How to write a privacy notice your users will actually understand
Last updated: 3 August 2026
By StartupDocs · Published 3 August 2026
A privacy notice is one of those documents founders often copy from a larger company's website, tweak a few names, and publish without much thought. The result is usually a wall of legalese that nobody reads and that may not even reflect what your startup actually does with personal data.
That approach carries real risk. Under UK GDPR and the UK Data Protection Act 2018, a privacy notice is a legal requirement, and the Information Commissioner's Office (ICO) expects it to be clear, concise, and accurate. Here is how to get it right.
What a privacy notice is for
A privacy notice tells people what personal data you collect about them, why you collect it, what you do with it, how long you keep it, and what their rights are. It is not the same as a cookie notice (though the two are often published together) and it is not the same as a data processing agreement.
You need one wherever you collect personal data: your website, your app, a sign-up form, a customer onboarding flow.
The information you must include
UK GDPR sets out a specific list of what a privacy notice must cover. Missing items can mean your processing lacks a proper lawful basis, or that individuals cannot exercise their rights effectively.
Your notice should cover:
- Who you are - your company name, address, and contact details
- Your data protection contact - an email address for privacy queries (most small startups do not need a formal Data Protection Officer, but you still need a contact point)
- What data you collect - be specific; "personal information" is too vague
- Why you collect it - the purpose of each type of processing
- Your lawful basis - consent, legitimate interests, contract performance, legal obligation, and so on
- Who you share data with - third-party processors, analytics tools, payment providers
- International transfers - if data leaves the UK or EEA, you must explain the safeguards in place
- How long you keep data - or the criteria you use to decide retention periods
- Individual rights - access, rectification, erasure, restriction, portability, objection
- How to complain - including the right to complain to the ICO
Writing in plain English
The ICO is explicit that privacy notices should be written in plain language. That means:
- Short sentences and short paragraphs
- Everyday words instead of legal terms where possible ("we collect" not "data subjects' personal data shall be processed")
- Active voice where you can manage it
- Concrete examples ("for example, your name, email address, and billing postcode")
Avoid copying directly from larger companies. Their notices often reflect complex group structures, international operations, and dozens of processing activities that simply do not apply to a ten-person startup.
Layered notices: a practical approach
If you genuinely need to cover a lot of ground, consider a layered approach. The first layer is a short summary, visible at the point of data collection, covering the essentials in a few sentences. The full notice sits behind a link for anyone who wants more detail.
This works well for sign-up forms, checkout flows, and mobile apps where screen space is limited.
Keeping your notice up to date
A privacy notice is not a one-off task. Every time you add a new tool, change a processor, start collecting a new type of data, or change your retention periods, your notice should be reviewed and updated.
Good habits to build:
- Review your notice whenever you onboard a new SaaS tool that processes personal data
- Date-stamp your notice so users know when it was last updated
- Keep a brief internal log of changes so you can demonstrate accountability if the ICO ever asks
Common mistakes to avoid
Vague lawful bases. Stating "legitimate interests" without explaining what those interests are will not satisfy the ICO's standards. Be specific.
Listing tools you no longer use. If you switched analytics providers six months ago, update the notice to reflect that.
Forgetting B2B data. Many founders focus on consumer-facing notices and forget that contact data collected for sales or partnership outreach is also personal data and needs to be covered.
One size fits all. If your product has multiple user types (for example, end users and business customers), each group may need their own notice.
A note on legal advice
This post is a practical guide to help you understand what a privacy notice should contain and how to approach writing one. It is not legal advice. If your startup processes sensitive categories of data, operates in a regulated sector, or serves users across multiple jurisdictions, you should consult a solicitor or specialist data protection adviser.
The ICO also publishes detailed guidance on privacy notices which is worth reading alongside this post.