Purpose
This document sets out the standards and operating procedures for collecting, processing, sharing, protecting, and retaining personal data in compliance with relevant data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It also defines how [Organisation Name] implements, maintains, and updates its public-facing Privacy Policy.
Working through related paperwork at the same time? See also our Privacy Notice for Employees Template, UK Data Retention & Disposal Policy Template and Subject Access Request Procedure Template.
Scope
This policy applies to all personal data [Organisation Name] collects and processes regarding customers, website visitors, enquirers, suppliers, and job applicants.
Internal employee personal data is governed separately under the internal employee privacy notice.
Responsibilities
- [Data Protection Lead / Role]: Maintains the Privacy Policy, audits data processing practices, responds to data subject rights requests, and coordinates regulatory compliance.
- [Department Heads / Managers]: Ensure data collection within their operational areas aligns with this policy. They must notify the [Data Protection Lead / Role] before introducing new data collection tools or third-party software.
- [All Staff]: Follow organizational data security protocols, handle personal data securely, and immediately pass privacy enquiries or requests to the [Data Protection Lead / Role].
Policy Standards
Data Controller Information
[Organisation Name], located at [Registered Address], acts as the data controller for personal data processed under this policy. Direct queries regarding data usage to the [Data Protection Lead / Role] at [Email Address].
Personal Data Collected
The organisation processes these categories of personal data:
- Contact and Identity Data: Name, email address, phone number, and postal address collected during enquiries, orders, or bookings.
- Transaction Data: Orders, bookings, quotes, invoices, and payment history. External payment providers process card payments; we do not store full card details locally.
- Technical and Device Data: Pages visited, device types, and cookie identifiers.
- Correspondence: Emails, electronic messages, call notes, and complaint records.
- Security Video Data: CCTV footage collected at specified operational sites with displayed signage.
- Recruitment Data: CVs, application forms, interview notes, and professional references.
Purposes and Lawful Bases for Processing
We process personal data under the following lawful bases:
- Contractual Necessity: To fulfill product or service orders, process bookings, and manage customer accounts.
- Legal Obligation: To maintain financial, tax, and accounting records and comply with regulatory duties.
- Legitimate Interests: To respond to general enquiries, improve operational services, and prevent fraud, balanced against individual privacy rights.
- Consent: To send direct marketing communications where required by law. Individuals may withdraw consent or opt out at any time using the unsubscribe links provided or by direct request.
We do not use automated decision-making that produces legal or similarly significant effects.
Data Sharing and International Transfers
- We may share personal data with contracted third-party processors acting on written instructions, including IT support, payment processors, booking platforms, communication services, and professional advisers.
- We may disclose personal data to regulatory authorities, tax authorities, or law enforcement when required by law.
- We never sell personal data to third parties.
- Where data moves to or is stored outside the domestic jurisdiction, we must establish appropriate statutory safeguards (such as adequacy regulations or standard data protection clauses) with the recipient.
Data Retention
We retain personal data only as long as necessary to fulfill its original purpose, in line with statutory requirements and the organizational Data Retention Schedule. Once the retention period expires, staff must securely destroy or anonymise the data.
Individual Rights
Data subjects have the following rights regarding their personal data:
- Access: Request a copy of held personal data (Subject Access Request).
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure and Restriction: Request deletion or restricted processing under specified legal conditions.
- Objection: Object to processing based on legitimate interests or direct marketing (staff must process direct marketing objections immediately).
- Portability: Receive personal data in a structured, commonly used format.
- Consent Withdrawal: Withdraw consent at any time where processing relies on consent.
Submit requests to [Email Address]. The organisation must respond within one calendar month.
Security Controls
Protect personal data using technical and organizational measures proportionate to risk:
- Limit access controls strictly to authorized personnel.
- Enforce password controls and multi-factor authentication on systems hosting personal data.
- Enable encryption on portable electronic devices.
- Provide mandatory data protection training for all staff.
- Apply physical security measures, such as locked storage for paper records and secure shredding upon disposal.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.
Implementation and Maintenance Procedure
- Audit Data Collection Points: Identify every operational channel where personal data enters the organisation (e.g., website forms, phone calls, point-of-sale systems, paper forms).
- Catalog Third-Party Processors: Document all external service providers handling personal data. Verify written processing agreements and transfer safeguards.
- Align Retention Schedules: Cross-reference privacy policy timelines with the internal Data Retention Schedule to ensure consistency.
- Verify Regulatory Fees: Complete the supervisory authority’s self-assessment to determine fee liability and process required registration payments.
- Publish Privacy Notice: Post the finalized privacy policy across all data collection interfaces, including website footers, booking systems, and intake documents.
- Maintain and Review: Update the policy immediately upon adopting new data collection practices, systems, or third-party vendors. Complete a formal review at the specified review interval.
Complaints and Escalation
Submit data handling inquiries or complaints internally to the [Data Protection Lead / Role] at [Email Address] first. Individuals also retain the right to lodge a complaint directly with the applicable national regulatory body (such as the Information Commissioner’s Office).
Records
The [Data Protection Lead / Role] must maintain the following records:
- Regulatory fee self-assessment outcomes and registration records.
- Log of Subject Access Requests and processing rights requests.
- Executed data processing agreements with third-party vendors.
- Version history and audit logs of the Privacy Policy.
Review and Governance
Review this policy and its associated public notices annually, or immediately following any material changes to data processing activities, operational software, or applicable legislation.
- Document Owner: [Data Protection Lead / Role]
- Approval Date: [Date]
- Next Review Date: [Date]
FAQs on a privacy policy
What is a privacy policy?
A privacy policy sets out the standards and operating procedures for collecting, processing, sharing, protecting, and retaining personal data in compliance with relevant data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It also defines how your organisation implements, maintains, and updates its public-facing Privacy Policy.
Having it written down means the same rules apply to everyone, so managers are not making judgement calls case by case under pressure.
What does a privacy policy include?
This template covers policy standards, implementation and maintenance procedure and complaints and escalation.
Every section is written to be filled in. The bracketed placeholders mark the decisions that are yours to make, such as timescales, approval owners and retention periods.
How to implement a privacy policy with Whale
Copy this template into Whale and work through the bracketed placeholders so it reflects how your organisation actually operates.
Assign it to the teams it applies to so it sits where people work rather than in a shared drive, and set a review date so it gets revisited on schedule instead of quietly going out of date.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.