A UK GDPR privacy notice has to say more in 2026 than it did in 2025, and one thing it must no longer say at all. Articles 13 and 14 still set the core content: who the controller is, what data is collected, why, on what lawful basis, who receives it, whether it leaves the United Kingdom, how long it is kept, and what rights the reader has.
The Data (Use and Access) Act 2025 added a lawful basis, a further-processing information duty and an automated decision-making regime that the notice has to reflect, and it removed Article 77, so a notice that tells readers to complain to a supervisory authority is now wrong. This guide lists what a UK notice must contain, the four places EU-derived notices go wrong, and how to build a set of notices for customers, staff, candidates and websites.
What this guide covers
- What a UK GDPR privacy notice must contain
- The four places an EU-derived UK GDPR privacy notice goes wrong
- The UK GDPR privacy notice complaint paragraph, since 19 June 2026
- Further processing and the new information duty
- One UK GDPR privacy notice or several
- Layering and delivery
- Keeping a UK GDPR privacy notice current
- Building the UK GDPR privacy notice set
- Frequently asked questions about the UK GDPR privacy notice

What a UK GDPR privacy notice must contain
The content rules are in Article 13, where the data is collected from the individual, and Article 14, where it is obtained from elsewhere. The two lists overlap almost entirely; Article 14 adds the source of the data, and sets a timing rule of at the latest one month after obtaining it. The items, in the order most notices present them:
- the identity and contact details of the controller and, where one has been appointed, the UK representative and the data protection officer;
- the purposes of the processing and the lawful basis for each, including, where legitimate interests is the basis, what the interest is;
- the recipients or categories of recipients;
- whether the data will be transferred outside the United Kingdom, and on what safeguard, with a way to obtain a copy of it;
- the retention period, or the criteria used to set it;
- the rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where consent is the basis;
- the right to complain, stated as the UK routes;
- whether providing the data is a statutory or contractual requirement, and the consequences of not providing it;
- the existence of solely automated decision-making, with meaningful information about the logic and the consequences;
- for Article 14, the source of the data and whether it came from publicly accessible sources.
Article 12 adds the manner a UK GDPR privacy notice must take: concise, transparent, intelligible, easily accessible, in clear and plain language, and free. A notice written in the register of a commercial contract fails Article 12 whatever it contains. The Commissioner’s guidance on the right to be informed is the reference for what it expects to see.
The four places an EU-derived UK GDPR privacy notice goes wrong
| Item | What EU-derived notices say | What a UK notice must say |
|---|---|---|
| Complaints | “You have the right to lodge a complaint with a supervisory authority under Article 77” | “You can complain to us using [route]; we will acknowledge within 30 days. You can also complain to the Information Commissioner’s Office (ico.org.uk)” |
| Lawful bases | The six Article 6(1) bases | The six bases plus, where relied on, recognised legitimate interests under Article 6(1)(ea), with the Annex 1 purpose named |
| Transfers | “Standard contractual clauses approved by the European Commission” | UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU clauses; the “not materially lower” test |
| Age of consent | Sixteen, or a member-state age | Thirteen, under Article 8 |
A fifth, subtler UK GDPR privacy notice error: the automated decision-making paragraph. EU-derived notices describe Article 22 as a right not to be subject to such decisions. The UK text now describes decisions that are permitted with safeguards under Articles 22A to 22C, and the notice should tell readers that solely automated significant decisions are made, if they are, and what the safeguards are: information, representations, human intervention and contest. Our guide to UK GDPR automated decision making covers the regime.
The UK GDPR privacy notice complaint paragraph, since 19 June 2026
This is the paragraph most notices need rewriting. Data Protection Act 2018 section 164A gives readers a statutory right to complain to the controller and requires the controller to facilitate complaints, acknowledge within 30 days and respond without undue delay. The notice is where facilitation starts: it names the route, links the electronic complaint form, and states the acknowledgement commitment. Section 165 preserves the right to complain to the Commissioner, and the notice states that too. Article 77 is not cited because it does not exist in UK law. Our guide to the data protection complaints procedure sets out what sits behind the paragraph.
Further processing and the new information duty
Section 77 of the 2025 Act added a UK GDPR privacy notice duty for further processing: where the controller intends to process the data for a purpose other than the one it was collected for, it must tell the individual about that purpose, and the other Article 13 information relevant to it, before doing so. The UK notice therefore needs a further-processing paragraph that says what happens if data is reused, and a procedure behind it that updates the notice or writes to the affected people when a new purpose is adopted.
The compatibility test in Article 8A, with its Annex 2 list of deemed-compatible purposes, decides whether the reuse is lawful; the notice decides whether it is transparent. For the lawful basis paragraph, the guide to recognised legitimate interests gives model wording.
One UK GDPR privacy notice or several
A single master notice rarely serves every audience. Customers, employees, job candidates, website visitors, people captured on CCTV and business contacts at suppliers receive different data processing for different purposes on different bases, and a notice that covers all of them is either enormous or vague. The usual structure is a master notice that carries the common content, and a short notice per audience that inherits it and adds the specifics.
| Notice | What it adds to the master |
|---|---|
| Customer | Account, order and payment purposes; marketing basis and preferences; profiling; retention by record type |
| Employee | HR purposes; special category data and the Schedule 1 condition; monitoring; references; retention per the HR schedule |
| Candidate | Recruitment purposes; sources (agencies, references, checks); retention after the decision; equality monitoring on a voluntary basis |
| Website | Cookies and similar technologies under PECR Schedule A1; analytics on the statistical exception with its objection route; forms |
| CCTV | Locations, purposes, retention, disclosure to police; signage version |
| Supplier and business contact | Legitimate interests under Article 6(11) for business correspondence; retention with the contract |
| Children | Age-appropriate language; Article 8 consent at thirteen; children’s higher protection matters under Article 25(1A) |
Layering and delivery
Article 12 wants the UK GDPR privacy notice accessible, and the Commissioner accepts layered notices: a short first layer with the essentials, expanding to the full text. The first layer should carry who the controller is, the main purposes, the complaint route and a link to the full notice. Delivery depends on the audience: a link at the point of collection for web forms; the staff handbook and the intranet for employees; the application page for candidates; signage for CCTV.
Article 14 notices go out within one month of obtaining the data, or at first contact if sooner, or at first disclosure to another recipient if sooner still. Record which version was live on which date, because a rights request or a complaint will turn on what the reader was told at the time.
Keeping a UK GDPR privacy notice current
A notice is a dated statement of the processing, so it changes when the processing does. Triggers: a new purpose or lawful basis; a new category of recipient or processor; a new transfer or a change in the adequacy list; a new retention period; a new automated decision process; a change in the law. The 2025 Act produced the largest single batch of changes, and any notice not revised since February 2026 needs the four items in the table above checked. Our summary of the Data (Use and Access) Act 2025 lists each change; the guide to UK GDPR vs EU GDPR sets out where a dual-regime notice needs two paragraphs.
Building the UK GDPR privacy notice set
A master notice, seven audience notices, a layered notice guide, and a procedure for further-processing information and version control. The UK GDPR Toolkit ships all nine documents written to the amended text: the section 164A complaint route with the 30-day acknowledgement, recognised legitimate interests where relevant, the UK transfer mechanisms, the age of thirteen, and the automated decision-making statement, with the complaints form and procedure that stand behind the paragraph. For the wider regime the notices describe, see our guide to the UK GDPR.
Frequently asked questions about the UK GDPR privacy notice
Is a privacy notice the same as a privacy policy?
In UK usage the notice is the document given to individuals under Articles 13 and 14, and the policy is the internal document that sets the organisation’s rules. Many websites label the notice a “privacy policy”; the content requirements are the same whatever it is called.
Do I need a separate UK notice if I already have an EU one?
You need UK content: the complaint route, the lawful bases, the transfer mechanism and the age of consent all differ. That can be a separate notice or a UK section within one document, provided each reader can tell which applies to them.
Does the notice have to name every processor?
Recipients or categories of recipients. Naming categories (“payment processors, cloud hosting providers”) is permitted; naming the processors is better practice for the significant ones and is expected where the reader could not otherwise understand who has their data.
How often should the notice be reviewed?
On every change to the processing, and at least annually as part of the compliance review. Keep each dated version.