Privacy Policy
A free, editable Word privacy policy for UK businesses to publish on their own website, a UK GDPR / Data Protection Act 2018 transparency notice (Articles 13–14) covering the data you collect, your purposes and lawful bases, sharing, international transfers, retention, security, and data-subject rights, with an ICO complaint route. No US/CCPA content.
What's inside
A complete, UK-drafted privacy policy
- What personal data you collect and how, written as a clear UK GDPR notice
- Purposes and lawful bases (Article 6), special category data (Article 9), and PECR cookies/marketing
- Who you share data with, and UK international-transfer safeguards (UK IDTA / Addendum)
- Retention, security (Article 32) and the full set of data-subject rights (Articles 15–22)
- Automated decision-making, children's data, and changes to the notice
- A contact and ICO-complaint block (ico.org.uk), governed by England & Wales
How it works
- 1
Tell us where to send it
Enter your name, work email and organisation. We email you an editable Microsoft Word (.docx) file, personalised with your name.
- 2
Fill in the bracketed fields
Open it in Word, Google Docs or LibreOffice and complete every [bracketed] field with your details and commercial terms.
- 3
Review and adapt before use
Adapt the clauses to your circumstances and have it reviewed by a qualified solicitor before you sign or publish it.
This template is not legal advice. Writford is a software company, not a law firm, and is not regulated by the SRA. This document is a starting point that must be reviewed, adapted and approved by a qualified solicitor before use. It was last reviewed on 25 June 2026.
Get the free template
We email you an editable Word copy, personalised with your name. No account needed.
Looking for something else? Browse all templates.
Does my UK business need a privacy policy?
Yes, if you handle anyone's personal data, which in practice includes any business with a website contact form, a customer list or employees. The obligation is to tell people what you collect, why, who you share it with and how long you keep it.
- What has to be in a UK privacy policy?
- Who you are, what personal data you collect, why you use it and on what lawful basis, who you share it with, whether it leaves the UK, how long you keep it, and the rights people have over it.
- Do I need to register with the ICO?
- Most organisations processing personal data must pay the ICO a data protection fee. It is an annual payment and the amount depends on size and turnover.
- How often should I update it?
- Whenever what you actually do changes: a new tool that handles customer data, a new supplier, a new purpose. A policy that describes something you stopped doing is worse than none.
- Can I copy another company's privacy policy?
- You can start from a template, but it must end up describing what you really do. A policy naming tools you do not use, or missing ones you do, is inaccurate and that is the thing being regulated.
- What is the difference between a privacy policy and a cookie notice?
- The privacy policy covers all personal data. The cookie notice covers what is stored on or read from a visitor's device, which has its own consent rules.