Go to main content
Certyneo

Website Privacy Notice template

Free
Customizable
Electronic signature

Overview

A website privacy notice is the transparency document required under Articles 13 and 14 of the UK GDPR whenever a website collects or otherwise processes personal data about its visitors — through contact forms, account creation, analytics, cookies, or newsletter sign-ups. It must be concise, transparent, intelligible and in plain language, made easily accessible (typically linked from every page footer), and provided at the point personal data is collected, in line with the Information Commissioner's Office (ICO) guidance on privacy notices. The notice must set out, at minimum: the identity and contact details of the controller (and, where appointed, its data protection officer); the purposes of processing and the lawful basis relied on for each (consent, contract, legal obligation, legitimate interests, and so on); the categories of personal data and recipients; the retention period, or the criteria used to determine it; and the data subject's rights, including the right to access, rectify, erase or restrict processing, the right to data portability, the right to object, and the right to complain to the ICO. Where cookies or similar tracking technologies are used, the Privacy and Electronic Communications Regulations (PECR) additionally require consent for all but strictly necessary cookies, generally addressed through a separate cookie banner and cookie policy linked from the privacy notice. When to use it: for any website — marketing site, SaaS product, e-commerce store — that collects personal data from visitors or customers in any form. Parties: the website operator, as controller (or joint controller, where relevant) of the personal data collected, and the website visitor, as data subject. Key sections: identity of the controller; categories of data collected and sources; purposes and lawful basis for each processing activity; recipients and any international transfers, with the applicable safeguard; retention periods; data subject rights and how to exercise them; use of cookies and a link to the cookie policy; and the right to complain to the ICO. Pitfalls to avoid: publishing a generic, boilerplate notice that does not reflect what the site actually does (a notice must be accurate to the real processing activities, not aspirational); listing every possible lawful basis for every purpose instead of identifying the single basis genuinely relied on for each; omitting the international transfer position where analytics or hosting providers are based outside the UK; and failing to keep the notice in sync with the actual cookie banner and consent management tool.

Information to customize

  • Controller's registered name

  • Controller's registered office address

  • Data protection contact (name/role and email)

  • Website URL

  • Categories of personal data collected

  • Purposes of processing and lawful basis for each

  • Recipients / third parties data is shared with

  • International transfer details, if any

  • Retention period or criteria

  • Link to the separate cookie policy

  • Contact email for privacy queries

  • Effective date of this notice

Customize your template

Signature recipient

Frequently asked questions

Does every website need a privacy notice?
Any website that collects personal data — through forms, accounts, analytics or cookies — needs a privacy notice under Articles 13 and 14 of the UK GDPR, regardless of the site's size or sector.
What is the difference between a privacy notice and a cookie policy?
The privacy notice covers all personal data processing on the site; the cookie policy focuses specifically on cookies and similar tracking technologies, and works alongside the cookie consent banner required under the Privacy and Electronic Communications Regulations.
Do we need to name a lawful basis for every purpose?
Yes, UK GDPR requires the notice to identify the specific lawful basis relied on for each processing purpose (such as consent, contract or legitimate interests), rather than listing every possible basis generically.
What happens if our data goes to a provider outside the UK?
Any transfer of personal data outside the UK requires an appropriate safeguard, such as a UK adequacy regulation covering that country, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — and the notice should say which applies.
Who can visitors complain to if they are unhappy with how their data is used?
Visitors can complain directly to the website operator first, and can also lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent data protection regulator.

Related templates

Information about this template

Last updated
29 August 2026
Country
GB
Legal notice
This template is provided for guidance only and must be adapted to your circumstances. It does not constitute legal advice.