Privacy Notice Template
Template
Privacy notice template (UK SME)
A starter UK GDPR-compliant privacy notice template covering the standard processing every SME does (customers, suppliers, prospects, employees, website visitors).
Who it’s for: Founders and operations leads at UK SMEs
How to use
Follow these steps
Identify all processing activities
Customers (orders, accounts, support), suppliers (contracts, invoices), prospects (marketing, lead capture), employees and contractors, website visitors (analytics, cookies).
Determine the lawful basis for each
Contract performance, legitimate interests, consent, legal obligation, or vital interests. Most B2B processing falls into Contract or Legitimate Interests. Marketing typically needs consent.
Document the data categories
What personal data you collect per activity — name, email, phone, business address, payment details, IP address, etc. Be specific.
Document the retention periods
How long you keep each category. Common: customer records 7 years (HMRC requirement), prospect data until withdrawal of consent, CV / unsuccessful applicants 6 months.
Document the data sharing
Who you share data with: payroll provider, accountant, marketing platform, IT support, regulator. Include international transfers and the safeguard (Standard Contractual Clauses, adequacy decision).
Document the rights
Standard UK GDPR rights — access, rectification, erasure, restriction, portability, objection, withdrawal of consent — plus how to exercise them (typically an email address).
Publish on your website
Link from the website footer and from any form that collects personal data. Date the notice and add a change log so updates are visible.
Rajoka Insights
Operating notes from a UK house of brands.
A weekly note from Mehmood. House-of-brands strategy, UK operating, and what's working across the portfolio. No fluff.
Delivered via Substack. Unsubscribe anytime.
Explore Rajoka
A family of firms. One operating standard.
Pick a brand, pick a stage, or tell us your problem.