Privacy notice
Also known as: collection notice, data protection notice, data-use notice, fair-processing notice, privacy policy, privacy statement
A privacy notice explains how an organisation uses personal data. It should tell the relevant audience who is responsible, what information is used, why it is needed, where it comes from, who receives it, how long it is kept, what choices or rights people have and how to ask questions. Legal content varies by jurisdiction.
Term explanation
At a glance
A privacy notice is an explanation for the people whose information an organisation uses. Its purpose is transparency: helping someone understand what will happen to their data and make informed choices or exercise rights.
“Privacy notice” and “privacy policy” are often used interchangeably in public-facing contexts, although an internal privacy policy may instead describe staff rules and governance. A good public notice is written for its audience, not copied from an internal compliance manual.
In plain language
A notice should identify the responsible organisation and provide a contact route. It should explain the categories of personal data involved, the purposes, relevant legal conditions, sources, recipients, overseas access, retention approach, individual rights or choices, complaint routes and any significant automated decision-making where applicable.
The exact mandatory items and wording depend on the jurisdiction and whether information is collected directly from the person or obtained elsewhere. The Hub’s jurisdiction lens should therefore change the legal-requirements panel without rewriting the basic explanation.
Why it matters
People should receive the information at a time and place that makes it useful. A notice hidden in a footer after collection may not provide meaningful transparency. Layered notices can work well: show essential information near the form or decision, with a link to fuller detail.
Different audiences may need different notices or layers. Employees, website visitors, app users, patients and children do not all need the same explanation. Accessibility, language, device size and reading level matter.
A practical example
An event form asks for a name and email to issue a ticket. Beside the fields, a short layer explains the purpose, identifies the organiser and links to a full notice. A separate optional choice covers marketing. The full notice explains the ticketing provider, retention and rights.
General principles
What a privacy notice is not
A notice is not permission for every future use. Publishing broad wording does not remove the need for a proper purpose, legal condition, minimisation, security or respect for rights. Nor should a notice promise practices that the organisation does not follow.
Avoid absolute claims such as “we never share data” if processors, professional advisers or regulators receive it. Explain the real arrangement accurately. A clear notice can be concise, but it should not achieve brevity by hiding material information.
Maintain notices as governed content
Treat each notice as a versioned product with an owner, audience, effective date and evidence of approval. Link notice sections to the underlying processing record so supplier, purpose or retention changes prompt review. Keep a change summary for material updates and decide how affected people should be informed.
Practical next steps
Compare each notice with the organisation’s actual data map. Confirm purposes, systems, suppliers, countries, retention and contact routes with operational owners. Test links and forms. Set an owner and review date, and update the notice when processing materially changes. Keep previous versions.
Related terms: transparency; controller; personal data; lawful basis; consent; retention; data-subject rights
Jurisdiction guidance
Select more lenses from the Hub landing page to compare across jurisdictions.
No jurisdiction-specific guidance is published for this lens yet.
Related terms
- Data controller — controller
- Personal data and personal information — personal data
Sources & citations
Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.
- ACT — Cyber and Data Protection Act (Chapter 12 07) (ACT)
ACT · primary · Read in the Legal Library
- CDPG 1 of 2025 — Compliance Assessments (CDPG-1-2025-CA)
CDPG-1-2025-CA · cites · Read in the Legal Library
- CDPG 4 of 2024 — The Right to Consent (CDPG-4-2024)
CDPG-4-2024 · cites · Read in the Legal Library
Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.