Guides

Your privacy notice vs your app stack: the compliance drift problem

10 June 2026 5 min read GuardianStack
On this page

Short answer: most privacy notices are accurate exactly once — on the day they’re written. Your privacy notice is a snapshot; your business is a film, and every tool you connect after launch day quietly ages that snapshot a little more. That gap between the document and the live store is “drift” — the silent divergence nobody puts in the calendar, and the compliance risk almost nobody schedules a check for.

What “compliance drift” actually is

UK GDPR expects your privacy notice to tell people the truth about how their data is handled — what you collect, why, who you share it with, and how long you keep it (Articles 13–14). The catch is that “the truth” is a moving target. You connect a new tool on a Tuesday, swap fulfilment providers a month later, add a chat widget before a busy season. Each change is small and sensible. None of them updates the privacy notice, so with every change the document describes a slightly older version of your store — until it describes a store that no longer exists.

Analysis · Notice vs reality

What the notice says vs what the live stack actually does

What the notice saysnotice (launch day) = snapshot
  • Names the payment processor and email tool you had at launch
  • Lists the purposes you had in mind on day one
  • No review date, no version history — untouched since
What the live stack actually doeslive stack (today) = film, still rolling
  • Payment tool now runs its own fraud-check profiling
  • Email has grown into SMS, retargeting and loyalty syncing
  • Analytics, chat and reviews apps arrived after the notice was written
Source: GuardianStack methodology · illustrative UK store example

Why it’s the risk nobody schedules

Most compliance risks announce themselves. Drift doesn’t. There’s no error message, no failed check, no invoice. The notice still looks tidy. That’s exactly why it’s dangerous: the problem is invisible right up until the moment it isn’t.

Drift usually surfaces at the worst time:

  • a customer complaint that exposes a tool you never disclosed — the same moment that turns into a data protection complaint if it isn’t handled calmly;
  • a subject access request, where the deadline is a month but finding every copy of someone’s data means checking every tool the notice should already list;
  • a B2B buyer doing due diligence who asks for your data map and DPAs;
  • a regulator following up, where “our notice is out of date” is not a comfortable position.

By then it’s not a five-minute fix — it’s an archaeology project to work out what changed and when.

The three shapes drift takes

Drift isn’t one failure mode — it shows up in a few different ways, and each needs a slightly different fix.

Concept · The three shapes drift takes

Undisclosed recipient, missing purpose, stale detail

Drift isn’t one failure — it’s three different gaps between the notice and the live stack.

undisclosed recipientUndisclosed recipient

A connected tool that handles personal data but is never named or categorised in the notice.

Example: A courier or review app the notice never lists.
missing purposeMissing purpose

A new use of data the notice doesn't cover, even for a tool it already names.

Example: Loyalty data now also used to build ad audiences.
stale detailStale detail

A retention period or third party that's changed since the notice was written.

Example: A courier switched, or data kept longer than stated.
Source: GuardianStack methodology · illustrative categories

The tools that cause it

Drift is almost always an app-stack problem. Every tool you connect can introduce a new purpose, a new data flow, or a new third party that should be reflected in your notice — and it’s usually the same tools that need a data processing agreement as well as a mention in the notice:

  • payment and checkout tools;
  • email, SMS and marketing platforms;
  • analytics, heatmaps and ad pixels;
  • reviews, loyalty and personalisation;
  • chat, helpdesk and CRM;
  • fulfilment, shipping and subscriptions;
  • agencies, freelancers and payroll or HR tools behind the scenes.

Each one is a small, reasonable decision. Collectively, they’re why the paperwork falls behind reality.

How to catch drift before it catches you

The fix isn’t to freeze your business — it’s to make the invisible visible on a regular cadence, not just at launch.

Framework · The re-check loop

Catching drift is a cycle, not a one-off task

Scan, compare, fix, re-check — and back to scan. Your stack keeps changing, so the check has to keep running.

Scan the live stackevery connected tool Compare to the noticewhat's named, what's not Fix the gapupdate wording or cover it Re-check on a cadencemonthly, or on every app change cadence — the loop keeps running stack changes keep happening — so the check has to keep running
Source: GuardianStack methodology

Doing that by hand, across a stack that keeps changing, is exactly the chore that never gets done. It’s also what continuous, automated re-checking is for. GuardianStack’s free public check gives you the outside-in snapshot in about 30 seconds; the connected checks then track the operating layer — DPAs, consent records, retention, and privacy-notice completeness — and re-check as things change, so gaps don’t reappear quietly between manual reviews.

Why staying aligned actually matters

The point isn’t fear of a fine — it’s not carrying a gap between paperwork and reality that you can’t see. Drift is a risk signal to manage, not proof of a breach in itself — but don’t lean on that. The transparency duty in Articles 13–14 fails on a notice that’s materially inaccurate or incomplete: a missing tool, purpose or third party that changes what someone would understand, or a new use of their data started before anyone was told. The goal isn’t a flawless notice at every instant — it’s catching the material gaps quickly. Staying aligned is what lets you answer a complaint, a request, or a due-diligence question without a scramble — the same readiness that underpins the wider GDPR picture for a UK Shopify store.

Honest note: whether a specific gap counts as “material” isn’t always a clean call — it depends on what the undisclosed tool actually does with the data, not just that it exists. This guide gets the general shape right; a genuinely contested case is worth checking against the ICO’s own guidance or with a specialist. It’s guidance, not a verdict on your specific notice.

Run this against your own notice

Diagnostic · Self-audit

Does your notice still match your live stack?

Six questions to run against your own privacy notice — the same ones GuardianStack’s automated checks track continuously.

1
Recipients

Does it name or clearly categorise every recipient/processor that handles personal data — specific enough that people understand who gets it?

2
Every purpose

Does it cover every current use of that data, including ones added after launch?

3
Lawful basis

Is the lawful basis for each purpose stated (with legitimate-interests detail where you rely on it)?

4
Retention periods

Are the retention periods stated the ones you actually apply today?

5
International transfers

Does it reflect where data is actually processed or stored, including outside the UK?

6
A review cadence

Is there an owner and a schedule for checking the notice against the live stack?

Source: UK GDPR Articles 13–14 · ICO — Guide to UK GDPR

Want to see where your own notice and live stack might already have drifted apart? The free public check looks at your storefront in about 30 seconds — no login, read-only.

The bottom line

Your privacy notice was true once. Keeping it true is an ongoing job, not a launch-day task, because your app stack never stops changing. Treat drift as the default state to manage — check it on a cadence, or automate the checking — and you turn a hidden liability into a routine.

Sources

The primary sources behind this guide — check them yourself:

Frequently asked questions

How often should I update my privacy notice?

Whenever what you actually do with personal data changes — a new tool, a new purpose, a new third party you share data with — not on a fixed annual date. Because those changes happen continuously, the practical answer is to review it on a regular cadence and any time you add or remove a data-handling tool.

What is compliance drift?

Compliance drift is the gradual divergence between your documented position (privacy notice, DPAs, retention rules) and what your business actually does, caused by everyday changes like adding apps or swapping providers. Nothing flags it, so it accumulates silently until an event exposes it.

How do I know if my privacy notice is out of date?

Compare what it says against the tools currently connected to your store and the data they handle. If there are apps processing customer data that the notice doesn't mention, or purposes it doesn't cover, it has drifted. An outside-in scan can surface the visible mismatches quickly.

See where your store actually stands

Run a free outside-in compliance check of your website — no login required, results in about 30 seconds.

Run the free website check
← Back to all articles