Your privacy notice vs your app stack: the compliance drift problem
On this page
Short answer: most privacy notices are accurate exactly once — on the day they’re written. Your privacy notice is a snapshot; your business is a film, and every tool you connect after launch day quietly ages that snapshot a little more. That gap between the document and the live store is “drift” — the silent divergence nobody puts in the calendar, and the compliance risk almost nobody schedules a check for.
What “compliance drift” actually is
UK GDPR expects your privacy notice to tell people the truth about how their data is handled — what you collect, why, who you share it with, and how long you keep it (Articles 13–14). The catch is that “the truth” is a moving target. You connect a new tool on a Tuesday, swap fulfilment providers a month later, add a chat widget before a busy season. Each change is small and sensible. None of them updates the privacy notice, so with every change the document describes a slightly older version of your store — until it describes a store that no longer exists.
What the notice says vs what the live stack actually does
Why it’s the risk nobody schedules
Most compliance risks announce themselves. Drift doesn’t. There’s no error message, no failed check, no invoice. The notice still looks tidy. That’s exactly why it’s dangerous: the problem is invisible right up until the moment it isn’t.
Drift usually surfaces at the worst time:
- a customer complaint that exposes a tool you never disclosed — the same moment that turns into a data protection complaint if it isn’t handled calmly;
- a subject access request, where the deadline is a month but finding every copy of someone’s data means checking every tool the notice should already list;
- a B2B buyer doing due diligence who asks for your data map and DPAs;
- a regulator following up, where “our notice is out of date” is not a comfortable position.
By then it’s not a five-minute fix — it’s an archaeology project to work out what changed and when.
The three shapes drift takes
Drift isn’t one failure mode — it shows up in a few different ways, and each needs a slightly different fix.
Undisclosed recipient, missing purpose, stale detail
Drift isn’t one failure — it’s three different gaps between the notice and the live stack.
undisclosed recipientUndisclosed recipientA connected tool that handles personal data but is never named or categorised in the notice.
missing purposeMissing purposeA new use of data the notice doesn't cover, even for a tool it already names.
stale detailStale detailA retention period or third party that's changed since the notice was written.
The tools that cause it
Drift is almost always an app-stack problem. Every tool you connect can introduce a new purpose, a new data flow, or a new third party that should be reflected in your notice — and it’s usually the same tools that need a data processing agreement as well as a mention in the notice:
- payment and checkout tools;
- email, SMS and marketing platforms;
- analytics, heatmaps and ad pixels;
- reviews, loyalty and personalisation;
- chat, helpdesk and CRM;
- fulfilment, shipping and subscriptions;
- agencies, freelancers and payroll or HR tools behind the scenes.
Each one is a small, reasonable decision. Collectively, they’re why the paperwork falls behind reality.
How to catch drift before it catches you
The fix isn’t to freeze your business — it’s to make the invisible visible on a regular cadence, not just at launch.
Catching drift is a cycle, not a one-off task
Scan, compare, fix, re-check — and back to scan. Your stack keeps changing, so the check has to keep running.
Doing that by hand, across a stack that keeps changing, is exactly the chore that never gets done. It’s also what continuous, automated re-checking is for. GuardianStack’s free public check gives you the outside-in snapshot in about 30 seconds; the connected checks then track the operating layer — DPAs, consent records, retention, and privacy-notice completeness — and re-check as things change, so gaps don’t reappear quietly between manual reviews.
Why staying aligned actually matters
The point isn’t fear of a fine — it’s not carrying a gap between paperwork and reality that you can’t see. Drift is a risk signal to manage, not proof of a breach in itself — but don’t lean on that. The transparency duty in Articles 13–14 fails on a notice that’s materially inaccurate or incomplete: a missing tool, purpose or third party that changes what someone would understand, or a new use of their data started before anyone was told. The goal isn’t a flawless notice at every instant — it’s catching the material gaps quickly. Staying aligned is what lets you answer a complaint, a request, or a due-diligence question without a scramble — the same readiness that underpins the wider GDPR picture for a UK Shopify store.
Honest note: whether a specific gap counts as “material” isn’t always a clean call — it depends on what the undisclosed tool actually does with the data, not just that it exists. This guide gets the general shape right; a genuinely contested case is worth checking against the ICO’s own guidance or with a specialist. It’s guidance, not a verdict on your specific notice.
Run this against your own notice
Does your notice still match your live stack?
Six questions to run against your own privacy notice — the same ones GuardianStack’s automated checks track continuously.
Does it name or clearly categorise every recipient/processor that handles personal data — specific enough that people understand who gets it?
Does it cover every current use of that data, including ones added after launch?
Is the lawful basis for each purpose stated (with legitimate-interests detail where you rely on it)?
Are the retention periods stated the ones you actually apply today?
Does it reflect where data is actually processed or stored, including outside the UK?
Is there an owner and a schedule for checking the notice against the live stack?
Want to see where your own notice and live stack might already have drifted apart? The free public check looks at your storefront in about 30 seconds — no login, read-only.
The bottom line
Your privacy notice was true once. Keeping it true is an ongoing job, not a launch-day task, because your app stack never stops changing. Treat drift as the default state to manage — check it on a cadence, or automate the checking — and you turn a hidden liability into a routine.
Sources
The primary sources behind this guide — check them yourself:
Frequently asked questions
How often should I update my privacy notice?
Whenever what you actually do with personal data changes — a new tool, a new purpose, a new third party you share data with — not on a fixed annual date. Because those changes happen continuously, the practical answer is to review it on a regular cadence and any time you add or remove a data-handling tool.
What is compliance drift?
Compliance drift is the gradual divergence between your documented position (privacy notice, DPAs, retention rules) and what your business actually does, caused by everyday changes like adding apps or swapping providers. Nothing flags it, so it accumulates silently until an event exposes it.
How do I know if my privacy notice is out of date?
Compare what it says against the tools currently connected to your store and the data they handle. If there are apps processing customer data that the notice doesn't mention, or purposes it doesn't cover, it has drifted. An outside-in scan can surface the visible mismatches quickly.
See where your store actually stands
Run a free outside-in compliance check of your website — no login required, results in about 30 seconds.
Run the free website check