External Privacy Notice Template for England and Wales

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a External Privacy Notice?

The External Privacy Notice is a fundamental document required under UK data protection legislation. It must be provided to data subjects when collecting their personal data, explaining how and why their information is processed. This document demonstrates compliance with transparency obligations under the UK GDPR and Data Protection Act 2018, while building trust with stakeholders. The External Privacy Notice should be regularly reviewed and updated to reflect changes in data processing activities or regulatory requirements.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

England and Wales

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the External Privacy Notice

An External Privacy Notice is a crucial legal document that you must provide to individuals when collecting their personal data. Under England and Wales law, this transparency notice explains how your organization processes, stores, and protects personal information, ensuring compliance with UK GDPR and Data Protection Act 2018 requirements while building trust with your stakeholders.

When do you need this document?

You need an External Privacy Notice whenever your organization collects personal data from individuals. This includes when customers fill out contact forms on your website, sign up for newsletters, make purchases, or provide information for service delivery. The notice must be available at the point of data collection, whether through your website, mobile app, or physical forms. Public sector organizations also require this document when handling citizen data, while employers need it for processing job applicant information. If your business uses cookies or tracking technologies, processes marketing data, or shares information with third parties, an External Privacy Notice is legally mandatory.

Key legal considerations

Your External Privacy Notice must clearly identify the legal basis for processing under Article 6 of UK GDPR, whether consent, legitimate interests, contractual necessity, or legal obligation. The document should specify data retention periods, explaining how long different types of information are kept and why. You must detail any automated decision-making processes and provide clear information about data subject rights, including access, rectification, erasure, and portability. If you transfer data internationally, the notice must explain safeguards in place and the legal mechanisms used. The language must be clear, concise, and easily understandable, avoiding legal jargon that might confuse data subjects.

Legal requirements in England and Wales

Under UK GDPR and Data Protection Act 2018, your External Privacy Notice must be provided at the time of data collection and be easily accessible thereafter. The Information Commissioner's Office (ICO) requires that notices include your organization's identity, contact details, and Data Protection Officer information where applicable. You must specify the purposes for processing and the legal basis, detail any legitimate interests, and explain data sharing arrangements with third parties. The notice should outline data subject rights under UK law, including how to exercise them and lodge complaints with the ICO. For electronic communications, compliance with Privacy and Electronic Communications Regulations (PECR) 2003 is also required, particularly regarding cookies and marketing communications. Public authorities must additionally consider Freedom of Information Act 2000 obligations, while organizations handling sensitive data must implement enhanced protections under the Computer Misuse Act 1990.

GOVERNING LAW

Applicable law

This External Privacy Notice is drafted to comply with England and Wales law. Key legislation includes:

UK GDPR: The UK General Data Protection Regulation - the primary data protection legislation in the UK post-Brexit, setting out the key principles, rights and obligations for processing personal data

Data Protection Act 2018: The UK's implementation of data protection legislation that works alongside the UK GDPR, providing specific data protection requirements and derogations

PECR 2003: Privacy and Electronic Communications Regulations - specific rules for electronic communications, including rules about cookies, marketing calls, emails and texts

Freedom of Information Act 2000: Legislation providing public access to information held by public authorities, relevant for public sector organizations

Computer Misuse Act 1990: Legislation covering unauthorized access to computer systems and data, relevant for security aspects of data protection

Human Rights Act 1998: Particularly Article 8 which enshrines the right to respect for private and family life, home and correspondence

ICO Guidelines: Regulatory guidance and codes of practice issued by the Information Commissioner's Office, the UK's data protection authority

EDPB Guidelines: European Data Protection Board guidelines which, while not binding post-Brexit, remain influential in UK data protection practice

EU GDPR: The European Union's General Data Protection Regulation, relevant when processing data of EU residents or operating in the EU

International Transfer Requirements: Post-Brexit requirements for transferring personal data between the UK and other countries, including adequacy decisions and appropriate safeguards

Financial Services and Markets Act 2000: Specific regulations for financial services sector handling personal data, including additional security and privacy requirements

Health and Social Care Act 2012: Specific regulations for handling medical and healthcare data, including additional privacy and confidentiality requirements

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it