Privacy Statement: the Top Five Things Organisations Get Wrong

A well structured privacy statement is key to GDPR compliance and a crucial trust signal to customers and suppliers. However, many organisations get this crucial data protection requirement wrong.

What is a Privacy Statement?

What is a Privacy Statement? Under the GDPR people have the right to be informed. This obliges data processors to provide people with details about how their data will be used, and their rights to control this. Typically you have to provide this at the point the data are collected.

This means data processors need to provide a privacy statement that sets out:

  • the data you collect
  • What you use it for
  • What the lawful basis for doing so is
  • People’s rights to control this; and
  • How people can exercise their rights

The privacy statement must also include details of your Data Protection Officer if you have one.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Why are they important?

 

As a legal requirement a privacy statement is an important part of GDPR compliance. They are also a great way of keeping people informed about your data processing. This makes it a useful tool for engaging with customers, suppliers and employees.

The requirement to have a privacy statement is key to comply with people’s right to be informed. Article 13 of the GDPR states that organisations collecting data from people must, at the time the data are collected, tell them:

  • who is collecting and using the data
  • the purposes of the data processing
  • the lawful basis for doing so
  • plus a range of other information

 

What does a good privacy statement look like?

 

A good privacy statement must be both comprehensive but also succinct.

While most organisations put their privacy statements online, you don’t have to – but you do have to make it easily accessible and free of charge.

One of the advantages of having an online privacy statement, alongside accessibility, is that you can get the balance between comprehensive and succinct right.

A succinct but not comprehensive privacy statementAn example of a poor privacy statement: succinct, but not comprehensive.

 

Our approach is to provide a summary of our data processing activity, but also providing a much more detailed document describing our data processing in greater depth. Finally we invite people to contact us with any questions. These three ways of accessing privacy information will suit different cohorts of people with different needs.

Things we also include, that many don’t are:

  • details of our registration with the Information Commissioner. This is a legal requirement so is good to share
  • summaries of things we don’t do like buying or selling marketing lists. This helps avoid doubts or gaps in information that people may be interested in
  • go into some detail about some of the organisations we work with, like those who manage our email lists, so they can look at their privacy information too

Top Five Mistakes

 

Of course a lot of organisations don’t seem to have any privacy information at all, which is probably the biggest mistake of all. But for those that do, this is where they inadvertently fall down:

1. They use a generic template without adapting it

Each privacy notice must be specific to the organisation processing data. This is because even organisations in the same sector, even direct competitors, will process data in different ways. For example some organisations use consent as the lawful basis for processing the data of prospective customers, others rely on (in our view the better) lawful basis of contractual obligation. While this may feel superficial it does affect how people can exercise their rights. Similarly they may have different IT systems, different organisation structures and so on.

We still even see references to the Data Protection Act 1998 in some privacy statements. This really shows they have not been reviewed or adapted.

Generic privacy statement templates are useful. However, they must be adapted to your organisation and the data processing it does.

A generic privacy notice that has not been updatedThis is an example of a template privacy statement that has not been reviewed and completed to provide organisation specific information

This privacy statement is clearly inadequate and does not come close to meeting legal requirements. Would you trust an organisation that produces legal documents like this? Both consumers and potential partners might be put off doing business with this organisation based on this privacy statement.

2. They fail to cover employees, or other important areas of data processing

It is important that your privacy statement is comprehensive so it must include everyone whose data you process. In almost every instance privacy statements fail to cover the processing of employee data, yet employees are people too!

Of course you can set out separate privacy information for employees, but we thinks it is a good idea to include employee data processing in your published privacy information because it:

  • is an easy way for employees to find it
  • informs prospective employees of what data you process for recruitment and appointment purposes
  • helps avoid version control issues by having two different sources of privacy information available

a privacy statement that is not comprehensiveThis privacy statement by a firm of accountants does not cover data processing very widely.

It doesn’t discuss employees. It also doesn’t cover financial information for service provision or payments, or any legally required data collection. These will be core parts of the company’s services.

Also, like many privacy statements it seems to only cover the use of the company’s website. In fact your privacy statement should cover all your data processing.

3. They get the lawful basis for processing wrong

It is important to get the lawful basis you are relying on right when setting out your privacy statement. This is for two reasons:

  • the lawful basis you rely on will impact on how you comply with people’s rights
  • some lawful bases require different approaches to demonstrate compliance. The Legitimate Interests lawful basis requires you to show how you have minimised the impact on people’s privacy. That is different to how you comply with consent as a lawful basis.

 

One of the challenges we still see is an overreliance on consent as a lawful basis, particularly as a catch-all lawful basis for all data processing. This can be a problem because consent is only appropriate as a lawful basis in some circumstances. It is useful for data processing that is consequence free. If the data processing must be done to, for example, engage with a prospective customer (providing a quote for example) then another lawful basis is more appropriate.

Also you may rely on more than one lawful basis for data processing throughout a customer or employee’s journey through your systems. You must think about all the things you use personal data for and define the lawful basis for all of them.

 

An example of an online contact formThis contact form is not part of a privacy statement but requires explicit consent before anyone can contact the company via an online form.

Firstly when someone contacts you they obviously want you to use their information to reply so the additional step of having the checkbox is not necessary.

Secondly is consent the right lawful basis here? It may be but prospective customers would have their data processed under the Contractual Obligation lawful basis. For other enquiries the Legitimate Interests lawful basis may be suitable.

4. The are far too legalistic

Privacy statements are there to engage with the people whose data you process, and to help you comply with their rights.

They are not a form of contract or a way of indemnifying yourself against a data breach or other tool to protect you from action. Yet too many privacy statements use dense legal language or contain irrelevant, sometimes bizarre information.

 

An overly legalistic privacy statementA privacy statement is not a form of terms and conditions for your services.

Why should someone leave a website if they disagree with any part of it? Why should a privacy statement cover information that could not identify a person?

Remembering what a privacy statement is for, and why it is required, will help you make it both comprehensive and succinct.

5. They don’t write for their audience

Privacy statements must be developed for the people whose data you collect and process, and by extension must be presented in a form that they can understand.

This means you must take care if there is any impediment to the people whose data you process understanding the information you want to provide. Examples include:

  • Producing audible privacy statements for people who are partially sighted or blind
  • Considering providing translations if you deal with people who don’t speak English
  • Using simple and straightforward language for younger people
  • Using videos or animations to explain complex data flows, rather than text

The problem here often arises from the legalistic issue described above. It can also arise because people misunderstand how GDPR rights apply to children and other vulnerable groups. Ultimately they can arise because we tend to write for people like us, and don’t always have insight into our audience’s needs.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

How to Draft a Privacy Statement

 

Our tips for drafting a high quality privacy statement:

  1. Understand all your data processing activity and the different lawful bases you rely on to do it. This will help your privacy statement be comprehensive.
  2. Understand your audience – customers, suppliers and employees – and write your privacy statement for them. Where possible engage with them to get the privacy statement into the best possible state.
  3. Use the simplest possible language. Avoid being legalistic. You are not trying to control people’s behaviour or establish a legal defence.
  4. Take the opportunity to engage, reassure and promote your commitment to privacy and compliance. This will help people trust you.
  5. Make your privacy statement as accessible as possible. Use animations, videos, infographics or other media to engage with people and reduce complexity.

  

NB: The examples shared above are real live privacy statements in the public domain. We have where necessary removed anything that identifies the organisation that published them, and we have no reason to suppose they handle data inappropriately. However, we have contacted them to offer support to make improvements.

 

Three Free Things You Can Do Right Now

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial

To improve your understanding of the GDPR and improve your compliance you can do any or all of the following: