Policy type
Select the type of policy you need to generate.
92 policies
Privacy Policy
Legally required in 100+ countries. Discloses exactly how you collect, use, store, and protect personal data - covering GDPR, CCPA, UK GDPR, and more.
Cookie Policy
Required under EU ePrivacy Directive and UK PECR. Lists every cookie and tracker on your site, explains their purpose, and documents your consent mechanism.
GDPR Compliance Policy
Comprehensive framework documenting all GDPR obligations - lawful basis mapping, data subject rights procedures, breach response, and DPO requirements.
CCPA Privacy Notice
Required for businesses serving California residents that meet CCPA thresholds. Covers the right to know, right to delete, and opt-out of data sales - updated for CPRA 2023.
Data Processing Agreement
Mandatory under GDPR Article 28 for any B2B data relationship. A legally binding contract between data controllers and processors specifying security measures and sub-processor rules.
Data Retention Policy
Documents how long each category of data is kept and how it is securely deleted. Required under GDPR's storage limitation principle - protects against over-retention fines.
Data Breach Response Policy
A step-by-step incident response plan for data security breaches. Covers detection, containment, authority notification (72-hour GDPR window), and affected-user communication.
HIPAA Privacy Policy
Federally mandated for US healthcare providers and Business Associates handling PHI. Covers patient rights, minimum necessary standard, breach notification, and BAA requirements.
COPPA Policy
Required by US law for any service directed at children under 13. Covers verifiable parental consent, data minimisation, prohibition on behavioural advertising, and safe harbour provisions.
Data Subject Access Request Policy
Defines how individuals can exercise their data rights under GDPR, CCPA, and UK GDPR - covering request submission, identity verification, response timelines (30 days GDPR / 45 days CCPA), and appeal procedures.
Data Transfer Agreement
Required for international transfers of personal data outside the EEA/UK. Incorporates EU Standard Contractual Clauses (SCCs), UK International Data Transfer Agreement (IDTA), and supplementary security measures.
Privacy Impact Assessment
DPIA template required under GDPR Article 35 for high-risk processing - covering data flows, necessity assessment, risk evaluation, and mitigation measures.
Consent Management Policy
Framework for collecting, recording, and managing user consent - covering opt-in mechanisms, granular consent options, withdrawal procedures, and audit trails.
82 more policy types
Create a free account to browse all 92 and generate your first three.
No card required. Sign in