Knowledge centre

Data protection · high risk

Plan a small-business privacy notice

Explain what personal data is used, why, for how long, with whom and how people exercise their rights.

Reviewed 04/08/2026Version 2

Write from the real data flow

A privacy notice should describe what the business actually does. Copying a long template can create promises that are wrong and hide the information people need.

Do this now

  1. Make a data map covering customers, prospects, staff, suppliers and website visitors.
  2. For each purpose, record the information used, source, lawful basis, recipients, location and retention period.
  3. Identify the legal entity or person responsible and provide a working contact route.
  4. Explain rights and how someone can complain.
  5. Give information at the right moment—for example on a form, enquiry, account creation or recruitment page—not only in a footer.
  6. Check that marketing consent and cookie choices are handled separately where required.
  7. Review processors such as email, website, CRM, payments and cloud storage.

What good looks like

A customer can understand what happens without legal training. The notice agrees with forms, software settings, contracts and retention practices, and the business can respond to a rights request.

Common mistakes

  • Listing every possible lawful basis without deciding which one applies.
  • Saying data is never shared while using cloud or payment providers.
  • Using vague retention such as “as long as necessary” without an internal rule.
  • Collecting optional information because a template includes the field.

When to get help

Get specialist advice for sensitive data, children, monitoring, profiling, international transfers, large-scale processing or unclear controller and processor roles.

Keep in your roadmap

Save the data map, published notice URL, version date, processor list and next review trigger.