Build a privacy policy from your actual data practices. Adds GDPR, CCPA/CPRA, CalOPPA, COPPA and PIPEDA sections only for the regimes that apply to you.
A privacy policy is not a formality you copy from a competitor. It is a legal disclosure describing what your product does with personal data, and a policy that describes someone else’s data practices is worse than useless — it is a documented misstatement about your own. This privacy policy generator builds one from your actual answers: what type of product you run, what categories of data you collect, which third-party services touch that data, what security measures you have, how long you keep things, and which privacy regimes apply to you.
It runs entirely in your browser, requires no account, and produces a plain-text policy you can copy, download, and paste into your CMS or app store listing. Regulation-specific sections are added only for the regimes you select, so a UK-only B2B tool does not end up with a COPPA section it has no business containing.
GDPR. Articles 13 and 14 prescribe what must be disclosed to a data subject: the identity and contact details of the controller and any data protection officer, the purposes of processing and the legal basis for each, the legitimate interests pursued where that is the basis relied on, recipients of the data, any transfer to a third country and the safeguard used, the retention period or the criteria for determining it, and the data subject rights. The rights section covers access (Article 15), rectification (16), erasure (17), restriction (18), portability (20) and objection (21), plus the right to withdraw consent at any time and the right to lodge a complaint with a supervisory authority. Note that a lawful basis under Article 6 is required for all processing, and special category data — health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation — needs an additional condition under Article 9(2).
CCPA as amended by the CPRA. The California section covers the consumer rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information, together with the prohibition on discriminating against consumers who exercise them. If you sell or share personal information, a clear and conspicuous “Do Not Sell or Share My Personal Information” link must appear on your site as well as in the policy, and you cannot require account creation to submit an opt-out. The statute applies to for-profit businesses doing business in California that meet at least one threshold: gross annual revenue above an inflation-adjusted figure (US$26.625 million for the 2025 threshold year), buying, selling or sharing the personal information of 100,000 or more California residents or households, or deriving 50% or more of annual revenue from selling or sharing that information. Check the current figure with the California Privacy Protection Agency before relying on the threshold.
CalOPPA. Older and broader in reach than the CCPA — it requires operators of commercial websites and online services that collect personally identifiable information from California residents to conspicuously post a privacy policy, and to disclose how the service responds to Do Not Track signals.
COPPA. Applies to operators of services directed to children under 13, and to general-audience services with actual knowledge that they collect personal information from children under 13. The core obligation is verifiable parental consent before collection, with specific notice and parental access rights. If you are not confident you fall outside it, this is one to take to counsel rather than a generator.
PIPEDA. Canada’s federal private-sector law, built on ten fair information principles including accountability, identifying purposes, consent, limiting collection, limiting use and retention, accuracy, safeguards, openness, individual access and challenging compliance. Some provinces have substantially similar legislation that applies instead.
| Mistake | Why it matters |
|---|---|
| Listing security measures you have not implemented | Turns a security shortfall into a false statement to consumers, which is the hook regulators and plaintiffs reach for first |
| Omitting a processor that receives data | Breaks the recipient disclosure required by GDPR Article 13 and the category disclosures under the CCPA |
| Selecting every regime to be safe | You are held to what your own policy promises, whether or not the law required it |
| Publishing and never updating | A policy that predates your current analytics stack describes a product you no longer run |
| No named legal entity or contact route | Removes the mechanism by which anyone can exercise a right, which is itself the violation |
| Treating the policy as the whole compliance job | Consent mechanics, retention enforcement, processor contracts and breach procedures all sit outside the document |
It is a starting draft, not legal advice, and it does not by itself make you compliant. It gets the structure and the standard disclosures right so that a lawyer’s review is a review rather than a rewrite. If you process sensitive data, operate in a regulated sector, or serve children, get it reviewed before publishing.
Yes. Analytics involves collecting information from users’ devices and sharing it with a third party, which triggers disclosure obligations under the GDPR if you have EEA visitors and under CalOPPA if you have Californian ones. It also triggers a consent question separate from the policy.
The privacy policy covers all personal data processing. A cookie policy covers what is stored on or read from the user’s device and by whom, and it is what the consent banner links to. Many organisations publish one document with a cookie section; the distinction matters mainly because consent for cookies is governed by the ePrivacy Directive, not just the GDPR.
Whenever your processing changes — a new analytics tool, a new payment processor, a new data category, a new market — and on a scheduled review at least annually. Keep the effective date visible, and keep prior versions.
The GDPR requires the recipients or categories of recipients. Naming them individually is more work to maintain but far more defensible, and it is what regulators and enterprise procurement reviewers increasingly expect. Naming them also forces you to keep an accurate inventory, which is useful on its own.
If the CCPA applies to you and you sell or share personal information as those terms are defined — and note that “sharing” captures cross-context behavioural advertising, so common ad-tech setups are in scope even without money changing hands — then yes, the link must be clear and conspicuous on your site, not buried in the policy.
No. Everything runs in your browser and the policy is generated locally. Nothing you enter is transmitted to us for storage.
Verify that the site behaves the way the policy says it does. Run the GDPR compliance checker against your live pages to see whether your policy, consent banner and trackers actually agree with each other, and use the cookie analyzer to enumerate what is really being set. Then handle the paperwork behind the policy with the GDPR role and retention mapper, and cover the internal side with the security policy generator.
A privacy policy is a legal document that discloses how an organization collects, uses, stores, shares, and protects personal information from users and customers. Privacy policies are legally required in most jurisdictions for any website, application, or service that collects personal data — from email addresses and cookies to payment information and health records.
This tool generates privacy policy templates tailored to your business type, data practices, and applicable regulations. While generated policies should be reviewed by legal counsel before publication, they provide a comprehensive starting point that covers required disclosures for major privacy regulations.
| Regulation | Jurisdiction | Key Requirements | Penalty |
|---|---|---|---|
| GDPR | EU/EEA | Lawful basis, data subject rights, DPO, 72h breach notification | Up to 4% of global revenue or EUR 20M |
| CCPA/CPRA | California, USA | Right to know, delete, opt-out of sale, non-discrimination | $2,500-$7,500 per violation |
| PIPEDA | Canada | Consent, purpose limitation, accuracy, access rights | Up to CAD 100,000 per violation |
| LGPD | Brazil | Legal bases, data subject rights, DPO, data protection impact assessment | Up to 2% of revenue or BRL 50M |
| POPIA | South Africa | Consent, purpose limitation, information officer | Up to ZAR 10M or imprisonment |
| UK GDPR | United Kingdom | Mirrors EU GDPR with UK-specific DPA 2018 provisions | Up to GBP 17.5M or 4% of revenue |