A privacy notice tells people what personal data you collect about them, why, who you share it with, how long you keep it and what rights they have. Most data-protection laws require one, and many also require it to be concise and in clear language. The good news is that plain language is easier to write than legalese, once you know what you actually do with the data. The exact required contents vary by jurisdiction, so check what applies to you; the structure below covers what most regimes ask for.
Start from what you actually do
Do not start from someone else's template. Start with a list, per group of people you deal with (clients, tenants, staff, website visitors, research participants), of:
- What data you collect, and where it comes from
- What you use it for, and the legal basis where your law requires one
- Who you share it with: service providers, advisers, authorities
- Where it is stored, including any transfers abroad
- How long you keep it
If you cannot fill this in, the notice is not your problem yet; knowing your data is. Privacy by design for small businesses helps with that step.
A structure that works
- Who we are and how to contact us about privacy.
- What we collect, grouped by type, in everyday words.
- Why we use it, each purpose linked to the data it needs.
- Who we share it with, by category, and why.
- How long we keep it, as periods or clear criteria.
- How we protect it, briefly and truthfully.
- Your rights and how to use them.
- How to complain, to you and to the relevant authority.
- Changes to the notice, with the date of the current version.
Plain-language rewrites
| Instead of | Write |
|---|---|
| We may process your personal data for the purposes of the performance of a contract | We use your name, address and payment details to provide the service you signed up for |
| Data may be disclosed to third parties | We share your details with our accountant and our IT provider, who only use them to work for us |
| Data will be retained for as long as necessary | We keep your file for six years after your matter closes, then delete it |
| Appropriate technical and organisational measures | Files are encrypted, access is limited to the people working on your matter, and all staff use two-factor sign-in |
Writing rules
- Use "we" and "you".
- One idea per sentence; short paragraphs; headings people can scan.
- Be specific. "May" and "such as" hide what you do; if you share with three kinds of provider, name the three kinds.
- Put the things people care about first: what you collect, who sees it, how long you keep it.
- Layer it: a short summary at the top, detail below or on a linked page.
Be truthful about your tools
Everything you claim must be true today. If client files sit in a case-management system, the provider is a processor and belongs in your sharing section; if you say data is encrypted and access-limited, it must be. In a system like Herarx, files are encrypted at rest, access is set per case, and there is an audit trail of activity, which makes the "how we protect it" section easy to write honestly. Describe how you share documents with clients as well; file sharing with clients covers the options.
Keep it true
Date every version and keep the old ones. Review the notice whenever you add a new tool, a new use of data or a new kind of client, and at least once a year. Tie it to the people who will act on it: the rights section should match how you actually handle requests, and the mistakes in subject access requests are much easier to avoid when the notice and the process agree.