Privacy policies non-compliant on a large scale: what hope when it comes to GDPR?

Just about every organisation publishes a privacy policy on its website. A privacy policy is a statement to the outside world about how an organisation will handle personal data collected through its website.

In October, the Information Commissioner’s Office (ICO) (the body responsible for data protection enforcement in the UK) published the results of a review into privacy policies. The ICO reviewed 30 UK websites in the retail, banking and lending, and travel and finance price comparison sectors and found that most privacy policies did not comply with the current Data Protection Act 1998. The problems with the websites reviewed included:

• 26 failed to specify how and where personal data would be stored;
• details about the cross- border transfer of personal data was found to be often too vague;
• 26 organisations failed to explain adequately whether they share personal data and, if so, who it would be shared with; and
• 24 organisations failed to inform users how they could delete or remove their personal data from the website.
• 24 organisations failed to inform users how they could delete or remove their personal data from the website.


So, if organisations with websites cannot comply with the current legislation, what hope is there that their privacy policies will comply with the new GDPR (or General Data Protection Regulation) which comes into effect on 25 May 2018?

It must be remembered that when the Data Protection 1998 became law, the on-line world was very much in its infancy and so it was not designed for that purpose. Indeed, Facebook was not launched until 2004 and YouTube not until 2005. The GDPR, however, is intended to very much relate to the world today. Helpfully, most of what a privacy policy must contain is set out in Article 13 of GDPR. This, therefore, makes it easier for an organisation to check everything is covered.

On the other hand, as the research appears to show, few websites currently comply with the existing legislation so they will certainly not comply with GDPR. Accordingly, many privacy policies will need to be amended.

For most organisations, its website is very much its public face. As we have already mentioned, its privacy policy is very much its public statement as to how its is going to handle personal data and, in many ways, its public statement to demonstrate its compliance (or indeed non-compliance) with GDPR. It is, therefore, vital for data protection purposes that organisations get their privacy policies correct. These are not standard documents as is often thought. They cannot be because the way in which organisations handle personal varies from organisation to organisation.

If you would like help with drafting your privacy policy or help generally with GDPR compliance, please contact Simon Bates or Helen Wright.

Victoria McMeel
Posts: 2
Stars: 0
Date: 08/05/18
Deborah Sutton
Posts: 1
Stars: 0
Date: 27/04/18
Guest Blogger
Posts: 14
Stars: 0
Date: 11/04/18
Dana Ewans
Posts: 24
Stars: 0
Date: 05/04/18
Carmen Stevens
Posts: 2
Stars: 0
Date: 28/03/18
Krystyna Ferguson
Posts: 4
Stars: 0
Date: 06/03/18
Stacey Edwards
Posts: 3
Stars: 0
Date: 26/02/18

Events & seminars

Browse our programme of training, seminars and special events.

Find out more

"Having the opportunity to tap into Jordans compliance and legal services when required is an added benefit to us and our clients"

Nimesh Pau, R Pau and Co


Keep informed with our free online newsletters and email updates.

Find out more