UK GDPR-compliant privacy notice for guests and customers, covering bookings, orders, CCTV, guest Wi-Fi, and loyalty programmes — required under Articles 13/14 UK GDPR and the Data Protection Act 2018 for essentially any business processing personal data.
⚠️ This is a blank template, not legal advice: check the wording with a lawyer and adapt it to your jurisdiction and your case.
CUSTOMER PRIVACY NOTICE
Business name (data controller) (Business address) Effective date: Effective date
This notice explains how Business name (data controller) (the "Company", the data controller) collects, uses, and protects your personal data, in accordance with the UK GDPR and the Data Protection Act 2018.
1. DATA CONTROLLER 1.1. Business name (data controller) is the data controller. Our ICO registration number is ICO registration number.
2. WHAT DATA WE COLLECT AND WHY 2.1. What data we collect and why CCTV: the premises are monitored by CCTV to prevent and detect crime and to protect the safety of staff and customers, on the basis of our legitimate interests. Signs are displayed at the entrance and in monitored areas. Footage is kept only as long as needed for that purpose (normally no more than 31 days) and is disclosed to the police or other authorities only where we are lawfully required or permitted to do so. Cookies: our website uses cookies and similar technologies. Cookies that are strictly necessary for the site to work are set automatically; analytics and advertising cookies are set only with your consent, which you may change or withdraw at any time through the cookie settings, in line with PECR.
3. LEGAL BASIS FOR PROCESSING 3.1. Purposes & legal basis (UK GDPR Art. 6)
4. SHARING AND INTERNATIONAL TRANSFERS 4.1. Third parties & international transfers
5. RETENTION 5.1. Retention period
6. YOUR RIGHTS 6.1. Your rights 6.2. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been mishandled. 6.3. Direct marketing: we send marketing messages only where you have consented or, for existing customers, on the "soft opt-in" basis permitted by PECR for our own similar goods and services. Every message includes a simple way to unsubscribe, and you may object to direct marketing at any time at no cost.
7. CONTACT US 7.1. Questions about this notice, or requests to exercise your rights, may be sent to Privacy contact email.
⚠️ Almost every business processing personal data must pay the ICO's annual data protection fee (currently £52/year for most small businesses); non-payment can lead to a fine. CCTV is a near-automatic trigger for this obligation.
— — — ⚠️ This is a boilerplate template, not legal advice. Employment, consumer-protection, food safety, and health & safety law in the United Kingdom differs between England, Wales, Scotland, and Northern Ireland, and is changing significantly through 2026–2027 under the Employment Rights Act 2025 — have this document reviewed and adapted by a solicitor (and, for disciplinary/grievance matters, checked against the current Acas Code of Practice at acas.org.uk) before use.
Fields that belong to a switched-off clause are dimmed — they are not asked for.
Your entry on the ICO data protection register (ico.org.uk)
e.g. bookings, orders, CCTV footage, guest Wi-Fi logs, loyalty programme, marketing preferences
e.g. contract performance, legitimate interests, consent — for each purpose stated above
Payment processors, booking platforms, and any transfer of data outside the UK
Access, rectification, erasure, restriction, objection, portability, and the right to complain to the ICO
2 of 10 fields are taken from the company, employee or counterparty record, the questionnaire can be dictated to the AI, and the finished document comes with a number, a PDF and an acknowledgement record.