Privacy Policy UK 2026: How to Write a Compliant Policy
15 August 2026
Learn how to write a UK GDPR-compliant privacy policy in 2026. Cover ICO requirements, cookies, and data subject rights. Free checklist included.
What is a privacy policy and why does the UK require one?
A privacy policy is a legal document that explains how your organisation collects, uses, stores, and shares personal data. In the UK, it is not just good practice – it is a legal requirement under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The Information Commissioner’s Office (ICO) expects every website or app that processes personal data to provide a transparent privacy notice. This includes data collected via contact forms, newsletter sign-ups, analytics, and cookies. Failing to provide one can lead to fines and reputational damage. Even if your site is small or you only collect an email address, you must have a privacy policy that clearly informs users about their rights and your processing activities.
Key legal frameworks: UK GDPR, Data Protection Act 2018, and PECR
The UK’s data protection landscape is governed by the UK GDPR, which aligns closely with the EU GDPR but operates independently post-Brexit. The Data Protection Act 2018 supplements the UK GDPR and sets out specific rules for law enforcement, national security, and other areas. Additionally, the Privacy and Electronic Communications Regulations (PECR) govern cookies, direct marketing, and electronic communications. When writing your privacy policy, you must reference these laws accurately. For example, if you use cookies for tracking, you need to disclose this and obtain consent under PECR. Also, note that if you serve customers in the EU, you may still need to comply with the EU GDPR. Your policy should clearly state your lawful bases for processing data.
Essential clauses every UK privacy policy must include
A UK-compliant privacy policy must cover certain key elements. Start with who you are (the data controller) and your contact details. Explain what personal data you collect, the purposes for processing, and the lawful bases under Article 6 of the UK GDPR. You must also state how long you retain data and whether you share it with third parties, including processors. Another crucial clause is how you handle international transfers – if you send data outside the UK, you must ensure safeguards are in place, such as International Data Transfer Agreements. Finally, you must detail user rights: the right to access, rectification, erasure, restriction, portability, and objection. You should also explain how users can complain to the ICO.
How to handle cookies and tracking under UK law
In the UK, cookies and similar tracking technologies are regulated not just by the UK GDPR but also by PECR. Before setting any non-essential cookies – such as those for analytics, advertising, or social media – you must obtain prior informed consent. This means your cookie banner must be easy to use, with clear options to accept or reject. Your privacy policy should include a dedicated section on cookies, listing each category and purpose. You must also explain how users can change their preferences or delete cookies. Since 2024, the ICO has been cracking down on 'cookie fatigue' tactics, so make refusal as easy as consent. In 2026, expect further enforcement, so keep your cookie consent framework up to date.
Privacy policy best practices for UK websites in 2026
Beyond legal compliance, a good privacy policy builds trust. Use plain English – avoid excessive legal jargon – and make your policy easy to find, typically via a footer link. Keep it up to date: review it at least annually or whenever your processing changes. Consider using a layered approach: a short summary of key points followed by a full policy. Ensure your policy is accessible, including for users with disabilities, and works on mobile. Also, be transparent about automated decision-making and profiling. In 2026, the ICO is increasingly focusing on 'privacy by design', so show evidence that you’ve baked privacy into your products. Finally, obtain legal advice if you’re unsure – a free template may not cover all your activities.
FAQ
If you don’t collect any personal data, you may not need a full privacy policy, but most websites do collect some data indirectly – such as IP addresses or cookies. Even if you have no forms, analytics tools like Google Analytics collect data. So, in practice, nearly every UK public-facing website requires a privacy policy. If you truly collect nothing, you can publish a simple statement explaining that, but remember that server logs often capture IP addresses automatically.