
Data protection policy toolkit
- 8 template policies customisable to your business
- Includes guidance on how to use each policy
- UK GDPR compliant
This data protection policy toolkit provides 8 data protection policy templates you are likely to need to comply with your data protection obligations. It also contains a how-to guide, which tells you how to use each policy.
Data protection policies included in this pack can be customised for your business and include:
- Privacy policy
- Cookie policy
- Data protection policy
- Staff privacy notice
- Data subject request policy
- Data protection impact assessment policy
- Personal data breach policy
Using this data protection policy toolkit helps you to ensure that your staff are aware of how to deal with customers' personal data, you protect your staff members' and customers' personal information, and your business deals with any personal data breaches or subject access requests efficiently.
Complying with your data protection obligations not only means you will avoid being fined by the ICO, but you will also maintain your business's reputation and reduce the risk of staff or customers taking legal action against you.
Q&A
When should I use this toolkit?
This data protection policy toolkit is useful for your business at any time, to help you comply with your legal obligations.
Before setting up a website or dealing with customer data, you should have a privacy policy and cookie policy in place to tell customers how you are dealing with their information.
Other template documents in this toolkit can be used internally to ensure that:
- your staff are aware of how to deal with customers' personal data;
- your business deals with staff members' personal information properly;
- you protect individuals' data while conducting higher risk business activities; and
- you have efficient procedures for dealing with data subject requests and personal data breaches.
What does this toolkit cover?
This toolkit contains 8 data protection policy templates, which can be customised to your business. It also includes guidance on how to use each policy.
The policies included in this toolkit cover privacy and cookies, dealing with staff data during recruitment and employment, dealing with individuals' requests to access their data, dealing with personal data breaches, and more.
Why do I need this toolkit?
Using this data protection policy toolkit helps you to comply with your obligations under data protection law. This not only reduces your risk of being fined by the ICO or having a complaint made against you, but it also means that you will protect your staff and customers' data properly.
Ensuring personal information is protected, and dealing with breaches or subject access requests quickly and efficiently, helps you to maintain your business's reputation, staff goodwill, and customer relationships.
Where can I find out more?
For comprehensive guidance on data protection policies, see Using personal data, policies and record-keeping.
Documents in Toolkit
Cookie policy
Data protection impact assessment policy
Data protection policy
Data subject request policy
How-to guide: Data protection policy toolkit
Personal data breach policy
Privacy policy
Staff privacy notice
Staff recruitment privacy notice
Related Toolkits
Data breach toolkit
Personal data breach policy
Template personal data breach register
Notice of a personal data breach (affected individuals)
- How-to guide: Data breach toolkit
Data subject request toolkit
- How-to guide: Data subject request toolkit
Data subject request policy
Subject access request form
Data transfer request form
Request form to correct inaccurate or incomplete data
Request form to delete data
Request form to stop using data
Letter acknowledging receipt of data subject request (and requesting verification of ID)
Letter asking for further information about a data subject request
Letter confirming no data held in response to data subject request
Letter explaining reasons for extension of time to respond to data subject requests
Letter to third party seeking consent to disclosure of information
Subject access request response template
Letter confirming that data processing has ceased
Letter explaining why data processing will continue
Letter confirming that data has been corrected
Letter explaining why data will not be corrected
Letter to party who has been supplied with data to confirm its correction
Letter confirming that data has been deleted
Letter explaining why data will not be deleted
Letter to party who has been supplied data to confirm its deletion
Letter supplying data in response to a portability request
Letter supplying data to a third party in response to a portability request
Small claims toolkit
- How-to guide: Small claims toolkit
Letter before action
Witness statement
Letter of non-attendance for small claims hearing
Redundancy toolkit
- How-to guide: Redundancy toolkit
Redundancy - Letter warning of proposed redundancies
Redundancy - Selection criteria form
Redundancy - Provisional selection for redundancy letter
Redundancy - First individual consultation meeting agenda
Redundancy - Outcome of individual consultation meeting
Redundancy - Invitation to final individual consultation meeting
Redundancy - Final individual consultation meeting agenda
Redundancy - Notice of termination of employment
Redundancy - Offer of alternative employment