Generate a privacy policy

Answer a handful of questions about what your site actually collects and get a structured, plain-English policy as Markdown and HTML. It is written around the information you are legally required to give people — but it is a template you must read, edit and have checked, not finished legal advice.

✓ Runs in your browser — nothing uploaded Free, no sign-upNo watermark
Downloads as .md and .html

How to use the Privacy Policy Generator

  1. Enter who is responsible for the site and how to contact them.
  2. Pick the law that applies where most of your visitors are.
  3. Tick everything your site genuinely does — and nothing it does not.
  4. Generate, then read every line, edit it to match reality, and have it checked.

Read this first

This tool produces a template, not legal advice. It cannot know what your site does, which third parties you have contracts with, or where your data sits. Publishing a policy that describes things you do not do is itself a compliance failure, because the regulator’s starting question is always whether the notice matches the processing. Use the output as a structured first draft, cut everything that is untrue, add everything you do that is missing, and have a solicitor or privacy professional review it before it goes live.

What the law actually requires you to say

Under the UK GDPR and the EU GDPR, Articles 13 and 14 set out the information you must give people — and Article 12 requires it to be concise, transparent, intelligible, easily accessible and in clear and plain language. That list is:

  • who the controller is, and how to contact them (and the data protection officer, if you have appointed one);
  • the purposes of the processing and the lawful basis for each — and where you rely on legitimate interests, what those interests are;
  • the recipients, or categories of recipient, of the personal data;
  • any transfer outside the UK or EEA and the safeguard relied on;
  • how long the data is kept, or the criteria used to decide;
  • the individual’s rights: access, rectification, erasure, restriction, portability and objection;
  • the right to withdraw consent at any time, where consent is the basis;
  • the right to complain to a supervisory authority — the ICO in the UK;
  • whether providing the data is a statutory or contractual requirement and what happens if it is not provided;
  • the existence of any automated decision-making, including profiling, and meaningful information about the logic involved.

Cookies are a separate rule

Cookie consent does not come from the GDPR. In the UK it comes from PECR, and in the EU from the ePrivacy Directive as implemented locally. The rule is simple and strict: anything not strictly necessary to deliver the service the user asked for requires consent before it is set. That covers analytics, advertising, embedded video, A/B testing and most heat-mapping. Consent must be freely given, specific, informed and unambiguous, and — the part most banners get wrong — as easy to withdraw as it was to give, which is why both the ICO and the French CNIL have pushed for a "Reject all" button that is as prominent as "Accept all".

California

The CCPA, as amended by the CPRA, applies to for-profit businesses that do business in California and meet one of three thresholds: annual gross revenue above $25 million; buying, selling or sharing the personal information of 100,000 or more consumers or households; or deriving 50% or more of revenue from selling or sharing personal information. If it applies, you need a notice at collection, a description of the categories of information you collect and disclose, a "Do Not Sell or Share My Personal Information" link if you share for cross-context behavioural advertising, and you must honour the Global Privacy Control browser signal.

Practical points

Publish the policy at a stable URL such as /privacy, link it from every page footer and from every form that collects data, and keep a dated copy of each version so you can show what a user agreed to. Review it whenever you add a tool that touches personal data, which in practice means every new analytics script, chat widget or embedded form. Penalties are real: up to £17.5 million or 4% of global annual turnover under the UK GDPR, and €20 million or 4% under the EU GDPR.

Frequently asked questions

Is this enough to be GDPR compliant?

No. A privacy notice is one requirement among many — you also need a lawful basis for each activity, a record of processing, contracts with your processors, a cookie consent mechanism and a way to handle rights requests. The policy is the visible part of a larger obligation.

Do I need a policy for a small personal site?

If it collects anything — a contact form, analytics, comments, even server logs tied to an identifiable person — then yes. The GDPR has no small-business exemption for transparency.

Can I just copy another site’s policy?

It is a bad idea and often a copyright infringement. More importantly, it will describe their processing, not yours, which is exactly what a regulator looks for when a complaint arrives.

What is the difference between a controller and a processor?

A controller decides why and how personal data is used; a processor only acts on the controller’s instructions. Running your own website makes you a controller, and your analytics or hosting supplier is usually a processor acting for you.

Does this cover terms of service too?

No. A privacy policy explains data handling. Terms of service are a separate contract governing use of the site, and the two should not be merged.

Privacy

This tool runs entirely inside your browser using WebAssembly and the Canvas/File APIs. Your files are never uploaded to ToolFlint or any third party; you can verify this in your browser's network tab or by switching to airplane mode after the page loads. Read how we process files.

Last updated 2026-09-23.