Menu
Menu
Data Protection Part 3 – Writing a Privacy Notice
Transcript
This is part three of a series produced by Support Cambridgeshire on Data Protection. In this video, we are looking at writing your privacy notice.
Let’s see what we’re going to cover.
We will start by looking at why you need a privacy notice. Then consider where to start. Next, we’ll look at the very important content of a privacy notice. Lastly, we’ll look at making your privacy notice available to people.
Why do you need a privacy notice
So why is it needed? A privacy notice is a statement that tells someone how and why you will be using their personal data.
Essentially, it’s a tool to help you comply with the transparency obligations of the UK General Data Protection Regulation, commonly known as the UK GDPR.
Because of this law, individuals have a right to be informed, and to comply, you must provide privacy information that tells individuals about your data processing in a way that is easily accessible and easy to understand.
Where do you start?
To provide individuals with privacy information, begin by checking your data audit. If you don’t have a data audit, then carry one out to find out about your processing activities.
This means looking at each data processing operation in your organisation and deciding what you are processing, why you’re doing it, where and when, the lawful reason that allows your processing to go ahead and who the data is shared with, how it is stored, and so on.
By doing the data audit, you will have all the information you need to get started on a privacy notice.
What about the content?
Exactly what should go into a privacy notice is set out by the Information Commissioner’s Office.
This is the UK regulator responsible for data protection.
Your privacy notice should include the following: what personal data you use such as name, address, telephone number, and email addresses; why you use it, in other words, what you need it for; how you use it; who, if anyone, it is shared with, such as another organisation or agency; How long you will keep it.
It should also provide the lawful basis for your processing, for example, this might be consent; the name and contact details of your organisation; the rights of individuals, and how to complain.
There may also be some other things that should be included, but only if they apply to your processing.
These are, if not obtained from the individual, then the source of someone’s personal data; your legitimate interests for the processing.
This only applies if you rely on legitimate interest as a lawful basis. The right to withdraw consent. Again, this only applies if consent is your lawful basis for processing.
Making your privacy notice available
But how should you go about providing privacy information? How and when do you make your privacy notice available?
Firstly, it must be provided at the time personal data is collected. This means it can be provided in person, or if a link is given, then to a website.
But remember, putting your privacy notice on a website is only going to reach those people who look at that particular website.
It must also be in a concise, accessible format using plain language, so keep it short and jargon-free.
Remember also that you don’t have to overwhelm someone with privacy information, so you can make it available in layers or parts to suit your audience.
You can also use handouts, clearly visible footnotes, dashboards, icons, and banners as needed.
Summary
A privacy notice is essential to meet your transparency obligations and should provide information about how and why you process someone’s data. There are certain pieces of information that you are required to provide, and they must be given at the time that personal data is collected. Finally, it must be clear, accessible, and free of jargon.
For further information, please refer to the Information Commissioner’s website. This includes, under the section on “advice for small organisations”, a privacy notice generator tool.
And a sample of a privacy notice generated by this tool is also available from Support Cambridgeshire.
Finally, there is a transcript that accompanies this video with links to additional information on key data protection terms, who needs to register with the Information Commissioner’s Office, dealing with freedom of information and subject access requests, and the soft opt-in for email marketing newsletters.
Guidance Links:
Key Data Protection Terms
Data protection fee self assessment
Freedom of Information
Subject Access Requests
The soft “opt-in”
Guidance on direct marketing
Privacy notice generator tool
Writing a data protection policy and procedures
AI and data protection