# UK GDPR privacy policy: contents and recent changes

> What a UK GDPR privacy notice must include, how the Data (Use and Access) Act 2025 adds complaint handling, and which clauses cover it.

A UK GDPR privacy policy must give the same core information as the EU version: who you are, what you collect, why and on what lawful basis, who receives it, international transfers, retention, and individual rights, including the right to complain to the Information Commissioner's Office. Since June 19, 2026, it should also explain how people can make a data protection complaint to you, because the Data (Use and Access) Act 2025 now requires controllers to have a complaints process.

Canonical URL: https://legalpolicygenerator.com/laws/uk-gdpr-privacy-policy

## Who this law applies to

The UK GDPR, read together with the Data Protection Act 2018, applies to processing in the context of the activities of an establishment in the United Kingdom. Like the EU text, it also reaches controllers and processors outside the UK that offer goods or services to people in the UK or monitor their behaviour there. Since the end of the Brexit transition period it has been a separate regime from the EU GDPR, so a business serving both markets has two sets of obligations, two regulators, and separate transfer rules. Overseas controllers caught by the extraterritorial rule generally need a UK representative, subject to exceptions. There is no size threshold for transparency duties. The Data (Use and Access) Act 2025 received Royal Assent on June 19, 2025 and is being brought into force in stages under the government's published commencement plan. The duty to have a data protection complaints procedure commenced on June 19, 2026. The ICO has said that parts of its right-to-be-informed guidance are under review because of the Act, so check the current commencement status of any provision before relying on it.

## What your privacy policy must include

The ICO's list of privacy information covers the name and contact details of your organisation; the name and contact details of your representative and data protection officer where you have them; the purposes of processing; the lawful basis for each purpose; the legitimate interests pursued where that basis is used; the categories of personal data obtained where it did not come from the individual; the recipients or categories of recipients; details of transfers outside the UK and the safeguards used; retention periods or the criteria used to set them; the rights available to individuals; the right to withdraw consent where consent is relied on; the right to lodge a complaint with a supervisory authority; the source of the data where it was not obtained from the individual; whether providing data is a statutory or contractual requirement; and the existence of automated decision-making, including profiling. With the Data (Use and Access) Act complaint provisions in force, the policy should also tell people how to complain to you directly. The Act expects controllers to facilitate complaints, for example with an electronic form, to acknowledge a complaint within 30 days of receiving it, to take appropriate steps to respond without undue delay, and to tell the complainant the outcome. Information must still be concise, transparent, intelligible, easily accessible, and in clear and plain language.

## How Legal Policy Generator handles it

Selecting United Kingdom GDPR adds a UK legal-bases clause and a UK rights clause that are separate from the EU clauses, so UK readers see the ICO, UK terminology, and the UK complaint process rather than EU wording. The UK rights clause states that the operator will acknowledge a data-protection complaint within 30 days, investigate without undue delay, keep the complainant informed, and communicate the outcome. The international-transfers clause becomes active with a UK-specific transfer statement. The list below is read from the clause library each time this page is rendered.

## Questionnaire answers that switch it on

The UK clauses activate only when the jurisdiction answer includes United Kingdom GDPR. Validation then requires at least one lawful basis, a purpose-to-basis mapping when more than one basis is chosen, an answer on whether UK information is transferred internationally, and confirmations about sensitive information and significant solely automated decisions. The UK module accepts a recognised legitimate interest basis introduced by the Data (Use and Access) Act 2025; choose it only where a listed condition applies and the provision is in force, and note that it is filtered out of EU wording when both modules are selected. Optional answers add a UK data protection officer contact and a UK representative contact. Transfer answers are kept separate from EU transfer answers, because UK adequacy regulations and the UK transfer tools differ from EU mechanisms. The complaint methods shown to readers come from the privacy request methods you select.

## Common mistakes

Reusing EU text that refers to the EU, a member-state authority, or EU standard contractual clauses without the UK tools confuses UK readers and may misdescribe transfers; UK transfers commonly rely on UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU clauses. Leaving out a direct complaint route is now a gap for UK controllers. Promising a complaint response faster than the business can deliver creates a public commitment that will be tested. Treating recognised legitimate interests as a general replacement for a balancing test overstates a narrow provision. Forgetting that ICO guidance is being updated can leave a notice relying on superseded wording. As with the EU regime, the notice has to match actual processing, contracts, security, and request handling.

## Common questions

### Do I need separate EU and UK privacy policies?

Not necessarily. One document can contain separate EU and UK sections, which is how the generator combines the two modules when both are selected.

### What did the Data (Use and Access) Act 2025 change for privacy notices?

Among other changes, controllers must now have a process for data protection complaints, which commenced on June 19, 2026. The Act also added recognised legitimate interests and other provisions that are commenced in stages.

### Does a UK business with EU customers need to follow both regimes?

It can. If it offers goods or services to people in the EU or monitors them there, the EU GDPR can apply alongside the UK GDPR, and an EU representative may be required.

### Is the ICO's privacy information guidance final?

The ICO has stated that its right-to-be-informed guidance is under review because of the Data (Use and Access) Act. Check the current version before publishing.

### Is the generated UK wording legal advice?

No. It reflects supplied facts and is not a guarantee of compliance. High-risk processing or unusual transfers need qualified review.

Generated wording reflects supplied facts. It is not legal advice or a guarantee of compliance or enforceability.
