
Solicitor-led Privacy Notice Drafting and Review Service
We’ll help your organisation demonstrate its commitment to transparency
We help organisations prepare and update privacy notices for websites, employees, customers, candidates, suppliers and other individuals. Our approach is based on how your organisation actually collects, uses, shares and retains personal data rather than relying on a generic template.
Privacy Notice Drafting and Review for UK Organisations
Have you updated your complaints information?
Since 19 June 2026, organisations have been required to provide individuals with a clear way to make a data protection complaint. The ICO specifically suggests that existing privacy notices can be adapted to explain how people can raise those complaints.
Read about the new complaints requirements →

Clara Westbrook
25+ Years PQE
Founder | Qualified Solicitor | Data Protection Specialist
07976 939 016
A common issue we find is that an organisation’s privacy notice has not kept pace with how personal data is actually being used. New software may have been introduced, suppliers may have changed, retention periods may have evolved or employee and customer information may now be used for purposes that are not properly reflected in the notice.
What to expect from our privacy notice service
We start by understanding how your organisation actually uses personal data before reviewing or drafting the relevant privacy information. This allows us to identify not only wording that needs updating, but also inconsistencies between your notices and your wider data protection documentation.
1
Existing privacy notice review
2
Review of your data use
3
Drafting and updating
4
Rights and complaints wording
5
Alignment with RoPAs and policies
6
Practical recommendations
The scope will depend on what you already have in place. Some organisations need a single website privacy notice reviewed, while others require a suite of employee, customer, candidate, supplier and service-user notices.
How our privacy notice service works
1. Tell us what privacy information you currently have
We review your existing notices, policies and relevant documentation and agree which processing activities and audiences need to be covered.
2. We compare the wording with how you actually use personal data
We consider what information you collect, why you use it, your lawful bases, who receives it, how long it is retained and the rights available to individuals. Where necessary, we speak with the relevant people within your organisation to clarify how particular processing activities operate.
3. Receive clear, tailored privacy wording
We prepare or update the relevant notices, discuss any areas that require clarification and provide final wording ready for publication or distribution. Where we identify wider compliance gaps, we explain the practical steps needed to address them.
Once appointed, we can arrange regular monthly meetings, agree priorities and establish an appropriate reporting structure for your organisation.
What are the benefits of reviewing your privacy notices?
People can understand what information you collect, why you need it and what happens to it.
Better alignment with your actual practices
Your public-facing privacy information reflects your systems, suppliers, retention practices and wider compliance documentation.
Fewer avoidable complaints and inconsistencies
Clear wording around rights, data use and complaints can reduce uncertainty and make it easier for your organisation to respond when individuals raise questions.
Having an established DPO means those questions can be considered before implementation rather than after a problem has occurred.
Our monthly service allows the level of support to reflect the size, risk profile and requirements of your organisation.
Privacy notice pricing
Pricing depends on the number of notices required, the complexity of your processing activities and the quality of the documentation already in place.
Existing Privacy Notice Review | New Privacy Notice | Transparency Document Set |
From £500 | From £1,500 | From £3,000 |
Review of your existing privacy notice or transparency wording | Drafting of a new privacy notice for your organisation | Review and drafting of multiple privacy notices |
Identification of gaps, unclear wording and missing information | Clear explanation of what data you collect, why you use it and who you share it with | Website, customer, employee, supplier and candidate notices |
Practical recommendations for improvement | Wording aligned with UK GDPR transparency requirements | Alignment with RoPAs, policies, consent wording and complaints process |
Suitable where you already have a notice that needs updating | Suitable where your current notice is missing, outdated or inaccurate | Suitable for organisations with several data collection points |
A well-drafted privacy notice should do more than satisfy a legal requirement. It should give people a clear and accurate explanation of what your organisation does with their personal data.
Why organisations choose WDPS
We are a solicitor-led data protection organisation with over 25 years’ experience in privacy, data protection and commercial law.
Our privacy notice work is based on understanding how your organisation actually uses personal data. We do not simply insert your details into a standard template. Where our review identifies inconsistencies between your privacy information, policies, RoPA or operational practices, we explain what needs to change and why.
Our team has experience supporting organisations across sectors including media, retail, travel, financial services and pharmaceuticals, giving us a practical understanding of how transparency requirements operate in different commercial environments.
This means that when an issue arises, your organisation has access to a real data protection professional who understands both the legal requirements and the practical considerations involved in implementing them.
Request privacy notice support
Speak directly with a data protection specialist +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4 pm).
If you would like us to review your existing privacy notice or prepare new transparency wording, send us a short description of what you need. We will let you know what information we require and confirm the appropriate scope and fee before work begins.
Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ
View our Privacy Policy here
Explore More Data Protection & Privacy Services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]
Stay ahead with expert data protection tips
Get practical advice, legal updates, and exclusive insights.
Frequently asked questions
When does an organisation need to provide privacy information?
You must give people clear privacy information when you collect and use their personal data. If the information comes from another source, different timing rules apply. The notice should be provided in a way that is easy for the relevant audience to find and understand.
Do we need separate privacy notices for customers, staff and job applicants?
Not always, but separate or layered notices are often clearer where the audiences, purposes, lawful bases or retention periods differ. The right structure depends on how your organisation collects and uses personal data.
Is a privacy notice the same as consent?
No. A privacy notice explains how personal data is used and supports transparency. It is not itself consent and does not create a lawful basis for processing. Your organisation must identify and document the appropriate lawful basis separately.
When should a privacy notice be updated?
Review it regularly and whenever your processing changes materially, such as a new purpose, technology, recipient, international transfer or retention period. Where required, people should be told about a new use before their personal data is reused.



