Free Download | Data Protection Template
The data protection policy that does more than tick a box ✅
Most businesses can tell you they take data protection seriously. Fewer can actually show it 📄
A data protection policy is how you close that gap: what personal data you hold, why you're allowed to hold it, and what everyone in the business is responsible for.
It covers everything a proper policy needs to:
👉 Lawful bases
👉 Individual rights
👉 Retention
👉 Breaches and international transfers
Free to download and easy to make your own.
Download your free Data Protection policy template!
What's in this template?
Every privacy programme needs a data protection policy at the centre of it. It's the document that says what personal data your business actually holds, why you're allowed to hold it, and what everyone, from the founders down, is responsible for.
Without one, "we take data protection seriously" is just a sentence. With one, it's something you can actually point to, for a due diligence questionnaire, an ICO inquiry, or a new starter's first week.
This isn't a watered-down summary. It's the real thing: lawful bases, individual rights, retention, breaches, international transfers, all of it, ready to copy, edit and roll out.
Short on time? Here's what's in this guide:
- What's inside the data protection policy template
- Why bother with a data protection policy
- Who this template is built for
- How to use it
- Where most data protection policies go wrong
- Frequently asked questions
📄 What's inside the data protection policy template
It's built section by section around every part of UK and EU GDPR your business actually needs to cover, plus the appendices so nobody has to memorise Article 5.
| Section | What it covers |
|---|---|
| Who's covered and what's in scope | Employees, contractors and third parties, and every type of personal data your business handles |
| The data protection principles | The seven principles behind UK and EU GDPR, spelled out in plain English (full detail in Appendix 1) |
| Lawful grounds for processing | The six lawful bases your business can rely on, and when each one applies (Appendix 2) |
| Individual rights | Every right people have over their data, from access requests to objecting to processing (Appendix 3) |
| Retention and records | How long personal data can be kept, and keeping an accurate Record of Processing Activities (ROPA) |
| Data breaches | What counts as a breach, and when the ICO and affected individuals need telling |
| Risk assessments | When a DPIA is needed, and who signs it off |
| International transfers | The rules for moving personal data outside the UK or EEA, and the safeguards that make it lawful |
| Security and training | Technical and organisational measures, plus what staff training needs to cover |
| Everyone's obligations | What the business commits to, and what every member of staff is individually responsible for |
Why bother with a data protection policy
Nobody sets out to fall behind on data protection. It just happens quietly, while everyone's busy building the actual business.
The problem is that UK GDPR's accountability principle doesn't just expect you to comply, it expects you to prove it. A data protection policy is the clearest, simplest way most businesses do that.
It also shows up in places you might not expect. Investors and enterprise customers ask for it during due diligence and procurement reviews. New hires need it to understand how data actually gets handled day to day. And if something ever does go wrong, it's the document that shows the ICO you had a system in place, not just good intentions.
Got questions on where your business stands?
Trust Keith runs free monthly Office Hours where you can ask a privacy expert directly.
Who this data protection policy template is built for
This one's for scaleups, not enterprises. It's a good fit if your business:
- Has roughly 50 to 250 employees
- Processes personal data at scale, or handles special category data (health, biometric, financial)
- Has a multinational customer base, or transfers data across borders
- Needs to prove compliance to investors, enterprise customers or regulators, without a full in-house legal or privacy team
How to use this data protection policy template
Step One: Make a copy and swap in your company name. Find and replace every instance of {Company Name} throughout the document.
Step Two: Name your Primary Security Contact. Someone needs to own this policy and be the point of contact for data protection questions, whether that's a DPO, Head of Legal, or a founder wearing that hat for now.
Step Three: Connect it to your other policies. This policy references your retention schedule, breach procedures and Record of Processing Activities. If those don't exist yet, they're the next things to build, alongside a risk register to keep track of it all.
Step Four: Train your team. A policy nobody's read isn't a policy, it's a PDF. Build it into regular staff training so people actually understand their obligations, not just sign to say they've seen it.
Step Five: Get it reviewed. Have a privacy expert check it's proportionate and accurate before you rely on it. Trust Keith customers get expert-tailored, audit-ready policies as standard; going it alone just means budgeting time for a proper review.
Where most data protection policies go wrong
Publishing it and never looking at it again. Data protection law and your business both change. A policy that isn't reviewed regularly stops matching reality within a year.
No supporting evidence behind it. A policy that says you keep a ROPA, run DPIAs and log breaches only counts if you're actually doing those things. The ICO looks for proof, not promises.
Treating it as a legal exercise, not an operational one. If staff haven't been trained on it, it's not protecting anyone. Most incidents come down to people, not policy gaps.
Ignoring international transfers. If personal data moves outside the UK or EEA, even via a US-based tool, that needs a lawful transfer mechanism in place, not an assumption that it's fine.
Confusing it with a privacy notice. A data protection policy is internal. A privacy notice is what you tell customers and candidates. Businesses need both, and they need to agree with each other.
Frequently asked questions
What should a data protection policy include?
Who it applies to, what personal data is in scope, the lawful bases for processing, how individual rights requests are handled, retention and breach procedures, rules on international transfers, security measures, and everyone's obligations under UK and EU GDPR. Trust Keith's free template covers all of it.
Is a data protection policy a legal requirement?
UK GDPR doesn't name a specific document you must have, but the accountability principle requires you to demonstrate compliance through appropriate policies and procedures. In practice, the ICO expects a documented data protection policy as basic evidence of this, and it's one of the first things investors, enterprise customers and auditors ask to see.
Is this data protection policy template really free?
Yes. Trust Keith built this to help data-centric scaleups get a proper policy in place quickly. It's free in exchange for a work email, and it's yours to edit, use and share internally.
Does this template cover both UK and EU GDPR?
Yes. It's built around UK GDPR and the Data Protection Act 2018, and references the equivalent EU GDPR requirements, so it works whether a business operates under one regime or both.
What's the difference between a data protection policy and a privacy notice?
A data protection policy is an internal document setting out how a business handles personal data and what staff are expected to do. A privacy notice is external, telling customers, users or job applicants what happens to their data. Businesses need both, and they should say consistent things.
How often should a data protection policy be updated?
At least once a year, and whenever data protection law changes, the business starts processing new types of personal data, or expands into a new market.
Does this template replace legal advice?
No. It's a strong starting point, but it should be reviewed by a privacy expert before being relied on, especially for businesses processing special category data or transferring data internationally.
Disclaimer: This template is provided free of charge for general information purposes only. It does not constitute legal advice and should not be relied upon as such. Always have your policy reviewed by a qualified privacy professional before relying on it.

.avif)