/processors, retention, international transfers and the rights that apply. Include customer-facing systems and background services: analytics, hosting, CRM, support, payments, authentication, email and advertising vendors.
The data inventory should be maintained. A privacy notice can become inaccurate simply because the product team added a new integration.
3. Timing matters when data comes directly and indirectly
Transparency information should be provided at the appropriate time. Where personal data is collected directly from the individual, Article 13 generally requires the information when the data is obtained. Where data is obtained indirectly, Article 14 generally requires the information within its statutory timetable, subject to applicable exceptions. That is why a link buried at the bottom of a site may not always be enough as the only disclosure: relevant privacy information should be integrated into the points where the user provides data or makes choices.
The Data (Use and Access) Act 2025 should also be considered where a business relies on any amended exception or further-processing rule rather than assuming the pre-2025 wording still applies unchanged.
4. A Privacy Policy and Cookie Policy solve different problems
PECR regulates storage and access technologies such as cookies, pixels, web storage, fingerprinting, scripts and tags. Following the Data (Use and Access) Act 2025 changes now in force, regulation 6 operates with specified Schedule A1 exceptions. These include the communication and strictly-necessary exceptions, together with newer statistical/analytics, appearance/functionality and emergency-assistance exceptions in defined circumstances. Some exceptions have conditions such as clear information and a simple way to object. Where storage/access technology processes personal data, the UK GDPR also applies. The Privacy Policy should explain the personal-data processing; the Cookie Policy/consent layer should explain the storage/access technology and the applicable consent or statutory exception.
One technology can therefore appear in both analyses for different reasons. Do not assume that all analytics can now operate without consent: the statistical exception is narrow and does not extend to online advertising, profiling or other uses outside its conditions.
5. Do not copy a competitor’s retention and vendor language
Retention, processors, international transfers and lawful bases should reflect the actual organisation. Copying another policy can produce false statements about how long data is kept, which companies receive it or whether the business sells/shares information in a way it does not.
6. Higher-risk processing needs more than a policy
A written privacy notice does not replace other legal duties. For example, UK GDPR Article 28 can require binding controller-processor terms, Article 35 can require a data-protection impact assessment for processing likely to result in high risk, and Chapter V governs restricted international transfers. Children’s services, special-category or biometric data, extensive profiling, complex advertising technology and international transfers are examples where legal/privacy analysis may need to come first.
Before you draft the Privacy Policy
- List all personal data collected directly from users.
- List personal data generated automatically by the website/app and vendors.
- Record each purpose and lawful basis.
- Identify processors, recipients and international transfers.
- Set defensible retention periods rather than copying generic periods.
- Map individual rights and contact channels.
- Coordinate cookies/storage access separately under PECR.
- Review the notice whenever the product or vendor stack materially changes.
Common mistakes and consequences
| Mistake | Practical consequence |
|---|---|
| Treating the policy as a template exercise before mapping data | The document can be polished but factually wrong. |
| Listing vendors from another company’s policy | The notice may describe processing that never occurs and omit processing that does. |
| Using Cookie Policy language as the entire privacy notice | PECR and UK GDPR transparency are different legal functions. |
| Promising deletion “immediately” or retention “only as needed” without a real schedule | The public promise may not match operational practice. |
| Never updating the policy | New integrations, purposes and transfers can make the notice stale. |
How StartWise™ Drafting fits
StartWise currently includes a UK Privacy Policy. For a reasonably standard business that has mapped its data processing, the user can answer guided questions, generate a tailored first draft and review any Drafting Notes.
StartWise does not discover every processing activity automatically, decide the lawful basis, conduct a DPIA or determine complex international-transfer obligations. Accurate inputs and a current data map remain essential.
Frequently asked questions
Does every UK business need a Privacy Policy?
Every business does not necessarily need a page with that title. However, where the UK GDPR transparency provisions apply, the controller generally must provide the required privacy information. For most online businesses, a Privacy Policy or Privacy Notice is the practical way to do so.
Can I use a free privacy-policy template?
You can use a template as a starting structure, but it must be adapted to the actual data processing, vendors, purposes, retention and rights.
Is a Privacy Policy the same as a Cookie Policy?
No. A Privacy Policy addresses personal-data processing. Cookie/storage-access information addresses PECR and the technologies used on devices. They often overlap but are not the same legal function.
Do I need to list every third-party provider?
The required disclosure depends on the applicable transparency rules and how recipients/categories are described. The notice must be clear and accurate enough to explain who receives the data.
When should I get specialist privacy advice?
Where processing involves children, special-category data, biometrics, extensive profiling, complex advertising technology, international transfers or a regulated sector.
Sources and related Entrepreneur Legal resources
- Primary authority: UK GDPR, Articles 4(1), 5(1)(a), 6, 13 and 14 (personal data, transparency, lawful basis and privacy information).
- Primary authority: Data (Use and Access) Act 2025, s.77 (amendments to information provided to data subjects).
- Primary authority: Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 6, as amended; Data (Use and Access) Act 2025, s.112 and Schedule 12.
- Primary authority: UK GDPR, Articles 9, 28, 35 and Chapter V (special-category data, processor terms, DPIAs and international transfers).
- Official guidance: ICO, Right to be informed (guidance currently under review following DUAA changes).
- Official guidance: ICO, Guidance on the use of storage and access technologies (final guidance updated 29 April 2026).
- Official guidance: ICO, Data (Use and Access) Act 2025 - summary of changes.
- Related Entrepreneur Legal resource: What Legal Documents Does a UK Startup Need? (2026 Guide).
- Related Entrepreneur Legal resource: Website Legal Requirements in the UK — insert the live Entrepreneur Legal UK article URL after publication.
- StartWise route: StartWise UK Access.
- Author profile: Gabriel Mbanefo / Entrepreneur Legal UK.
Disclaimer
StartWise™ Drafting is not legal advice, lawyer review, legal approval or legal sign-off. Creating an account, purchasing drafting credits or generating a document does not by itself create a lawyer-client relationship. Entrepreneur Legal UK is the trading name of Entrepreneur Legal Ltd. Entrepreneur Legal Ltd is not regulated by the Solicitors Regulation Authority and does not carry on reserved legal activities.
Choose the right next step
Draft through StartWise. Review for less.
Explore the current guided UK workflows, or contact Entrepreneur Legal UK where your matter requires review, consultation or bespoke support.
