Skip to content
PeekWellThe Rulebook
Join now

Privacy notice requirements: findable under UK GDPR

At a glance

UK-10HighUK GDPR Arts. 12(1) and 13; penalties in Art. 83(5)(b) and DPA 2018 s. 157

Peeky looks for a privacy notice that exists, opens, matches the language of the site and can be reached in two clicks or fewer from any page.

Last checked against the source:

I need to fix thisI need the rule

The rule

Article 12(1) of the UK GDPR says the controller “shall take appropriate measures to provide any information referred to in Articles 13 and 14 and any communication made under or by virtue of Articles 15 to 22D and 34 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child.”

Article 13(1) sets what must be provided when personal data is collected from the person it concerns: the identity and contact details of the controller, the contact details of the data protection officer where there is one, and the purposes of the processing together with its legal basis. The rest of paragraph 1 and paragraph 2 cover recipients, transfers, retention, the person’s rights and the right to complain. Article 13 requires this “at the time when personal data are obtained”.

Two things about the text are worth knowing. First, the Data (Use and Access) Act 2025 has changed it: the legislation.gov.uk versions of Articles 12 and 13 show amendments that took effect on 5 February 2026, and Article 13 shows further changes on 19 June and 30 September 2026, mainly about complaints and the name of the regulator. A policy drafted before those dates may need its complaints paragraph looked at again. Second, the UK GDPR does not use the words “privacy policy” or say where a notice goes on a website. This check is about whether the information can be found, and leaves its content to UK-07.

The ICO’s guidance is the closest thing to a rule for websites. It says the UK GDPR requires you to “provide” the information in an “easily accessible form”. Putting it on a website is accepted (“this is often how organisations deliver privacy information”), but “you must proactively make individuals aware of this information and you need to give them an easy way to access it. Simply putting it on your website, in case people happen to look there, is not enough.” The ICO adds a notice at the top of the page: because of the Data (Use and Access) Act, the guidance is under review and may change.

The ICO’s advice for small organisations is more concrete. A company that holds personal data, “which is generally any small business, charity or group that has information about people such as their names and email addresses”, needs a privacy notice, and needs one on its website “if that’s mainly how your clients and customers find you”. Its example is a cake maker whose notice link is “immediately visible on the contact form page”.

Penalties follow the rights provisions. Article 83(5)(b) of the UK GDPR places “the data subjects’ rights pursuant to Articles 12 to 21” in the upper tier, a list the legislation.gov.uk text shows extended on 5 February 2026 for the Act’s automated decision-making provisions. Section 157 of the Data Protection Act 2018 sets the higher maximum at 17.5 million pounds or 4% of worldwide annual turnover for an undertaking, whichever is higher, against 8.7 million pounds or 2% for the standard maximum.

The one ICO penalty found for this article that turns in part on whether people were given clear information is TikTok, covered below, and it concerns clarity more than reachability. The Italian and French decisions in EU-09 show how the same wording has been applied to missing and scattered notices elsewhere, though they do not bind the UK.

What PeekWell checks and how

UK-10 asks one question: can a visitor reach a privacy notice from any page without hunting? The scan answers it from the pages it opened, not from what the site says about itself.

The method is the same as EU-09, which describes it in full. The scan crawls the footer and navigation of the public pages it visits, collects links that look like a privacy policy, follows them to confirm they open, counts the clicks from each page and compares the language of the policy with the site’s main language. It flags a missing link, a link that does not open, a policy in another language and a policy more than two clicks away. Two clicks is the scan’s working measure. Neither the UK GDPR nor the ICO sets a number.

The decision is made by code. A link, a status, a click count and a language are all matters of record, and a language model plays no part.

The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. It checks that a notice can be found and opens, and does not judge whether it is complete or accurate; that is UK-07 and UK-06. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.

Why it matters for a company

A missing or hidden notice is easy for a regulator to see, because it can be checked from a browser. The ICO’s guidance makes the standard plain: being on the website is not enough if people are unlikely to notice it, and the information is due when the details are collected.

The TikTok decision shows what happens when information exists but is not clear. The ICO’s own summary says the company “failed to provide users with clear information about how their data was being collected, used and shared meaning users (especially children) were unlikely to be able to make informed decisions.” That sat alongside findings about children’s data and age checks, so the 12.7 million pound penalty is not for transparency alone, and the page does not say which articles each finding rested on. TikTok appealed and then withdrew, which makes the 2023 notice final.

For a company the practical consequences are of three kinds. The information is due at the time of collection, so a notice added later does not cover the period before. A complaint about something else can lead a regulator to look at the website as a whole. And with the Data (Use and Access) Act in force, the text and the ICO’s guidance are both moving, so an old notice is more likely to be out of step.

Smaller companies and larger companies

The rule has no size threshold, and the ICO’s small-organisation pages are written for sole traders as much as for groups. What differs is how the gap appears.

In a small company the site is usually a template or a hosted builder. The notice was produced once, perhaps with the ICO’s own generator, and linked from the home page footer. Then the site changes: a campaign landing page, a booking form added by a freelancer, a shop plug-in with its own checkout. Each collects names and emails, and none links the notice. Nobody’s job is to check. The ICO’s advice asks for a link on the contact form page itself, which is an easy step to miss.

In a larger company the pieces multiply: brands, regional sites, microsites, apps and sign-up flows built by different teams. A group notice may be long and general, with key points far down the page, which is where the TikTok finding about clarity becomes relevant. Scale also changes the stakes, since the higher maximum is tied to turnover.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

  • TikTok Information Technologies UK Limited and TikTok Inc

    ICO (United Kingdom), 2023£12.7 million

    The ICO found that TikTok failed to provide users with clear information about how their data was being collected, used and shared, so users, especially children, were unlikely to be able to make informed decisions. The same penalty notice covered children's data and age checks. TikTok dropped its appeal, and the ICO announced on 24 September 2026 that the penalty notice is final.

    Read the ICO (United Kingdom) publication about TikTok Information Technologies UK Limited and TikTok Inc

Smaller companies

No ICO decision against a smaller company that turns mainly on a missing or hard-to-reach privacy notice could be confirmed at the ICO's own site, so none is listed.

How to fix it

The ICO’s advice is to make the notice “freely available and easy to access” and to make sure people know where to find it, whether it is “in a poster, a web page or a pop-up”. These steps put that in place on most sites and site builders.

  1. List every public page type and form. Home, product pages, blog, booking and checkout, landing pages and any microsite. Anything with its own template needs its own check.
  2. Put one link in the shared footer. Add a link labelled “Privacy notice” or “Privacy policy” to the footer template so every page type inherits it. Keep it at normal size and contrast, and do not hide it in a menu that opens only on small screens.
  3. Add a link beside every form. Next to each contact form, newsletter box or booking form, add a short line with a link to the notice, so people see it before they start typing. That is the ICO’s own example.
  4. Match the language. If a page is in Welsh, French or Polish, link a notice in that language. Where you run several language versions, give each a link to the right one.
  5. Check that the link opens. Open it in a private window, on a phone and on a computer. A notice that returns an error, redirects to the home page or needs a sign-in does not count.
  6. Review the complaints paragraph. The amendments from 19 June and 30 September 2026 touch the complaints wording in Article 13. Ask whoever maintains the notice to check it against the current text.
  7. Re-scan. Run a scan again. The finding should disappear once each page type shows a working link within two clicks, in the site’s language.
<footer>
  <a href="/privacy/">Privacy notice</a>
</footer>

What goes inside the notice is a separate question, and UK-07 covers the Article 13 list. Whether a setup meets the ICO’s view is for your legal adviser, and Peeky reports only what it sees.

Questions

Does a UK website need a privacy policy?

If the business holds personal data, yes. The ICO's advice for small organisations says any company holding things like names and email addresses needs a privacy notice, and that it needs one on its website if that is mainly how customers find it. A contact form or a newsletter sign-up is enough to bring a site in.

What is the difference between a privacy notice and a privacy policy?

None that matters for the rule. The UK GDPR talks about the information in Articles 13 and 14, and the ICO calls it privacy information or a privacy notice. Websites usually label the page Privacy policy or Privacy notice, and either name is fine so long as visitors can find it.

Where should the privacy notice go on a website?

Somewhere people will see it before they hand over their details. The ICO says putting it on the website is acceptable, but you must proactively make people aware of it, and simply putting it there in case people happen to look is not enough. Its own example for a small business links the notice on the contact form page itself.

What does Article 13 of the UK GDPR require?

Who you are, why you use the data and on what legal basis, who receives it and, in paragraph 2, how long you keep it and what rights people have. It must be given when the data is collected. The rule has the wording, including the amendments the Data (Use and Access) Act has made.

How does Peeky check for a missing privacy notice?

Peeky reads the footer and navigation of the public pages it visits, follows the policy link, counts the clicks from each page and compares the language of the policy with the site's. It never signs in or fills in a form. How a scan works has the full path.

Filed with

The rule

UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law), Arts. 12(1), 13 and 83(5)(b)

Read the rule (UK GDPR (Regulation (EU) 2016/679 as it forms part of UK law), Arts. 12(1), 13 and 83(5)(b))

A case

TikTok Information Technologies UK Limited and TikTok Inc

ICO (United Kingdom), 2023

Read the decision (TikTok Information Technologies UK Limited and TikTok Inc)

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. UK GDPR, Article 12 (legislation.gov.uk, revised version showing Data (Use and Access) Act 2025 amendments from 5 February 2026)
  2. UK GDPR, Article 13 (legislation.gov.uk, revised version showing amendments from 5 February, 19 June and 30 September 2026)
  3. UK GDPR, Article 83 (legislation.gov.uk)
  4. Data Protection Act 2018, section 157: maximum amount of penalty (legislation.gov.uk)
  5. ICO, When should we provide privacy information? (guidance under review after the Data (Use and Access) Act)
  6. ICO, Cookies and privacy notices in detail (advice for small organisations)
  7. ICO, How to write a privacy notice and what goes in it (advice for small organisations)
  8. ICO, TikTok withdraws two appeals in children's privacy action and accepts £12.7m fine, 24 September 2026

Last checked against the source:

For information only. Not legal advice.