Privacy Notice
A privacy notice is a public-facing document that tells people how an organization collects, uses, shares, and stores their personal information. It also explains the rights individuals have over their data, such as the right to withdraw consent where consent is the basis for processing. It is the primary way an organization communicates its data-handling practices to the people whose information it holds.
A privacy notice is an external-facing disclosure intended to satisfy the information and transparency requirements under applicable data protection regimes. It describes an organization's practices for the collection, use, sharing, and storage of personal information and, where relevant, sets out the information rights of data subjects, including the right to withdraw consent where consent serves as the lawful basis for processing (as noted in UK ICO guidance). Required content varies by jurisdiction: EU/UK data protection law and US state privacy frameworks impose differing disclosure obligations, so the specific elements a notice must contain depend on the governing law and the categories of data and processing involved. A privacy notice is distinct from internal privacy or data protection policies that govern staff conduct, and it is a transparency instrument rather than a substitute for the underlying lawful basis, consent mechanism, or security controls. It is sometimes labeled a 'privacy policy' or 'data protection notice,' though terminology and legal requirements evolve; practitioners should verify content requirements against the current authoritative text for each relevant jurisdiction.
Why it matters
A privacy notice is the principal instrument through which an organization discloses its data-handling practices to the individuals whose personal information it processes. Transparency is a foundational expectation under data protection regimes: EU and UK data protection law, along with US state privacy frameworks, impose disclosure obligations on organizations, though the specific content each notice must contain varies by jurisdiction and by the categories of data and processing involved. A notice that is missing, inaccurate, or misleading can undermine the transparency an organization is expected to provide and may expose gaps between stated and actual practices.
The notice also functions as the channel through which individuals learn about the rights they hold over their data. As UK ICO guidance notes, a privacy notice should set out people's information rights, including the right to withdraw consent where consent serves as the lawful basis for processing. Where individuals cannot readily understand how their information is collected, used, shared, and stored, they are less able to exercise those rights meaningfully.
Because disclosure requirements differ across jurisdictions and evolve over time, a privacy notice is not a fixed, one-size-fits-all document. Practitioners should treat it as a living transparency instrument that must be verified against the current authoritative text for each governing law, rather than as a static form that satisfies obligations universally.
Who it's relevant to
Inside Privacy Notice
Common questions
Answers to the questions practitioners most commonly ask about Privacy Notice.

