GDPR Policy Generator

GDPR compliance is not one document. It is a public transparency notice plus an internal record that proves the notice is honoured - the lawful basis register, the Article 30 records, the rights procedure and the breach plan. This generator produces that set, for EU GDPR or UK GDPR, with the correct supervisory authority named rather than a generic reference.

Generate now See pricingRead the full guide

What's included in every draft

Quality verification

Every document is verified for accuracy, completeness, and jurisdiction-specific requirements before delivery.

Jurisdiction-aware

180 jurisdictions including GDPR, UK GDPR, CCPA/CPRA, LGPD, PIPL, PDPA, PIPEDA, POPIA.

120+ languages

Translate policies into the languages your users actually read, with terminology tuned to local law.

Who needs this policy

Businesses outside the EU with EU customers

Article 3(2) turns on where the person is, not where you are. Selling to EU customers or monitoring their behaviour brings you into scope and usually requires an Article 27 representative.

SaaS companies answering security questionnaires

Enterprise procurement asks for the DPA, the sub-processor list, the breach commitment and evidence of Article 30 records. Having them ready is a sales advantage, not just a compliance one.

Agencies handling client customer data

Processing on a client’s instructions requires a written Article 28 agreement. Most agency contracts do not have one, and it surfaces during the client’s own audit.

Companies preparing for an ICO or DPA enquiry

A regulator opening a file asks for the records of processing first. Reconstructing them after the request is significantly harder than maintaining them.

Jurisdiction coverage

EU GDPR (Regulation 2016/679)

The full Chapter III rights set, Chapter IV accountability duties and Chapter V transfer rules, with the one-stop-shop position addressed: a named lead supervisory authority where you have an EU main establishment, and an Article 27 representative where you do not.

UK GDPR and the Data Protection Act 2018

The UK regime has diverged. Output references the ICO rather than the EDPB, the International Data Transfer Agreement or the UK Addendum rather than the EU SCCs alone, and the amendments made by the Data (Use and Access) Act 2025.

National implementations

GDPR left dozens of opening clauses for member states. The draft can reflect German BDSG rules on employee data and the mandatory DPO threshold, French CNIL retention référentiels, and the digital age of consent, which ranges from 13 to 16 across the bloc.

ePrivacy and cookies

Cookie consent is governed separately - by PECR in the UK, the TDDDG in Germany, CNIL guidelines in France and equivalent national laws elsewhere. The GDPR set references those rules rather than folding them into Article 6.

How it works in five minutes

  1. Describe your processing

    Purposes, data categories, recipients, retention and where data goes. This is the raw material for both the notice and the internal records.

  2. Choose EU GDPR, UK GDPR or both

    The regulator, the transfer mechanism and the cookie rules differ, and the draft adapts rather than hedging.

  3. Review the generated set

    The public notice and the internal records are produced together, so the two stay consistent with each other.

  4. Publish, file and schedule the review

    The notice goes on the site; the records stay internal. Both need a review date, because accountability is an ongoing obligation.

Frequently asked questions

Is a GDPR policy the same as a privacy policy?

No. The privacy policy is the outward-facing notice required by Articles 13 and 14. The GDPR policy set is the internal machinery - lawful basis register, records of processing, rights procedure, breach plan - that lets you demonstrate the notice is honoured when a regulator asks.

Does GDPR apply if my business is outside the EU?

Yes, where you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) is about the individual’s location. Many businesses in that position also need an Article 27 EU representative.

What is the difference between EU GDPR and UK GDPR?

The texts are close but they are separate laws with separate regulators, separate fine ceilings and separate transfer regimes. The UK also amended its version through the Data (Use and Access) Act 2025, so a document written purely against EU GDPR is behind on UK detail.

Do I need records of processing if I am a small business?

The under-250-employee exemption in Article 30(5) is narrower than it appears: it falls away if processing is not occasional, is likely to result in a risk to rights, or involves special category data. Most businesses processing customer data regularly fall outside it.

How long do I have to report a breach?

72 hours to the supervisory authority from becoming aware, where the breach is likely to result in a risk to individuals - and without undue delay to the individuals themselves where the risk is high.

Versions written for your situation

The law, the platform and the business model all change what a GDPR policy has to say. These 23 pages each cover one of those situations in detail - the specific rules, the data flows involved, and the mistakes that come up most often.

By country

The law, the regulator and the transfer rules change at the border. These pages are written for one jurisdiction each.

By platform

What your platform collects by default, which apps add to it, and where the finished document actually gets published.

By business type

The data flows, contracts and failure modes that are specific to how this kind of business operates.

Ready to draft your gdpr policy?

Answer a short questionnaire. Download, publish, or host with PolicifyAI.

Start now

Last reviewed 16 August 2026.

PolicifyAI is not a law firm and does not provide legal advice. Generated policies are drafting starting points that require review by qualified counsel before publication or reliance.