Data protection · Check before acting
Write a privacy notice for what your business really does
Map the personal data first, then explain what you collect, why, who receives it, how long it is kept and how people can use their rights.
Write from the real data flow
A privacy notice should describe what the business actually does. Copying a long template can create promises that are wrong and hide the information people need.
Do this now
- Make a data map covering customers, prospects, staff, suppliers and website visitors.
- For each purpose, record the information used, source, lawful basis, recipients, location and retention period.
- Identify the legal entity or person responsible and provide a working contact route.
- Explain rights and how someone can complain.
- Give information at the right moment—for example on a form, enquiry, account creation or recruitment page—not only in a footer.
- Check that marketing consent and cookie choices are handled separately where required.
- Review processors such as email, website, CRM, payments and cloud storage.
What good looks like
A customer can understand what happens without legal training. The notice agrees with forms, software settings, contracts and retention practices, and the business can respond to a rights request.
Common mistakes
- Listing every possible lawful basis without deciding which one applies.
- Saying data is never shared while using cloud or payment providers.
- Using vague retention such as “as long as necessary” without an internal rule.
- Collecting optional information because a template includes the field.
When to get help
Get specialist advice for sensitive data, children, monitoring, profiling, international transfers, large-scale processing or unclear controller and processor roles.
Keep in your roadmap
Save the data map, published notice URL, version date, processor list and next review trigger.
