Is your Privacy Notice putting you at risk?

The European Data Protection Board (EDPB), the body that co-ordinates data protection enforcement across the EU, has launched its latest enforcement focus on transparency. That means regulators across 27 countries will be checking whether businesses are giving people clear, accessible information about how their personal data is used. At the top of their list? Privacy notices.

This follows hot on the heels of the 2025 focus on the right to erasure, which found that a recurring problem was businesses simply not telling people about their rights in the first place. The message from regulators is clear,  it's not enough to handle data correctly behind the scenes, you need to communicate it properly too.

Why does your privacy notice matter?

Under GDPR, you are legally required to tell people, in plain language, what personal data you collect, why you collect it, how long you keep it, and what rights they have. This isn't just a box-ticking exercise. A clear, up-to-date privacy notice builds trust with your customers and protects your business if a complaint or audit arises.

Many businesses set up a privacy notice when they launched their website and haven't looked at it since. But your notice should reflect what you actually do with data today, not what you planned to do three years ago. If you've introduced new tools, changed suppliers, started marketing by email, or added a booking system, your notice needs to keep up.

Privacy notice do’s and don'ts

What should you check right now?

Pull up your privacy notice and ask yourself:

  • Does it reflect everything you actually do with personal data today?

    Does it mention all the tools and platforms you use, CRM, email marketing, booking systems, analytics?

  • Does it explain your customers' rights clearly, and tell them how to exercise those rights?

  • Does it include a contact email or form for data requests?

  • When was it last updated?

If you're unsure about the answers to any of those, it's worth getting a professional review before a regulator asks the same questions.

Need a privacy notice review? Privacy Path helps Irish and UK businesses get their GDPR documentation sorted, no jargon, no stress. Visit privacypath.ie to find out how we can help.

Next
Next

When an Employee Leaves: What Should You Do With Their Email Account?