Company Privacy Notice Template for England and Wales
Generate a bespoke document
What is a Company Privacy Notice?
The Company Privacy Notice is a fundamental document required by UK data protection legislation, particularly since the implementation of the UK GDPR and Data Protection Act 2018. It serves as a transparent communication tool between organizations and individuals whose data they process. The document must detail all aspects of data processing activities, including collection methods, purposes, legal bases, sharing practices, and security measures. Organizations operating in England and Wales must maintain an up-to-date privacy notice that accurately reflects their data processing practices and ensures compliance with regulatory requirements.
Trusted by high-performance teams
About the Company Privacy Notice
A Company Privacy Notice is your organization's formal commitment to transparency under England and Wales data protection law. This document serves as the primary communication tool between your company and individuals whose personal data you collect, process, or store. Under the UK GDPR and Data Protection Act 2018, you must provide clear, accessible information about your data processing activities to build trust and ensure legal compliance.
When do you need this document?
You need a Company Privacy Notice whenever your organization processes personal data of individuals. This includes collecting customer information through websites, handling employee records, processing supplier contact details, or gathering data through marketing activities. The notice is essential for e-commerce businesses collecting customer data, service providers processing client information, employers handling staff records, and any organization using cookies or analytics tools on their website. You must provide this notice before or at the point of data collection, ensuring individuals understand how their information will be used.
Key legal considerations
Your privacy notice must include specific mandatory information under UK GDPR Article 13 and 14. You must clearly identify your organization as the data controller, specify the categories of personal data collected, and explain the lawful basis for processing under UK GDPR Article 6. The document should detail how long you retain data, outline individuals' rights including access, rectification, and erasure, and provide information about any automated decision-making processes. You must also explain any international data transfers and the safeguards in place. Regular reviews and updates are crucial as your privacy notice must remain accurate and reflect current processing activities. Failure to provide adequate privacy information can result in significant fines up to £17.5 million or 4% of annual global turnover.
Legal requirements in England and Wales
Under England and Wales law, your privacy notice must comply with UK GDPR principles of transparency, fairness, and accountability. The Information Commissioner's Office (ICO) requires the notice to be written in clear, plain language that average individuals can understand. You must make the privacy notice easily accessible, typically through prominent website links or physical copies where appropriate. Special considerations apply for sensitive personal data processing, requiring explicit consent or other specific lawful bases. For electronic communications, you must also comply with PECR 2003 regulations regarding cookies and marketing. The notice should specify your UK representative if you're based outside the UK but process UK residents' data. Additionally, if your organization is a public authority, you may need to reference Freedom of Information Act obligations alongside data protection requirements.
GOVERNING LAW
Applicable law
This Company Privacy Notice is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

