Blog

Privacy Notice – Part 2

Writing a privacy notice

Once you’ve identified and pulled together all the information that you need to put into your privacy notice, and please do invest quality time doing this stage of the work, you need to then put pen to paper to write the privacy notice.  Now, this can be easier said than done when you’ve never actually written a privacy notice before!  I’ve written many privacy notices for businesses over the last few years and it is now second nature to me to write them.  However, if I’m being honest, writing the first couple did take me more time until I got into a style for writing them.  It is therefore easy to understand why it can be a daunting task for businesses to write their own privacy notice, when it is likely to be the only one they will typically do (albeit they will need to keep their privacy notice up to date going forward).

So you’ve pulled together all the information you need for your privacy notice to be GDPR compliant, and do refer back to our first blog in our privacy notice series for the full list of what you need to include (http://staging.dunwelldataprotection.co.uk/privacy-notice-part-1/).  The next question is can you just drop all this into a document, call it a privacy notice and issue to individuals?  Well, no not really.  You will no doubt have pulled together a lot of information as you now have an awful lot to tell an individual about what you do with their personal data and how you intend to use it. So just dropping this into a document will create one very long document that is difficult to navigate through and this is not the answer nor is it compliant with GDPR.

What does GDPR tell me about writing a privacy notice?

This is where it can get frustrating for a business writing their privacy notice, because GDPR specifically sets out that a privacy notice must be written in a concise, transparent, intelligible, easily accessible form, using clear and plain language.  WHAT! I hear you cry.  How can you turn your lengthy document of everything you have to tell an individual into something that is simple and easy to understand and importantly something that will be read?  To help understand what each of these requirements mean we’ll have a little look at what the Information Commissioner’s Office (ICO) advises you can do to comply with these requirements.

Concise – the good news is, there are ways of writing and presenting your privacy notice so that you can provide all the information you must do and for it to be concise.

  • Use an appropriate technique to deliver the information, such as a layered approach.
  • Use headings to separate the information into easily digestible chunks, each dealing with a different aspect of what you do with personal data.
  • Keep your sentences and paragraphs short.
  • Omit any irrelevant or unnecessary information.

Transparent – this means being open, honest and truthful with people about what you do with their personal data and giving them all the information they are required to have, so that they can make an informed choice as to whether to give you their personal data or not. 

  • Don’t offer individuals choices that are counter-intuitive or misleading.
  • Don’t hide information from people.
  • Make sure you clearly bring to people’s attention any uses of data that may be unexpected, or could have significant effects on them.
  • Align your privacy information with your organisation’s values and principles. People will be more inclined to read it, understand it, and trust your handling of their personal data.

Intelligible – your privacy notice needs to be understood by the people whose personal data you’re collecting and it should be user friendly.

  • Adopt a simple style that your audience will find easy to understand.
  • Don’t assume that everyone reading the information has the same level of understanding as you.
  • Explain complex matters in basic terms.
  • Ensure that what you say is unambiguous.
  • Be as precise as you can about what you do with people’s data.

Easily accessible – it should be easy for individuals to find and access your privacy notice.  Don’t make it difficult for someone to find, the risk is you could lose them as a customer/client.

  • Adapt how you provide your privacy information to the context in which you collect or obtain people’s data.
  • If you provide individuals with a link, ensure that you direct them straight to the relevant privacy information and do not have to seek it out amongst other information.
  • Make the information consistently easy to access across multiple platforms.

Clear and plain language – this means the words and phrases you use are straightforward and familiar for your intended audience.

  • Use common, everyday language.
  • Avoid confusing terminology, jargon, or legalistic language.
  • Align to your house style.
  • Use expertise (in-house or externally sourced) to help your privacy information fit with the style and approach your customers expect.

So as you can see there is more to writing a privacy notice and getting it right so it complies with GDPR. 

Unfortunately, there are still lots and lots of privacy notices published on websites that are wrong (yes, even though it is over 2 years ago since GDPR became applicable law).  Many don’t include all the information that they must include, and some you can’t even find anywhere.  Some still refer to out of date legislation and want to charge you a fee for making a subject access request! 

However, there are also good privacy notices published too, therefore proving it can be done to write a privacy notice that gives the individual all the information they need and is written in a way that is concise, transparent, intelligible, easily accessible form, using clear and plain language.

Our privacy notice feature will continue as we look at some of the different ways you can provide your privacy notice to individuals.