Using a Privacy Policy Template? What UK Businesses Should Check Before Publishing It
Privacy Policy templates are available from anywhere. You can download one online, use a template supplied by a website provider, or even ask an AI tool to draft one for your business in seconds. And there is nothing necessarily wrong with doing it.
A template can give you a useful starting structure. AI can help you draft and improve the wording. However, the problem starts when the finished Privacy Policy, more commonly referred to by the Information Commissoner’s Office as Privacy Notice, doesn’t reflect what actually happens inside your business.
A Privacy Notice isn’t simply something to add to the footer of your website because you have been told you need one. It informs people what happens to their personal data when they engage with your business. And to do that properly, you need to understand the business before you write the document.
Don’t start with Privacy Notice. Start with your business.
One of the risks of starting with a template is that the questions can become:
what should we put in this section?
What wording should we use here?
Can AI fill this bit in for us?
I would start somewhere else. What actually happens to personal data in this business?
The ICO recommends that before writing a Privacy Notice, businesses understand information such as the personal data they collect, where it comes from, why they have it, their lawful bases, who they share it with (including with AI tools), and how long they retain it. That means looking beyond your website.
Think about what happens when someone:
fills in an enquiry form;
craetes an account;
buys something;
subscribes to marketing;
contacts customer support;
applies for a job;
uses your app or platform;
makes a hair, dental, or a doctors appointment via your online booking system that may also request credit card information;
engages with your AI assistant either via a chat widget, message app like WhatsApp or via email; or
asks you to exercise one of their privacy rights.
Your CRM, payment provider, email marketing platform, analytics tools, cloud services, customer support platform, and AI tools may all form part of the picture. So, your Privacy Notice needs to reflect your processing, rather than describing how a generic business might operate.
What should a UK Privacy Notice cover?
Exactly what needs to be provided depends on the circumstances and how and why the organisation processes personal data.
However, the ICO identifies information that must always be provided in relevant circumstances, along with other information that is required where applicable. This includes:
Your organisation’s contact details,
Purpose and lawful bases for processing,
Retention periods,
People’s right and infomraotin about making a complaint.
Depending on the circumstances, it can also include your Data Protection Officer’s contact details, recipeints of data, international transfers, legitimate interests, withdrawal of consent, and automated decision-making or profiling.
If you obtain personal data from somewhere other than the individual, there are additional transparency considerations, including telling people about the categories of personal data obtained and its source.
This is one reason simply asking an AI tool: “Write a UK GDPR complaint Privacy Notice for my business” isn’t enough.
The AI doesn’t automatically know your lawful bases, retention periods, systems, suppliers, data flows, international transfers, or how your business actually uses people’s information.
A professionally written document can also still be an inaccurate document.
Could your customer actually understand it?
This is something I think from experience most businesses overlook and should pay much more attention to.
Privacy Notices are not written primarily for solicitors and privacy professionals. They are writtent for people who personal data you are collecting and using.
The ICO tells small organiations that they need to explain their use of personal data in a way that is easy for people to understand and stresses the importance of openness and simple language. This becomes particularly important when information is addressed to children.
That means reviewing your Privacy Notice from the perspective of the person reading it.
Ask: “Would our typical customer understand this?”
If your customers aren’t solicitors or privacy professionals, a Privacy Notice full of legal jargon and terminology may technically contain information while doing a poor job of communicating it.
The UKHSA’s privacy notice standard makes the same broader point: privacy information should be concise, transparent, intelligible, easily accessible, and avoid unneccessarily legalistic and technical terminology. Its standard is specifically for UKHSA protected data applications, rather than a universal checklist for every UK business, but the communicaiton aligns with ICO guidelines.
Don’t forget the complaints process
What happens if somebody is concerned about the way you’ve handled their personal data?
Could they work out what to do from your Privacy Notice?
The ICO says people should be told how they can compain if they have concerns about the way their information is being used. Its detailed guidance also says people should be informed about their rights to complain to a supervisory authority; for UK organisations of those regularly collecting data from people living in the UK, this will commonly mean informing people abou the ICO and providing its contact details.
But think about the operational side as well. If somebody sends a privacy complaint to your business tomorrow, who receives it? Do they know what to do with it? This si where the written Privacy Notice and what actually happens inside the business need to connect.
Make it easy for people to contact you about privacy
You may already have a general contact form or an info@ inbox. But consider whether that’s the best way to receive privacy requests and concerns.
A dedicated privacy email address and/or privacy-specific form can make these enquiries easier to identify and route to the right person.
If you have appointed a Data Protection Officer, include the appropriate DPO contact details where applicable. The ICO specifically identifies DPO contact details as information that needs to be provided were a DPO applies. The important point isn’t simply creating another email address. It’s making sure there is a working process behind the contact method.
Does your team know what the Privacy Notice says?
This is one of the checks I think is easily overlooked.
A business publishes its Privacy Notice and then nobody inside the organisation looks at it again, and it happens more often than not.
Your Privacy Notice contains committments about how the organiation handles peoples information. Suppose your notice tells customers they can contact you to exercise their privacy rights. What happens when a request arrives? Suppose it says you onlly retain certain information for a defined period. Is that what actually happens? Suppose it says informations is only shared with particular categories of third parties and doesn’t even mention the us of AI processing customer’s information. Do the teams buying new software or introducing AI tools understand that?
A Privacy Notice shouldn’t operate separately from the business. Relevant employees should understand the commitments the organisation has made and know what to do when somone exercise a right or raises a concern.
Here’s one userful way AI can help
I’ve talked about the limitations of using AI to create a Privacy Notice, but AI can be genuinely useful during the review process. One simple use is to ask it to act as a second pair of eyes and assess the notice from the perspective of your customers or intended audience.
For example you could use this prompt:
Review this Privacy Notice from the perspective of our typical customer, [briefly describe your customer or intended audience]. If no specific audience is provided, assume the reader has no legal or privacy knowledge background.
Identify any wording, legal terminology or sections that may be difficult to understand. Explain why they may be confusing and suggest plain-language alternatives.
Do not change the legal meaning or remove any obligations. Provide recommendations only; do not rewrite the notice.
Then after the AI outputs the feedback review the recommendations yourself. The purpose of this exercise isn’t to ask AI whether your Privacy Notice is legally compliant. It is to test whether the person your’re writing it fo is likely to understand it. And remember not to paste confidential, personal or otherwise restricted information into an AI tool ulness its use for that information has been appropriately approved. That’s is teh same governance prinicple I wrote in my recent article on employees putting customer information into AI tools
Before you publish, ask one final question
After you have worked through the requirements, reviewed the working and checked the document, ask:
Does this Privacy Notice describe what actually happens in our business?
Not what the template said should happen. Not what AI assumed happened. Not what you intend to happen eventually. What actually happens today.
If you answer is no, you may have more than a document problem. You may have identified a process, privacy or governance issue that needs addressing inside the business. And that is precisely why reviewing a Privacy Notice can be valuabe. It isn’t simple an exercise in producing another policy for your website. Your Privacy Notice is a promise to people about how you will handle their personal data. Make sure your business can keep it.
Want to review your existing Privacy Notice?
Download our Free UK Privacy Notice Review Checklist (no email required), including practical questions to work through before publishing or updating your notice, plus an AI prompt you can use to test whether your intended audience can understand it.
This resource provides general information and is not legal advice.
Not sure your Privacy Notice reflects your business?
We help businesses review and develop Privacy Notices that reflect how personal data is actually handled, not simply what a template says should happen.

