Data Collection Notice Template for England and Wales

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Collection Notice?

The Data Collection Notice is a fundamental document required by UK data protection legislation to ensure transparency in data processing activities. It must be provided whenever personal data is collected directly from individuals or obtained from other sources. The notice should be drafted in clear, plain language and must include specific information required by the UK GDPR about how personal data will be used, shared, and protected. This document is particularly crucial following the UK's exit from the EU and implementation of the UK GDPR, as organizations must demonstrate compliance with domestic data protection requirements.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Collection Notice

A Data Collection Notice is your legal obligation under UK data protection law whenever you collect personal information from individuals. This essential document serves as a transparency tool, informing data subjects about how you will process their personal data and ensuring your compliance with the UK GDPR and Data Protection Act 2018.

When do you need this document?

You must provide a Data Collection Notice at the point of data collection, whether collecting information directly from individuals through forms, websites, or applications, or when obtaining personal data from third parties. This applies to all sectors including healthcare providers collecting patient information, employers gathering staff details, retailers processing customer data, and schools collecting student records. The notice must be provided before or at the time of collection, and you cannot rely on retrospective notifications except in very limited circumstances defined by law.

Key legal considerations

Your Data Collection Notice must include several mandatory elements to satisfy UK GDPR requirements. You must clearly identify yourself as the data controller, specify the types of personal data you're collecting, and explain your lawful basis for processing under Article 6 of UK GDPR. The notice should detail all purposes for which you'll use the data, including any secondary processing activities, and identify any third parties with whom you may share the information. Data retention periods must be specified, along with information about individuals' rights including access, rectification, erasure, and the right to object to processing. You must also provide your contact details and those of your Data Protection Officer if applicable, plus information about the right to lodge complaints with the Information Commissioner's Office.

Legal requirements in England and Wales

Under English and Welsh law, the UK GDPR and Data Protection Act 2018 establish strict transparency obligations that differ from EU requirements in several key areas. The Information Commissioner's Office provides specific guidance on drafting compliant notices, emphasizing the need for clear, plain English that avoids legal jargon. Your notice must be easily accessible and prominently displayed, particularly for online data collection where it should be available through clear links. For special category data such as health information or criminal convictions, additional legal bases and safeguards must be explained. The Privacy and Electronic Communications Regulations 2003 impose additional requirements for electronic marketing and cookie notices that may need integration with your data collection notice. Failure to provide adequate transparency can result in ICO enforcement action, including fines up to £17.5 million or 4% of annual global turnover, whichever is higher.

GOVERNING LAW

Applicable law

This Data Collection Notice is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The United Kingdom General Data Protection Regulation - Primary legislation governing data protection in the UK post-Brexit, setting out fundamental principles for personal data processing

Data Protection Act 2018: The UK's implementation of data protection laws, working alongside UK GDPR to provide a comprehensive data protection framework

PECR 2003: Privacy and Electronic Communications Regulations - Specific rules for electronic communications, including rules about cookies and electronic marketing

ICO Guidelines: Guidance and Codes of Practice from the Information Commissioner's Office - The UK's data protection regulator providing practical guidance on compliance

EDPB Guidelines: European Data Protection Board Guidelines - While not directly binding post-Brexit, still considered relevant best practice for UK data protection

Transparency Requirements: Articles 13/14 of UK GDPR requiring clear information about data processing to be provided to data subjects

Lawful Basis: Legal requirement to identify and document valid grounds for processing personal data under Article 6 of UK GDPR

Purpose Limitation: Principle requiring personal data to be collected for specified, explicit and legitimate purposes and not processed in a manner incompatible with those purposes

Data Minimization: Principle requiring personal data to be adequate, relevant and limited to what is necessary for the purposes for which they are processed

Storage Limitation: Principle requiring personal data to be kept for no longer than necessary for the purposes for which it is processed

Data Subject Rights: Rights granted to individuals under UK GDPR including access, rectification, erasure, and data portability

International Transfers: Requirements for transferring personal data outside the UK, including adequate safeguards and transfer mechanisms

Security Measures: Requirements to implement appropriate technical and organizational measures to ensure security of personal data

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it