Practical explainer; the linked ICO page flags that its guidance is under review.
What happened
The ICO’s privacy-information guidance explains the information people should receive, including the organisation’s identity, processing purposes, relevant lawful bases, recipients, retention and rights. Which details apply depends on the activity. The source is under review following UK reforms, so check its current version when preparing a notice.
Source: ICO — original source ↗
What it means for your website
Before editing your policy, map a few real journeys. What happens when someone sends an enquiry, creates an account or buys a service? Which inbox, database and payment provider receive information? How long is it kept? These questions produce better copy than borrowing a long policy from another website. Look for obvious mismatches such as old company names, unused tools and missing current suppliers. Put useful information close to the form as well as in the full notice. A scanner can find a policy link and some wording; it cannot establish that every statement matches what your business actually does.
Three useful next steps
- Map enquiry, account and payment information flows.
- Remove inaccurate names, tools and retention claims.
- Review the notice whenever the underlying service changes.
Sources & context
Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.
ICO — original sourceOur practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.