Home / GDPR Privacy Policy Generator

GDPR Privacy Policy Generator

GDPR is switched on, so the policy includes legal bases, EEA/UK rights, transfers and the supervisory-authority complaint right. The checklist beside it tracks every Article 13 item.

Free template, not legal advice. Replace every [bracketed] field, make sure it matches what you actually do, and get a lawyer's review for anything high-stakes. How clauses are sourced.

1 Quick start: what do you run?
2 Your details
3 Which laws should it cover?

Not sure? Check which laws apply to you.

4 What do you collect?
Platform
5 Services you use
6 A few specifics
+ Anything else

Only this description, your business name and chosen laws are sent to the AI. Check the draft carefully; it is a starting point, not legal advice.

Answers auto-save in this browser only.

Privacy Policy

[Bracketed] fields are placeholders · Template, not legal advice

Who we are

This Privacy Policy explains how [Business name] ("we", "us", "our") collects, uses and shares personal information when you use [Website or app name] (the "website"), available at [website URL]. For the purposes of the EU and UK General Data Protection Regulation, [Business name] is the controller of your personal data.

If you have any questions about this policy or your information, contact us:

  • Email: [contact email]
  • Postal address: [Business address]

Information we collect

Depending on how you use the website, we collect the following categories of personal information:

  • Contact details: name, email address, phone number.
  • Usage data: pages or screens viewed, features used, clicks, referring page, time and date of visits.
  • Device & log data: IP address, browser type, operating system, device identifiers, crash logs.
  • Cookies & similar tech: cookies, local storage, pixels and SDK identifiers.

We collect this information directly from you (when you fill in a form, create an account, buy something or contact us), automatically from your device when you use the website, and from the service providers listed below.

How we use your information

  • To provide, operate and maintain the website.
  • To create and manage your account.
  • To answer your questions and provide customer support.
  • To understand how the website is used and improve it.
  • To keep the website secure and to comply with our legal obligations.

Legal bases for processing (EEA and UK visitors)

We rely on the following legal bases under Article 6 of the GDPR:

  • Contract: to provide the services you have asked for, such as your account or an order.
  • Legitimate interests: to run, secure and improve the website, where these interests are not overridden by your rights. [Describe each legitimate interest you rely on.]
  • Consent: for non-essential cookies, marketing emails and precise location. You can withdraw consent at any time without affecting processing that happened before.
  • Legal obligation: to keep records required by tax, accounting or other laws.

How we share information

We do not share your personal information except as described here. We share it with service providers who process it on our behalf and only as needed to provide their services:

  • Google Analytics, for website and app analytics (privacy policy: https://policies.google.com/privacy).

We may also disclose information if required by law, to protect our rights or the safety of others, or as part of a merger, acquisition or sale of assets, in which case we will tell you before your information becomes subject to a different privacy policy.

Cookies and tracking technologies

We and our partners use cookies and similar technologies on the website. Some third parties, such as analytics and advertising providers, may collect information about your online activities over time and across different websites when you use the website. See our Cookie Policy for details and for how to change your choices.

Your rights under the GDPR (EEA and UK)

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to our processing, including processing based on legitimate interests and direct marketing;
  • receive your data in a portable format;
  • withdraw consent at any time, where we rely on consent.

To exercise these rights, contact [contact email]. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work, or where you believe an infringement occurred.

International transfers: our service providers may process data outside your country, including in the United States. Where we transfer personal data out of the EEA or UK, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses. [Confirm the transfer mechanism for each provider.]

Automated decisions: we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. [Edit if you do.]

How long we keep information

We keep personal information as long as your account is active, and afterwards only as long as we need it for the purposes above or to meet legal, tax or accounting obligations.

How we protect information

We use reasonable administrative, technical and physical safeguards appropriate to the sensitivity of the information, including encryption in transit (HTTPS). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children

The website is not directed to children under 13 (or under the age of digital consent in your country, which is between 13 and 16 in the EU), and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will change the "Effective date" below, and if the changes are significant we will notify you by email or by a notice on the website before they take effect.

Effective date

This Privacy Policy is effective as of [Effective date].

11 left · View document ↓

GDPR checklist

What the generated policy covers for GDPR, with the provision each item comes from.

  • Who you are and how to contact youArt. 13(1)(a)
  • Data protection officer contact (if you have one)Art. 13(1)(b)
  • Categories of personal information collectedArt. 13 & 14
  • Where the information comes fromArt. 14(2)(f) (data not obtained from the person)
  • Why you use itArt. 13(1)(c)
  • Legal basis for each purposeArt. 13(1)(c)–(d), Art. 6
  • Who you share it withArt. 13(1)(e)
  • International transfersArt. 13(1)(f)
  • How long you keep itArt. 13(2)(a)
  • People's rights and how to use themArt. 13(2)(b)–(c), Arts. 15–22
  • Right to complain to a regulatorArt. 13(2)(d)
  • Automated decision-making / profilingArt. 13(2)(f)
  • ChildrenArt. 8
  • Security safeguardsArt. 32

Official sources: Regulation (EU) 2016/679, EUR-Lex; Your Europe: Data protection under GDPR

What Article 13 requires

When you collect personal data directly from someone, Article 13 of the GDPR says you must tell them, at the time of collection: your identity and contact details (and your EU representative's, if you need one); your data protection officer's contact details, where applicable; the purposes and legal basis of processing, including the legitimate interests you rely on; the recipients or categories of recipients; any transfer outside the EU and the safeguard used; how long the data will be stored or the criteria for deciding; the rights of access, rectification, erasure, restriction, objection and portability; the right to withdraw consent; the right to lodge a complaint with a supervisory authority; whether providing the data is a statutory or contractual requirement; and the existence of automated decision-making, including profiling.

Article 12 adds that this must be concise, transparent, intelligible and easily accessible, in clear and plain language. A privacy policy that lists every possible processing activity in legalese fails that test even if it mentions everything.

Non-EU businesses

Under Article 3(2), GDPR applies to organisations outside the EU that offer goods or services to people in the EU, or monitor their behaviour there. Such organisations usually also need to appoint a representative in the EU (Article 27), with limited exceptions for occasional, low-risk processing. The UK applies the same rules through the UK GDPR.

Frequently asked questions

Does a GDPR privacy policy make me GDPR compliant?

No. The notice is one obligation (transparency). GDPR also requires a lawful basis for each processing activity, data processing agreements with processors, security, records of processing in many cases, breach notification and handling rights requests within one month.

Which legal basis should I pick?

Article 6 lists six. Most websites rely on contract (to deliver what the user asked for), legitimate interests (analytics without cookies, security, fraud prevention) and consent (non-essential cookies, marketing). The UK ICO's lawful basis guidance is a clear walkthrough.

Is it really free? Do I need an account?

Yes, and no. Every generator is free with no sign-up, watermark or paywall. Your answers stay in your browser; they are never sent to our server unless you use the optional AI clause writer or policy checker.

Is a generated policy legal advice?

No. PolicyForge produces a starting template from your answers. It cannot know every detail of your business or every law that applies to you. Read the whole document, replace every [bracketed] placeholder, make sure it describes what you actually do, and have a lawyer review it if you handle sensitive data, sell to children, or operate at scale.

Related generators