A privacy notice review service should do more than proofread a policy. The useful task is to compare the notice against the organisation’s real processing activities, the information required by the UK GDPR, the way privacy information is delivered to people, and any changes in law or business practice. The result should identify omissions, contradictions and wording that is formally present but not transparent in practice.
What a UK privacy notice review should cover
The starting point is the UK GDPR right to be informed. The ICO states that individuals must receive clear information about how their personal data is collected and used, and that the information must be concise, transparent, intelligible, easily accessible and written in clear and plain language. A review therefore needs two tests: whether the required information is present, and whether a person can realistically understand what will happen to their data.
A reviewer should not assess the notice in isolation. Compare it with the website, forms, CRM fields, analytics and advertising tools, payment systems, customer-support records, recruitment processes, suppliers, processors and internal retention practices. If the notice says one thing but the operational systems do another, improving the prose alone does not resolve the transparency problem.
1. Map the processing before reviewing the wording
Build a short processing map for each important activity: what personal data is obtained, from whom or from what source, why it is used, the lawful basis relied on, who receives it, where it is stored or transferred, how long it is retained, and what rights may apply. This map becomes the control document against which the notice is checked.
Pay particular attention to processing introduced after the notice was last updated. New marketing software, AI-assisted features, fraud controls, call recording, location data, new payment providers or a new overseas processor can make an old notice inaccurate even if the wording still reads professionally. The ICO says privacy information should be regularly reviewed and updated, and new uses should be brought to people’s attention before the new processing starts.
2. Check the information required by Articles 13 and 14
The information required differs depending on whether personal data is collected directly from the individual or obtained from another source. The review should therefore distinguish those two routes instead of using one undifferentiated checklist. The ICO’s current guidance identifies core items including the organisation’s identity and contact details, the purposes of processing, the lawful basis, relevant legitimate interests, recipients or categories of recipients, international transfers, retention information, individual rights and the right to complain.
Where data comes from another source, the notice may also need to explain the categories of personal data and the source. Where data is collected directly, the notice may need to explain whether providing it is a statutory or contractual requirement and the possible consequences of not providing it. Automated decision-making and profiling require their own analysis where applicable.
3. Test purposes and lawful bases against reality
Generic purposes such as “business administration” or “improving services” may be too vague if they conceal materially different uses. Separate purposes where that helps a person understand why their data is used. For each purpose, verify the lawful basis actually relied on rather than listing every possible basis. If legitimate interests are used, the notice should identify the relevant interests where required and the underlying assessment should exist outside the notice.
Do not treat consent as a convenient default. If an activity is not genuinely based on consent, the notice should not describe it that way. Likewise, if special category data or criminal-offence data is processed, the compliance analysis extends beyond an ordinary Article 6 basis. The notice review should flag that issue for the underlying processing assessment rather than pretending that a wording change alone makes the processing lawful.
4. Review recipients, processors and international transfers
Compare the notice with current vendor and data-flow records. Identify material recipients and categories of recipients accurately enough for people to understand where their data may go. Check payment providers, hosting, email delivery, customer support, analytics, advertising, identity checks, professional advisers and group companies where relevant.
If personal data is transferred internationally, the notice should accurately describe the transfer information required for the organisation’s circumstances. The review should check current hosting and processor locations rather than copying an old statement that all data remains in the UK. If a supplier has changed its sub-processors or storage region, update the data-flow record first and then make the public notice consistent with it.
5. Make retention information specific enough to be useful
The ICO expects privacy information to explain retention periods or the criteria used to determine them. A notice that says data is kept “for as long as necessary” without explaining the operative criteria may tell a reader very little. Review the organisation’s actual retention schedule and connect the public explanation to identifiable categories of data or processing.
Check whether operational systems can in fact implement the periods described. If backups, customer accounts, support tickets or uploaded documents are retained under different rules, the notice should not imply one universal period. A good review records any mismatch between written retention language and technical deletion or archival behaviour.
6. Check rights, complaints and contact routes
The notice should explain the rights that are relevant to the processing and provide a workable way to exercise them. Test the stated contact route: does the email address work, does the request reach the right team, and can the organisation identify a privacy request when it arrives through an ordinary support channel? Include the right to complain to the ICO in the manner required by the current guidance.
If the organisation has a data protection officer or UK representative where applicable, check that the correct contact details are used. Remove obsolete addresses and named contacts that no longer perform the role. A privacy notice is an operational interface as well as a legal document; a right that cannot be exercised through the published route is a practical defect.
7. Review timing and the way the information is delivered
Publishing one privacy policy in a footer may not be enough for every collection point. The ICO states that where data is collected directly from an individual, privacy information should be provided at the time the data is obtained. Where data comes from another source, the timing rules differ and the ICO guidance describes a reasonable-period requirement with a one-month outer limit, subject to the applicable exceptions.
Review forms, account creation, checkout, recruitment, cookies and tracking, telephone collection and offline collection to see what a person is told at the relevant moment. Layered notices and just-in-time explanations can make complex processing easier to understand. The full notice and the short notice must remain consistent; a short form should not promise less processing than the full notice actually describes.
8. Check readability, layering and mobile presentation
Legal completeness does not excuse unreadable presentation. Test the notice on mobile as well as desktop. Headings should let a user find purposes, sharing, retention and rights without scanning a wall of text. Links should work. Important qualifications should not be hidden behind vague labels. If children or other audiences need different language, the review should address that audience specifically.
Look for contradictions created by years of incremental edits: one section may say data is never sold, another may describe advertising disclosures; one paragraph may promise deletion after a fixed period while another uses indefinite criteria. Search for duplicate definitions, inconsistent controller names, outdated company details and references to products that no longer exist.
9. Compare the notice with cookies, marketing and product flows
A privacy notice review should be coordinated with related transparency surfaces. Compare it with the cookie or tracking information, consent controls, marketing sign-up language, account settings and any product-specific privacy explanations. The goal is not to duplicate every document but to avoid contradictory statements about purposes, lawful bases, sharing or user choices.
For digital products, perform a simple journey test as a new user: open the site, submit a form, create an account, upload a document, make a payment or request support where those features exist. Record what information is shown at each step and compare it with the processing map. This often identifies gaps that are invisible in a desktop review of the privacy notice alone.
10. Account for the Data (Use and Access) Act changes
The ICO currently marks parts of its UK GDPR right-to-be-informed guidance as under review because of changes introduced by the Data (Use and Access) Act 2025. That makes “last reviewed” dates especially important in 2026. A review service should verify the current ICO guidance and the legislation in force on the review date rather than relying on a checklist saved before those changes.
This does not mean every privacy notice automatically needs wholesale rewriting. It means the reviewer should identify which provisions or processing activities are affected by current changes and document the source and review date. Where guidance is expressly under review, avoid presenting an old interpretation as permanently settled.
Privacy notice review checklist
- Confirm the correct controller identity, contact details, DPO and representative where applicable.
- Map purposes, data categories, sources and lawful bases against actual systems.
- Check direct collection against Article 13 information and indirect collection against Article 14 information.
- Verify recipients, processors, international transfers and current vendor arrangements.
- Compare stated retention periods with the operational retention schedule.
- Check individual rights, withdrawal routes where relevant and the ICO complaint information.
- Review profiling and automated decision-making statements where those activities exist.
- Test when privacy information appears at forms, checkout, accounts, recruitment and other collection points.
- Compare the notice with cookies, marketing, product copy and other privacy explanations.
- Record the legal/guidance sources and the date on which the notice was reviewed.
Official sources checked
This guide was checked against current ICO material on 26 September 2026. The ICO currently states that parts of its guidance are under review following the Data (Use and Access) Act, so a live review should verify the current position rather than rely on an archived checklist.
Review or prepare a UK privacy notice from your actual processing activities