Free policy template

Data protection policy

Use our data protection policy template to ensure your business complies with the GDPR and the Data Protection Act (DPA), safeguarding personal data.

What's inside

  • Compliant data handling
  • Manages customer information
  • Promotes transparency
  • Sets data standards

Word document. Drafted by Lawyerly's commercial solicitors. Last updated September 2026.

Download your free copy

Tell us who you are and the file is yours straight away.

What a data protection policy is, and what it is not

A data protection policy is an internal document. It tells the people in an organisation how they are expected to handle personal data, who to go to, and what to do when something goes wrong. It is not a privacy notice, which is the external document explaining to individuals what is done with their data and is required by Articles 13 and 14 of the UK GDPR. Organisations frequently publish one and believe they have the other. They are different documents with different readers, and an auditor will ask for both.

Why the internal one is worth having

Article 5(2) makes the controller responsible for compliance and, separately, for being able to demonstrate it. That is the accountability principle, and it is why the policy matters: it is the evidence that the organisation set expectations, alongside records of processing, training records and impact assessments. After a breach the Information Commissioner's Office looks at what was in place beforehand, and an organisation that can produce a policy, show its people were trained on it and point to a breach log is in a materially different position from one that cannot.

What the 2026 changes added

This template reflects the Data (Use and Access) Act 2025. Three things in it affect what a policy has to say. There is now a recognised legitimate interests basis, which removes the balancing test for certain defined purposes and therefore needs handling differently from ordinary legitimate interests. The subject access rules have been codified, including the position on a reasonable and proportionate search and on stopping the clock while identity or scope is clarified, in force since February 2026. And from 19 June 2026 organisations have had to run a complaints procedure for data protection complaints, acknowledge a complaint within 30 days and respond without undue delay. That is a process to build rather than a paragraph to add.

The obligations with deadlines attached

Two have hard timings and belong in the policy in terms staff can act on. A subject access request must be answered within one month of receipt, extendable by two further months where the request is complex, and the clock starts when the request arrives anywhere in the organisation, including a sales inbox or a social media account. A personal data breach likely to result in a risk to individuals must be reported to the Information Commissioner's Office within 72 hours of becoming aware of it, which in practice means people need to know to escalate the same day rather than investigate first.

Completing it from what is actually happening

Name the person responsible at clause 3, complete every contact in the table at clause 4, and make sure the retention schedule referred to at clause 18 exists rather than being referred to. The section asking what personal data the organisation holds should be filled in from reality, not intention. The exercise usually turns up processing nobody had recorded: a spreadsheet of candidates, a shared drive of old client files, a marketing tool holding contacts that were never consented to. That is the point of it, and it feeds the record of processing activities Article 30 requires.

Then give it to everyone on their first day, train them on it, and keep a record of who was trained and when. That record is part of what has to be shown to the regulator.

Most organisations need four documents together: this one, a privacy notice, a cookie policy where the website sets cookies, and a data processing agreement with every supplier handling personal data on their behalf. Our UK GDPR and data protection solicitors put the set together and review what is already in place.

Need more than a template?

Talk to a solicitor about your situation

A template gets you started. When the facts are yours, one of our commercial solicitors will tailor it, or tell you plainly that you need something else. The first conversation is free.

Willem van der Merwe

Co-Founder

Read profile