Your policy should describe you

A copied privacy policy can look reassuring while describing a completely different business.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Practical explainer

Practical explainer; the linked ICO page flags that its guidance is under review.

What happened

The ICO’s privacy-information guidance explains the information people should receive, including the organisation’s identity, processing purposes, relevant lawful bases, recipients, retention and rights. Which details apply depends on the activity. The source is under review following UK reforms, so check its current version when preparing a notice.

Source: ICO — original source ↗

What it means for your website

Before editing your policy, map a few real journeys. What happens when someone sends an enquiry, creates an account or buys a service? Which inbox, database and payment provider receive information? How long is it kept? These questions produce better copy than borrowing a long policy from another website. Look for obvious mismatches such as old company names, unused tools and missing current suppliers. Put useful information close to the form as well as in the full notice. A scanner can find a policy link and some wording; it cannot establish that every statement matches what your business actually does.

Three useful next steps

  1. Map enquiry, account and payment information flows.
  2. Remove inaccurate names, tools and retention claims.
  3. Review the notice whenever the underlying service changes.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

ICO — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading