Knowledge centre
Data protection · high risk
Plan a small-business privacy notice
Explain what personal data is used, why, for how long, with whom and how people exercise their rights.
Reviewed 04/08/2026Version 2
Write from the real data flow
A privacy notice should describe what the business actually does. Copying a long template can create promises that are wrong and hide the information people need.
Do this now
- Make a data map covering customers, prospects, staff, suppliers and website visitors.
- For each purpose, record the information used, source, lawful basis, recipients, location and retention period.
- Identify the legal entity or person responsible and provide a working contact route.
- Explain rights and how someone can complain.
- Give information at the right moment—for example on a form, enquiry, account creation or recruitment page—not only in a footer.
- Check that marketing consent and cookie choices are handled separately where required.
- Review processors such as email, website, CRM, payments and cloud storage.
What good looks like
A customer can understand what happens without legal training. The notice agrees with forms, software settings, contracts and retention practices, and the business can respond to a rights request.
Common mistakes
- Listing every possible lawful basis without deciding which one applies.
- Saying data is never shared while using cloud or payment providers.
- Using vague retention such as “as long as necessary” without an internal rule.
- Collecting optional information because a template includes the field.
When to get help
Get specialist advice for sensitive data, children, monitoring, profiling, international transfers, large-scale processing or unclear controller and processor roles.
Keep in your roadmap
Save the data map, published notice URL, version date, processor list and next review trigger.
