GDPR Policy Template UK
GDPR & Data Protection Policy Template (UK)
Approx. 7 pages · 15 sectionsBranded PDF + editable WordLast reviewed:
What is a gdpr & data protection policy and who needs one?
A data protection policy is your internal rulebook for handling personal data lawfully under the UK GDPR and the Data Protection Act 2018: principles, lawful bases, rights requests, security, breaches and retention. Any organisation processing personal data benefits from one, and buyers ask for it whenever a contract touches staff, customer or citizen data.
Buyers need confidence that suppliers handle personal data lawfully. This template covers the data protection principles, roles, lawful bases, data subject rights, breaches, international transfers and retention.
Why buyers ask for this
UK GDPR requires buyers to use only suppliers who give sufficient guarantees about protecting personal data, so this policy is almost always requested when a contract involves handling personal information.
Who needs it
Any organisation that processes personal data, and particularly suppliers whose contract involves buyer or citizen data.
Where it comes up in a PQQ, SQ or PSQ
Under the Procurement Act 2023, supplier selection uses the Procurement Specific Questionnaire (PSQ) plus each buyer's own conditions of participation and quality questions. Typical questions this policy supports:
- "Provide your data protection / GDPR policy" in technical ability conditions of participation
- Questions on your ICO registration (data protection fee) and Data Protection Officer or lead
- "Have you had a personal data breach reported to the ICO in the last three years?"
- Processor due-diligence questions where you will handle personal data on the buyer's behalf
- – Almost always requested where the contract involves personal data
- – Supports responses on data processing and breach notification
What's inside
The full gdpr & data protection policy runs to about 7 pages (including the branded cover and document control page) across 15 sections:
- Purpose
- Scope
- Roles & Responsibilities
- Data Protection Principles
- Lawful Bases & Special Category Data
- Data We Process
- Individual Rights
- Data Security
- Use of Processors and Third Parties
- International Transfers
- Data Breaches
- Training & Awareness
- Records & Documentation
- Enforcement
- Review
Key points covered
- Scope and definitions
- The data protection principles (UK GDPR Art. 5)
- Lawful bases for processing
- Individuals' rights and how requests are handled
- Security measures
- Personal data breaches and ICO notification within 72 hours where required
- International transfers
- Retention, training and responsibilities
Every document carries your logo, company name, version number, approval signatory and next review date, in branded PDF plus editable Word.
UK legislation, standards and guidance it references
Excerpt preview
[Your Company Ltd] (“the Company”) is committed to protecting the privacy and security of personal data in accordance with: The aim of this Policy is to: This Policy applies to: Compliance with this Policy is mandatory.
Get your gdpr & data protection policy in minutes
£19.99 per policy, or £199 for all 39 policies. One-off payment.
Tender deadline this week? Download in 10 minutes.
How to adapt it
- Read every section and remove anything that doesn’t reflect how your organisation actually works.
- Complete the bracketed [ADAPT] prompts with your own arrangements, people and data.
- Have the policy approved and signed by a director or equivalent, and communicate it to staff.
- Keep evidence that you follow it, and review it by the date shown.
GDPR & Data Protection Policy FAQs
Is a data protection policy the same as a privacy notice?
No. A privacy notice tells individuals how you use their data. A data protection policy is an internal document setting out how your organisation complies.
Do I need to pay the ICO fee?
Most organisations that process personal data must pay the ICO data protection fee unless exempt. Check the ICO's self-assessment tool.
When must a personal data breach be reported to the ICO?
Under UK GDPR Article 33, a notifiable breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals.
How much does the GDPR & Data Protection Policy template cost?
£19.99 per policy, or £199 for all 39 policies. It is a one-off payment with no subscription, and you download branded PDF and editable Word files straight away.
Free guides
- Which policies do UK public-sector tenders ask for?
- Tender policy checklist for UK public-sector bids
- Documents needed for public sector tenders: a UK checklist
General information, not legal advice. Requirements differ between buyers and change over time; always check the tender documents.