Privacy notice for a consultancy
A privacy notice for a consultancy, advisory or professional services firm, drafted for the firm with the cookie notice and consent guidance, for a fixed fee of £595 in five working days.
Privacy notice for a consultancy
Buy now, £595A consultancy holds the contact details of its clients and prospects, the data its clients give it to do the work (for which it is usually a processor), the data its own systems and subcontractors handle, and the records its professional obligations require it to keep. The privacy notice has to separate the data the firm controls from the data it processes for clients, state the basis for business-to-business marketing, describe the cloud tools and where they host, and set the retention that professional rules and limitation periods require. Drafting for the business, I deliver the privacy notice, the cookie notice and guidance on consent in five working days for a fixed £595.
Who this is for
Management, IT, HR, marketing, financial and other consultancies and professional services firms in England and Wales, from a sole consultant to a firm with associates and subcontractors.
What matters in a consultancy privacy notice
Clients, contacts and the data a professional relationship holds
Being the controller, the business is required by Article 13 of the UK GDPR to tell the people whose data it controls what it does with it, and for a consultancy that is the individuals at client organisations (names, roles, contact details, the correspondence and meeting records), prospects and referrers, suppliers and associates, website visitors and the recipients of the firm's marketing; the lawful bases are the contract with the client under Article 6(1)(b) for the engagement, legitimate interests under Article 6(1)(f) for relationship management, marketing to corporate contacts and the firm's own administration, and legal obligation under Article 6(1)(c) for the records the firm's regulator, insurer or tax position requires, with consent kept for the optional.
The firm as processor for client data and controller for its own
The personal data a client gives the firm to do the work (the client's employees' data for an HR project, its customers' data for a marketing review, its systems' data for an IT engagement) is processed by the firm as the client's processor under Article 28 of the UK GDPR under a data processing agreement, or as a controller where the firm decides the purposes (an independent investigation, advice the firm gives on its own responsibility), and the notice should say that client data is covered by the client's notice and the engagement terms rather than by this notice, and that the firm's own records of the engagement (its working papers, its advice) are the firm's; a consultancy that describes its clients' data as its own has told its clients it decides what happens to it.
Business-to-business marketing and the firm's prospects
Marketing to individuals by electronic means needs consent under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, or the soft opt-in where it applies, which covers sole traders and partnerships, while marketing to a named person at a limited company may rest on legitimate interests with an opt-out, which is the basis most consultancies use for their newsletters and prospecting; the notice should state the basis, the sources of the contacts (networking, referrals, professional networks, public sources, with Article 14 requiring the firm to tell people whose data it obtained elsewhere), the opt-out in every message, and the retention of prospects who never become clients.
The cloud tools, the subcontractors and the transfers
The notice should describe the categories of processor the firm uses (email and document platforms, the CRM, the project and collaboration tools, the accounting software, the e-signature service, the video platform) and the international transfers most of them involve (US-hosted tools under the safeguards Article 46 of the UK GDPR requires, with the international data transfer agreement or the addendum to the EU clauses, or an adequacy regulation), the associates and subcontractors the firm engages on client work (as its sub-processors, with the client's consent where the data processing agreement requires it, under confidentiality and data protection terms the firm's subcontractor agreements should contain), and the firm's security measures in outline.
Confidentiality, professional obligations and the records the firm must keep
Where the firm is regulated (accountants, financial advisers, HR consultants with professional body membership, consultancies supervised for anti-money laundering purposes under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017), the notice should state the obligations that affect the data: client due diligence records kept for the period the regulations require, the professional body's rules on records and confidentiality, the insurer's requirements, and the duty to report where the law requires it; the firm's confidentiality obligations to clients sit alongside and the notice should say that client information is not disclosed outside the engagement except as the law requires.
Retention, conflicts and the data that outlasts the engagement
The notice should state the retention: engagement records and working papers for the period after completion that the firm's professional rules, its insurer and the limitation period for claims justify (commonly a period of years), due diligence records for the period the regulations require, prospects' data for a stated period after the last contact, and the conflict-checking records the firm keeps so that it can identify conflicts in future engagements, which is a legitimate interest the notice should state; it should cover the individual's rights (access, rectification, erasure, restriction, portability, objection), how to exercise them, the one-month time limit, and the right to complain to the Information Commissioner's Office, and the website's cookies under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 with the consent mechanism the pack provides guidance on; where the fee under the Data Protection (Charges and Information) Regulations 2018 applies, the business registers with the Information Commissioner's Office and the notice says so.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Does our privacy notice cover the data our clients give us for projects?
It does not. That data is processed for the client under the engagement terms and the data processing agreement, with the client's notice covering it. The firm's notice covers the data the firm controls: its contacts, prospects, records and website.
Can we email prospects at companies without consent?
Named individuals at limited companies, on legitimate interests with an opt-out; sole traders and partnerships need consent or the soft opt-in. The notice states the basis and the sources.
How long do we keep client files after an engagement?
For the period the firm's professional rules, its insurer and the limitation period justify, commonly a period of years, with due diligence records for the period the regulations require. The notice states the periods.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Consultancy agreement for a retainer arrangement
- Privacy notice for a marketing agency
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.