External Privacy Notice Template for England and Wales
Generate a bespoke document
What is a External Privacy Notice?
The External Privacy Notice is a fundamental document required under UK data protection legislation. It must be provided to data subjects when collecting their personal data, explaining how and why their information is processed. This document demonstrates compliance with transparency obligations under the UK GDPR and Data Protection Act 2018, while building trust with stakeholders. The External Privacy Notice should be regularly reviewed and updated to reflect changes in data processing activities or regulatory requirements.
About the External Privacy Notice
An External Privacy Notice is a crucial legal document that you must provide to individuals when collecting their personal data. Under England and Wales law, this transparency notice explains how your organization processes, stores, and protects personal information, ensuring compliance with UK GDPR and Data Protection Act 2018 requirements while building trust with your stakeholders.
When do you need this document?
You need an External Privacy Notice whenever your organization collects personal data from individuals. This includes when customers fill out contact forms on your website, sign up for newsletters, make purchases, or provide information for service delivery. The notice must be available at the point of data collection, whether through your website, mobile app, or physical forms. Public sector organizations also require this document when handling citizen data, while employers need it for processing job applicant information. If your business uses cookies or tracking technologies, processes marketing data, or shares information with third parties, an External Privacy Notice is legally mandatory.
Key legal considerations
Your External Privacy Notice must clearly identify the legal basis for processing under Article 6 of UK GDPR, whether consent, legitimate interests, contractual necessity, or legal obligation. The document should specify data retention periods, explaining how long different types of information are kept and why. You must detail any automated decision-making processes and provide clear information about data subject rights, including access, rectification, erasure, and portability. If you transfer data internationally, the notice must explain safeguards in place and the legal mechanisms used. The language must be clear, concise, and easily understandable, avoiding legal jargon that might confuse data subjects.
Legal requirements in England and Wales
Under UK GDPR and Data Protection Act 2018, your External Privacy Notice must be provided at the time of data collection and be easily accessible thereafter. The Information Commissioner's Office (ICO) requires that notices include your organization's identity, contact details, and Data Protection Officer information where applicable. You must specify the purposes for processing and the legal basis, detail any legitimate interests, and explain data sharing arrangements with third parties. The notice should outline data subject rights under UK law, including how to exercise them and lodge complaints with the ICO. For electronic communications, compliance with Privacy and Electronic Communications Regulations (PECR) 2003 is also required, particularly regarding cookies and marketing communications. Public authorities must additionally consider Freedom of Information Act 2000 obligations, while organizations handling sensitive data must implement enhanced protections under the Computer Misuse Act 1990.
GOVERNING LAW
Applicable law
This External Privacy Notice is drafted to comply with England and Wales law. Key legislation includes:
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it