Data Processing Notice Template for England and Wales

Generate a bespoke document

What is a Data Processing Notice?

A Data Processing Notice is required whenever an organization processes personal data in England and Wales. This document fulfills the transparency obligations under the UK GDPR and Data Protection Act 2018, providing data subjects with clear information about how their personal data is handled. It must be provided at the time personal data is collected and should be easily accessible, written in clear language, and contain all information required by Articles 13 and 14 of the UK GDPR. The notice forms a crucial part of an organization's data protection compliance framework.

Trusted by high-performance teams

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Processing Notice

A Data Processing Notice is a fundamental document required under England and Wales data protection law that informs individuals about how their personal data is collected, used, and protected. This transparency document ensures your organization complies with the UK GDPR and Data Protection Act 2018 by providing clear information to data subjects about your data processing activities.

When do you need this document?

You must provide a Data Processing Notice whenever you collect personal data from individuals, whether directly or indirectly. This applies when customers fill out forms on your website, employees provide personal information during recruitment, clients sign contracts that involve data processing, or when you obtain personal data from third-party sources. The notice must be provided at the point of data collection or within one month if data is obtained from other sources. Without this notice, your organization risks significant ICO fines and enforcement action for failing to meet transparency obligations.

Key legal considerations

Your Data Processing Notice must contain specific information required by Articles 13 and 14 of the UK GDPR. This includes your identity as data controller, the types of personal data being processed, the purposes and legal bases for processing, data retention periods, and information about data subject rights. You must also disclose any third-party recipients of the data, international transfers, and your contact details. The notice should be written in plain English, easily accessible, and provided free of charge. If you change your processing activities, you must update the notice and inform affected data subjects. Consider including information about automated decision-making, profiling activities, and the source of data if not collected directly from individuals.

Legal requirements in England and Wales

Under the UK GDPR and Data Protection Act 2018, Data Processing Notices must comply with strict transparency requirements enforced by the Information Commissioner's Office (ICO). The notice must be provided before or at the time of data collection, with specific timeframes for indirect collection scenarios. Your organization must ensure the information is presented in a concise, transparent, and easily understandable format, using clear and plain language appropriate for your audience. The ICO's guidance emphasizes layered privacy notices for complex processing activities, allowing individuals to access detailed information when needed. Failure to provide adequate transparency information can result in administrative fines of up to 4% of annual global turnover or £17.5 million, whichever is higher, plus potential enforcement orders and reputational damage.

GOVERNING LAW

Applicable law

This Data Processing Notice is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: UK General Data Protection Regulation - The primary data protection legislation in the UK post-Brexit, setting out fundamental principles for personal data processing

DPA 2018: Data Protection Act 2018 - The UK's implementation of data protection standards, complementing and supplementing the UK GDPR

PECR: Privacy and Electronic Communications Regulations 2003 - Specific rules for electronic communications, including rules on cookies and direct marketing

ICO Guidelines: Information Commissioner's Office Guidelines and Codes of Practice - Official guidance from the UK's data protection regulator on implementing data protection requirements

EDPB Guidelines: European Data Protection Board Guidelines - While not binding post-Brexit, these guidelines remain influential in UK data protection practice

Transparency Requirements: Articles 13 and 14 of UK GDPR requiring clear information about data processing activities to be provided to data subjects

Lawful Bases: Legal grounds under UK GDPR for processing personal data, such as consent, contract, legal obligation, legitimate interests

Data Subject Rights: Rights granted to individuals under UK GDPR including access, rectification, erasure, portability, and objection to processing

International Transfers: Rules and safeguards for transferring personal data outside the UK, including adequacy decisions and appropriate safeguards

Data Retention: Requirements for specifying and adhering to defined periods for keeping personal data

Security Measures: Technical and organizational measures required to ensure appropriate security of personal data

Special Category Data: Additional requirements for processing sensitive personal data such as health, racial, religious, or biometric information

Breach Notification: Procedures and obligations for notifying authorities and affected individuals of personal data breaches

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it

Ready to agree with confidence?
See Genie in action.