If your organisation collects, stores or otherwise processes personal data, from customer names and email addresses to employee records, you are legally required to handle that data responsibly under the UK GDPR, Data Protection Act 2018, and the Data (Use and Access) Act (“DUAA”) 2025.
A data protection policy is the document that sets out how you do this. It is one of the key governance documents that the Information Commissioner's Office (ICO) (which is in the process of being restructured into the Information Commission under the DUAA 2025) or commercial clients may ask to see when assessing your compliance, and it is the foundation of good data governance.
This differs from a privacy notice, published externally for customers and visitors. A data protection policy is internal, guiding how staff handle personal data day to day.
Who Needs a Data Protection Policy?
Although UK GDPR does not expressly require every organisation to have a document called a "data protection policy", most businesses that process personal data should have one as part of meeting their accountability obligations, regardless of their size. It should be a living document, reviewed regularly rather than a one-off exercise.
The Core Elements
- Scope and purpose. Define which staff, systems and types of personal data the policy covers, clarify key terms used within the document, and confirm the organisation's commitment to compliance.
- The data protection principles. Your policy should reflect the seven principles under Article 5 of the UK GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability.
- Lawful bases for processing. Explain which of the lawful bases (consent, contract, legal obligation, vital interests, public task, or legitimate interests) your business relies on for its different categories of processing activities, and how these are recorded. The DUAA 2025 introduces Recognised Legitimate Interests as a new lawful ground for processing personal data. It operates much like legitimate interests, but it removes the need to carry out the balancing test. This ground is limited to specified purposes, so commercial activities, marketing and similar processing will generally still need a full legitimate interests assessment.
- Roles and responsibilities. Identify who is accountable for data protection internally, for example, a designated data protection lead, and a Data Protection Officer where required, and staff duties to follow the policy and report suspected breaches promptly.
- Policy governance and implementation. The policy should explain how it is applied in practice and monitored via training, review and oversight.
- Data subject rights. Set out how the business handles access, correction, erasure, restriction and portability requests, and objections to processing. The DUAA 2025 also requires an internal data protection complaints process, allowing individuals to raise concerns directly with the organisation before escalating them to the ICO. The policy will therefore need to cover how requests and complaints are verified, logged, tracked and resolved within applicable timescales. Organisation’s also need to cover their approach to automated decision-making, profiling and AI tools.
- Special Category Data. Where the organisation processes special category data (such as health, biometric or racial or ethnic origin data), the policy should explain the additional safeguards and Article 9 conditions relied upon.
- Security measures. Describe the technical and organisational security measures in place, including encryption, access controls, password management, multi-factor authentication, secure disposal procedures and staff device policies, to protect data from loss, misuse, or unauthorised access.
- Data breach procedures. Include a clear process for identifying, containing and assessing breach risk, notifying the ICO without undue delay (and within 72 hours where required) if a risk to the affected individuals is likely, and informing affected individuals if there's a high risk to their rights.
- Privacy by Design and risk assessments. Organisations should explain how data protection considerations are incorporated into new projects, systems and processes, and when a Data Protection Impact Assessment is required and how risks are assessed and mitigated.
- Third parties and international transfers. Cover how suppliers and processors are vetted and engaged under Article 28-compliant contracts, and explain the safeguards used for international transfers of data, including mechanisms such as the UK International Data Transfer Agreement or the International Data Transfer Addendum, and the DUAA’s updated requirements for assessing transfers.
- Direct marketing. The policy should also address compliance with consent, opt-out and objection-handling rules where marketing occurs.
- Training and review. Commit to regular staff training and periodic policy reviews, for example annually or sooner if the law changes or the organisation’s processing activities change.
- Retention and disposal. State how long data categories are kept, either within the policy or a linked retention schedule.
- Related documentation. The policy should sit alongside wider data protection documentation, including privacy notices, retention schedules, breach procedures, records of processing, data maps and DPIA processes, all helping to demonstrate accountability.
Recent Legal Changes You Should Reflect
The DUAA 2025 has now brought the bulk of its data protection provisions into force, with reforms rolling out in stages throughout 2026. Key changes to reflect include Recognised Legitimate Interests as a new lawful ground for processing certain personal data; the relaxation of restrictions to automated decision-making provisions, subject to appropriate safeguards; the new internal complaints procedure; and the transition from the ICO’s functions to the Information Commission. If your policy hasn't been reviewed recently, it may no longer reflect the latest legal requirements introduced by the DUAA 2025.
Common Mistakes to Avoid
Many businesses adopt a generic template that doesn't reflect their actual data practices, or fail to train staff on applying it. Others overlook the vetting of processors and safeguards used for international transfers, or never update the document once written. A policy should be tailored to your organisation's activities, systems, workforce and risk profile, as a generic template may cover the relevant legal principles, but is unlikely to address your real processing activities, contracts and operational risks.
Get It Right, First Time
An accurate, up-to-date data protection policy embedded in day-to-day operations is one of the most effective ways to demonstrate UK GDPR compliance, reduce legal risk, and build trust with customers, employees and partners.
Get in touch with our specialist data protection solicitors today for a policy review or a tailored drafting service.
Accurate at the time of writing. This information is provided for general information purposes only and should not be relied upon as legal advice.





.png)