How to Write a Privacy Notice in Plain Language — Herarx Blog

How to Write a Privacy Notice in Plain Language

A privacy notice people can actually read: what it must cover, a section-by-section structure, plain-language rewrites of the usual legalese, and how to keep it true.

December 13, 2025
How to Write a Privacy Notice in Plain Language
Back to blog

A privacy notice tells people what personal data you collect about them, why, who you share it with, how long you keep it and what rights they have. Most data-protection laws require one, and many also require it to be concise and in clear language. The good news is that plain language is easier to write than legalese, once you know what you actually do with the data. The exact required contents vary by jurisdiction, so check what applies to you; the structure below covers what most regimes ask for.

Start from what you actually do

Do not start from someone else's template. Start with a list, per group of people you deal with (clients, tenants, staff, website visitors, research participants), of:

  • What data you collect, and where it comes from
  • What you use it for, and the legal basis where your law requires one
  • Who you share it with: service providers, advisers, authorities
  • Where it is stored, including any transfers abroad
  • How long you keep it

If you cannot fill this in, the notice is not your problem yet; knowing your data is. Privacy by design for small businesses helps with that step.

A structure that works

  1. Who we are and how to contact us about privacy.
  2. What we collect, grouped by type, in everyday words.
  3. Why we use it, each purpose linked to the data it needs.
  4. Who we share it with, by category, and why.
  5. How long we keep it, as periods or clear criteria.
  6. How we protect it, briefly and truthfully.
  7. Your rights and how to use them.
  8. How to complain, to you and to the relevant authority.
  9. Changes to the notice, with the date of the current version.

Plain-language rewrites

Instead ofWrite
We may process your personal data for the purposes of the performance of a contractWe use your name, address and payment details to provide the service you signed up for
Data may be disclosed to third partiesWe share your details with our accountant and our IT provider, who only use them to work for us
Data will be retained for as long as necessaryWe keep your file for six years after your matter closes, then delete it
Appropriate technical and organisational measuresFiles are encrypted, access is limited to the people working on your matter, and all staff use two-factor sign-in

Writing rules

  • Use "we" and "you".
  • One idea per sentence; short paragraphs; headings people can scan.
  • Be specific. "May" and "such as" hide what you do; if you share with three kinds of provider, name the three kinds.
  • Put the things people care about first: what you collect, who sees it, how long you keep it.
  • Layer it: a short summary at the top, detail below or on a linked page.

Be truthful about your tools

Everything you claim must be true today. If client files sit in a case-management system, the provider is a processor and belongs in your sharing section; if you say data is encrypted and access-limited, it must be. In a system like Herarx, files are encrypted at rest, access is set per case, and there is an audit trail of activity, which makes the "how we protect it" section easy to write honestly. Describe how you share documents with clients as well; file sharing with clients covers the options.

Keep it true

Date every version and keep the old ones. Review the notice whenever you add a new tool, a new use of data or a new kind of client, and at least once a year. Tie it to the people who will act on it: the rights section should match how you actually handle requests, and the mistakes in subject access requests are much easier to avoid when the notice and the process agree.