GDPR Policy Generator UK
UK GDPR, the Data Protection Act 2018 and PECR - drafted for the ICO, not for a generic "GDPR" audience.
UK GDPR compliance is judged on the internal record, not the public notice. The ICO’s accountability framework asks for the lawful basis register, the Article 30 record, the DPIA log and the breach procedure - and asks to see them dated before the incident, not after.
Since Brexit the UK runs its own data protection regime. UK GDPR sits alongside the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR) govern cookies and marketing separately, and the Information Commissioner’s Office is the regulator you name in your policy - not the EDPB, and not "your local supervisory authority".
The Data (Use and Access) Act 2025 changed the enforcement arithmetic. PECR penalties, previously capped at £500,000, now run to UK GDPR levels - £17.5 million or 4% of global turnover. Cookie banners and marketing consent, historically the cheapest rules to ignore in the UK, became the most expensive.
A UK-facing policy also has to handle transfers in the opposite direction from an EU one. The UK issues its own adequacy decisions, uses the International Data Transfer Agreement or the Addendum to the EU SCCs rather than the SCCs alone, and has its own UK-US Data Bridge for certified American importers.
What a GDPR policy in the UK has to cover
A record of processing activities covering purposes, categories, recipients, transfers and retention
Legitimate interests assessments for every purpose relying on that basis
A DPIA screening process, with DPIAs completed for the ICO’s listed high-risk processing
A data subject rights procedure with identity verification and the one-month statutory clock
A breach procedure meeting the 72-hour ICO notification deadline, with the internal escalation path named
The UK regime is diverging from the EU’s. The Data (Use and Access) Act 2025 adjusted the rules on automated decision-making, research purposes and complaint-handling, so a compliance pack written purely against EU GDPR is now behind on UK-specific detail.
How the UK actually moves personal data
UK-resident customer and account records
Names, addresses, order history and support tickets held by a UK business are almost always processed under contract or legitimate interests - but the basis has to be stated per purpose, and marketing is a separate purpose with a separate basis.
Analytics and advertising identifiers
GA4, Meta and TikTok pixels and any server-side tagging all read or write to the device. Under PECR that needs consent before the tag fires, which is a stricter test than "we have a legitimate interest in analytics".
Payments through UK and EEA processors
Stripe, GoCardless, Worldpay and PayPal each act as independent controllers for fraud prevention, so the policy has to describe a hand-off, not just a sub-processor.
Transfers to US SaaS vendors
Most UK businesses send data to American hosting, email and support tools. Each destination needs a named mechanism: the UK-US Data Bridge for certified importers, otherwise the IDTA or the UK Addendum plus a transfer risk assessment.
Employee and applicant data
The ICO’s employment practices guidance treats recruitment records, monitoring and reference checks as high-scrutiny processing, and expects a separate privacy notice for staff rather than a line in the customer policy.
Cookie consent records
PECR compliance is proved by the consent log - timestamp, version of the banner, and the categories accepted. Without it, an ICO complaint is your word against the complainant’s.
Third parties the draft will ask you about
Stripe · GoCardless · Worldpay · Royal Mail and DPD · Google Analytics 4 · Mailchimp · HubSpot · AWS eu-west-2 (London) · Microsoft 365 · Xero
The rules that apply
UK GDPR + Data Protection Act 2018
The transparency duties in Articles 13 and 14, the lawful basis requirement in Article 6, and the DPA 2018 schedules that carry the UK-specific conditions for criminal-offence and special-category data.
PECR (as amended by the Data (Use and Access) Act 2025)
Consent before any non-essential storage or access on a device, and opt-in for electronic marketing outside the narrow soft opt-in. Penalties now match UK GDPR levels.
The ICO
Your named supervisory authority. Users must be told they can complain to the ICO, and the ICO expects a working contact route for you before that escalation.
Consumer Rights Act 2015 + Consumer Contracts Regulations 2013
Fourteen-day cancellation on distance sales, statutory quality rights that no policy can exclude, and the unfair-terms test that voids overreaching liability caps.
Online Safety Act 2023
If users can post or message each other, Ofcom-regulated duties on illegal content and children’s access apply, and your published rules and reporting route are part of the compliance record.
What the generated GDPR policy contains
Article 13 and 14 transparency notice
The full disclosure set, split by whether the data came from the person or from somewhere else.
Lawful basis register
Every processing activity mapped to one of the six bases, with the legitimate interests assessment written down where you rely on that basis.
Records of processing (Article 30)
The internal register a supervisory authority can ask for at any time, covering purposes, categories, recipients, transfers and retention.
Data subject rights procedure
How a request arrives, how identity is verified, who handles it, and the one-month clock with its two-month extension.
International transfer mechanism
Adequacy, SCCs with a transfer impact assessment, or the UK IDTA/addendum - named per destination, not asserted in general.
Breach detection and 72-hour notification
The internal escalation path, the assessment test, and the template for notifying the regulator and, where required, the individuals.
Processor and sub-processor controls
Article 28 terms, the sub-processor list, and the change-notification commitment your customers will ask for.
Making a UK policy operational
Check whether you need to pay the ICO data protection fee
Most UK controllers must register and pay an annual fee of £52, £78 or £2,900 depending on size and turnover. It is a separate legal duty from publishing a policy and is enforced independently.
Decide whether you need an EU representative
If you also target EU customers, Article 27 of the EU GDPR may require an EU-based representative even though you are UK-established. Name them in the policy if so.
Record your lawful basis before you publish
The ICO expects the decision to predate the notice. Keep the legitimate interests assessment for each LI-based purpose on file.
Run a cookie scan and reconcile it against the banner
Compare what actually fires before consent against what the banner claims. Any tag firing pre-consent is the finding an ICO complaint will start from.
Set the breach clock
Seventy-two hours to the ICO from awareness, and without undue delay to individuals where the risk is high. The escalation path has to exist before the incident.
Where this usually goes wrong
Naming the EDPB or "the supervisory authority" instead of the ICO
A UK policy that never names the ICO reads as a copied EU document. It also fails the practical test of Article 13(2)(d): the person has to know where to complain.
Treating the EU SCCs as sufficient for UK transfers
The EU clauses alone do not cover a UK export. You need the UK Addendum bolted on, or the standalone IDTA. This is the single most common defect in UK policies copied from EU templates.
Relying on legitimate interests for analytics cookies
PECR requires consent for storage and access regardless of the GDPR basis for the processing that follows. The ICO wrote to the UK’s largest websites about exactly this pattern.
A cookie banner with no equally prominent reject
The ICO’s published position is that accept and reject must take the same number of clicks. A banner with "Accept all" and a buried "Manage settings" is the version that draws the letter.
Missing the soft opt-in conditions for email marketing
The B2C soft opt-in only applies to your own similar products, sold to someone who bought from you, with an opt-out offered at collection and in every message. Businesses routinely claim it for purchased lists, where it does not apply.
Frequently asked questions
Does UK GDPR still apply after Brexit?
Yes. UK GDPR was retained in domestic law and then amended by the Data Protection Act 2018 and the Data (Use and Access) Act 2025. It is a live UK statute enforced by the ICO, not a transitional arrangement.
Do I need both UK and EU GDPR compliance?
If you have customers in both, yes. They are separate laws with separate regulators. In practice one policy can serve both provided it names both regimes, both regulators and the correct transfer mechanism in each direction.
Do I have to register with the ICO?
Most organisations processing personal data by automated means must pay the annual data protection fee unless an exemption applies. Publishing a policy does not discharge that duty.
How much can the ICO fine a small business?
Up to £17.5 million or 4% of global annual turnover under UK GDPR, and since the Data (Use and Access) Act 2025 the same ceiling applies to PECR breaches such as cookie and marketing failures. In practice the ICO’s small-business enforcement is dominated by nuisance-marketing penalties in the tens of thousands.
Is a UK privacy policy different from an EU one?
Structurally no, substantively yes in three places: the regulator named, the transfer mechanism used, and the cookie rules cited - PECR rather than the ePrivacy Directive as implemented locally.
Does GDPR apply to a business outside the EU?
Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about where the person is, not where you are - and Article 27 may also require you to appoint an EU representative.
What is the difference between EU GDPR and UK GDPR?
The text is nearly identical, but they are separate laws with separate regulators, separate fine ceilings in different currencies, and separate transfer regimes. A business serving both needs both named, not "GDPR" as shorthand.
Do I need a Data Protection Officer?
Only where your core activities involve large-scale regular monitoring or large-scale special-category data, or you are a public authority. Many businesses do not need one - but if you do not have one, say who is accountable instead.
Is a GDPR policy the same as a privacy policy?
No. The privacy policy is the outward-facing notice. The GDPR policy set is the internal machinery - lawful basis register, ROPA, rights procedure, breach plan - that lets you answer a regulator when they ask how the notice is honoured.
GDPR Policy Generator UK
Answer a short questionnaire and get a draft written for the UK. Free to start, no card required.
Generate your GDPR policyOther documents for the UK
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.