A well structured privacy statement is key to GDPR compliance and a crucial trust signal to customers and suppliers. However, many organisations get this crucial data protection requirement wrong.
What is a Privacy Statement?
What is a Privacy Statement? Under the GDPR people have the right to be informed. This obliges data processors to provide people with details about how their data will be used, and their rights to control this. Typically you have to provide this at the point the data are collected.
This means data processors need to provide a privacy statement that sets out:
- the data you collect
- What you use it for
- What the lawful basis for doing so is
- People’s rights to control this; and
- How people can exercise their rights
The privacy statement must also include details of your Data Protection Officer if you have one.
Why are they important?
As a legal requirement a privacy statement is an important part of GDPR compliance. They are also a great way of keeping people informed about your data processing. This makes it a useful tool for engaging with customers, suppliers and employees.
The requirement to have a privacy statement is key to comply with people’s right to be informed. Article 13 of the GDPR states that organisations collecting data from people must, at the time the data are collected, tell them:
- who is collecting and using the data
- the purposes of the data processing
- the lawful basis for doing so
- plus a range of other information
What does a good privacy statement look like?
A good privacy statement must be both comprehensive but also succinct.
While most organisations put their privacy statements online, you don’t have to – but you do have to make it easily accessible and free of charge.
One of the advantages of having an online privacy statement, alongside accessibility, is that you can get the balance between comprehensive and succinct right.

Our approach is to provide a summary of our data processing activity, but also providing a much more detailed document describing our data processing in greater depth. Finally we invite people to contact us with any questions. These three ways of accessing privacy information will suit different cohorts of people with different needs.
Things we also include, that many don’t are:
- details of our registration with the Information Commissioner. This is a legal requirement so is good to share
- summaries of things we don’t do like buying or selling marketing lists. This helps avoid doubts or gaps in information that people may be interested in
- go into some detail about some of the organisations we work with, like those who manage our email lists, so they can look at their privacy information too
Top Five Mistakes
Of course a lot of organisations don’t seem to have any privacy information at all, which is probably the biggest mistake of all. But for those that do, this is where they inadvertently fall down:
1. They use a generic template without adapting it
Each privacy notice must be specific to the organisation processing data. This is because even organisations in the same sector, even direct competitors, will process data in different ways. For example some organisations use consent as the lawful basis for processing the data of prospective customers, others rely on (in our view the better) lawful basis of contractual obligation. While this may feel superficial it does affect how people can exercise their rights. Similarly they may have different IT systems, different organisation structures and so on.
We still even see references to the Data Protection Act 1998 in some privacy statements. This really shows they have not been reviewed or adapted.
Generic privacy statement templates are useful. However, they must be adapted to your organisation and the data processing it does.

This privacy statement is clearly inadequate and does not come close to meeting legal requirements. Would you trust an organisation that produces legal documents like this? Both consumers and potential partners might be put off doing business with this organisation based on this privacy statement.
2. They fail to cover employees, or other important areas of data processing
It is important that your privacy statement is comprehensive so it must include everyone whose data you process. In almost every instance privacy statements fail to cover the processing of employee data, yet employees are people too!
Of course you can set out separate privacy information for employees, but we thinks it is a good idea to include employee data processing in your published privacy information because it:
- is an easy way for employees to find it
- informs prospective employees of what data you process for recruitment and appointment purposes
- helps avoid version control issues by having two different sources of privacy information available

It doesn’t discuss employees. It also doesn’t cover financial information for service provision or payments, or any legally required data collection. These will be core parts of the company’s services.
Also, like many privacy statements it seems to only cover the use of the company’s website. In fact your privacy statement should cover all your data processing.
3. They get the lawful basis for processing wrong
It is important to get the lawful basis you are relying on right when setting out your privacy statement. This is for two reasons:
- the lawful basis you rely on will impact on how you comply with people’s rights
- some lawful bases require different approaches to demonstrate compliance. The Legitimate Interests lawful basis requires you to show how you have minimised the impact on people’s privacy. That is different to how you comply with consent as a lawful basis.
One of the challenges we still see is an overreliance on consent as a lawful basis, particularly as a catch-all lawful basis for all data processing. This can be a problem because consent is only appropriate as a lawful basis in some circumstances. It is useful for data processing that is consequence free. If the data processing must be done to, for example, engage with a prospective customer (providing a quote for example) then another lawful basis is more appropriate.
Also you may rely on more than one lawful basis for data processing throughout a customer or employee’s journey through your systems. You must think about all the things you use personal data for and define the lawful basis for all of them.

Firstly when someone contacts you they obviously want you to use their information to reply so the additional step of having the checkbox is not necessary.
Secondly is consent the right lawful basis here? It may be but prospective customers would have their data processed under the Contractual Obligation lawful basis. For other enquiries the Legitimate Interests lawful basis may be suitable.
4. The are far too legalistic
Privacy statements are there to engage with the people whose data you process, and to help you comply with their rights.
They are not a form of contract or a way of indemnifying yourself against a data breach or other tool to protect you from action. Yet too many privacy statements use dense legal language or contain irrelevant, sometimes bizarre information.

Why should someone leave a website if they disagree with any part of it? Why should a privacy statement cover information that could not identify a person?
Remembering what a privacy statement is for, and why it is required, will help you make it both comprehensive and succinct.
5. They don’t write for their audience
Privacy statements must be developed for the people whose data you collect and process, and by extension must be presented in a form that they can understand.
This means you must take care if there is any impediment to the people whose data you process understanding the information you want to provide. Examples include:
- Producing audible privacy statements for people who are partially sighted or blind
- Considering providing translations if you deal with people who don’t speak English
- Using simple and straightforward language for younger people
- Using videos or animations to explain complex data flows, rather than text
The problem here often arises from the legalistic issue described above. It can also arise because people misunderstand how GDPR rights apply to children and other vulnerable groups. Ultimately they can arise because we tend to write for people like us, and don’t always have insight into our audience’s needs.
Sign Up Here:
Our tips for drafting a high quality privacy statement: NB: The examples shared above are real live privacy statements in the public domain. We have where necessary removed anything that identifies the organisation that published them, and we have no reason to suppose they handle data inappropriately. However, we have contacted them to offer support to make improvements. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence. To improve your understanding of the GDPR and improve your compliance you can do any or all of the following: How to Draft a Privacy Statement
Three Free Things You Can Do Right Now
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: