Privacy Policy Generator EU
EU GDPR, the ePrivacy Directive as implemented locally, and the one-stop-shop - with the right lead authority named.
An EU privacy policy is judged against Articles 13 and 14 line by line. The two clauses that most often fail are the transfer disclosure - which has to name a mechanism per destination rather than gesture at "appropriate safeguards" - and the complaint route, which has to point at a real supervisory authority.
EU compliance is not one regime but one regulation applied by twenty-seven authorities, plus national laws that fill the gaps GDPR deliberately left. The cookie rules in particular are national: the ePrivacy Directive is implemented by the TDDDG in Germany, by the Loi Informatique et Libertés and CNIL guidelines in France, by Article 22.2 LSSI in Spain and by the Telecommunicatiewet in the Netherlands.
If you are established in more than one member state, the one-stop-shop mechanism gives you a lead supervisory authority based on your main establishment. That authority is the one to name. If you are established nowhere in the EU but target EU users, there is no lead authority - every national regulator can act, and Article 27 requires you to appoint an EU representative.
The regulatory surface has widened well beyond GDPR. The Digital Services Act imposes notice-and-action and transparency duties on anyone hosting user content, the AI Act layers transparency obligations onto systems that interact with people, and the Data Act adds switching and access rights for connected products and cloud services.
What a privacy policy in the EU has to cover
Controller identity plus, where you are outside the EU, the Article 27 representative’s name and EU address
Lawful basis per purpose, with the Article 9(2) condition wherever special category data is involved
Recipients by category and, for material ones, by name - hosting, payments, analytics, support
Transfer mechanism per destination: adequacy, the EU-US Data Privacy Framework, or the 2021 SCCs with a transfer impact assessment
The right to lodge a complaint with a supervisory authority, with the lead authority named if you have one
Automated decision-making under Article 22 is the clause most often left out. If you score, rank or reject users algorithmically - credit checks, fraud scoring, automated moderation - the notice has to say so and explain the logic involved.
How the EU actually moves personal data
Cross-border customer data inside the EEA
Intra-EEA movement is not a "transfer" and needs no Chapter V mechanism, but it does need the recipient categories disclosed and, where a group company is involved, a controller-to-controller or Article 26 joint-controller arrangement.
Transfers to the United States
Certified importers can be covered by the EU-US Data Privacy Framework; everyone else needs the 2021 SCCs plus a transfer impact assessment that engages with US surveillance law rather than asserting adequacy.
Consent signals under the TCF
If you sell programmatic advertising you are likely inside the IAB Transparency and Consent Framework, which brings its own vendor list, purpose taxonomy and string format that the policy has to reflect.
Special category data by accident
Health-adjacent apps, dietary preferences, trade union membership in payroll and political affiliation in CRM records all trigger Article 9 and need a condition from Article 9(2), not just a basis from Article 6.
Employee monitoring and works councils
In Germany, Austria and the Netherlands, monitoring tools frequently require works council agreement before deployment, independently of the GDPR basis.
Third parties the draft will ask you about
Stripe · Adyen · Mollie · Klarna · Google Analytics 4 · Matomo · Brevo · AWS eu-central-1 · OVHcloud · Hetzner
The rules that apply
GDPR (Regulation 2016/679)
Articles 13 and 14 for the notice, Article 6 for the basis, Article 30 for the internal record, and Chapter V for transfers out of the EEA.
ePrivacy Directive, as implemented nationally
Consent for storing or accessing information on a device. The rule is European, the implementation and the enforcement thresholds are national.
One-stop-shop and Article 27
A lead authority if you have an EU establishment; an appointed EU representative and exposure to every authority if you do not.
Consumer Rights Directive and the Omnibus Directive
Fourteen-day withdrawal on distance sales, plus disclosure duties on ranking, reviews and personalised pricing.
Digital Services Act
Published terms, a notice-and-action mechanism, statement-of-reasons for moderation decisions and an internal complaints route for anyone hosting third-party content.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Getting an EU-facing policy right
Establish whether you have a main establishment
It determines whether you get a lead authority or face all twenty-seven. Where central decisions about processing are actually taken is the test, not where the company is registered.
Appoint an Article 27 representative if you are outside the EU
Required for most non-EU businesses targeting EU users. The representative’s name and address go in the privacy policy.
Set the age of digital consent per market
It ranges from 13 to 16 across member states. If you serve minors, the age gate has to be country-aware.
Document transfer impact assessments
One per destination country and vendor, referencing the actual legal environment, kept on file for the regulator rather than summarised in the notice.
Map DSA duties if you host user content
Notice-and-action, statements of reasons and an internal complaint system are separate obligations from anything in GDPR.
Where this usually goes wrong
Naming "the EU supervisory authority" instead of a real one
There is no such body. Users must be told they can complain to their own national authority, and if you have a lead authority you should name it.
Assuming the Data Privacy Framework covers every US vendor
It covers only organisations that have actively self-certified and remain on the list. Most smaller US SaaS vendors have not, which leaves you on SCCs plus a transfer impact assessment.
A cookie banner that pre-ticks or infers consent
The Planet49 ruling settled this: pre-ticked boxes are not consent, and continued scrolling is not consent. Several national regulators treat it as an automatic finding.
Ignoring national add-ons
Germany requires an Impressum, France requires mentions légales, and several member states set their own age of digital consent between 13 and 16. A pure GDPR document misses all of it.
Legitimate interests for advertising without an assessment
The EDPB and the courts have narrowed this repeatedly. Behavioural advertising on legitimate interests, with no documented balancing test, is the pattern that produced the largest recent fines.
Frequently asked questions
Does GDPR apply to my business if I am not in the EU?
Yes, if you offer goods or services to people in the EU or monitor their behaviour. Article 3(2) turns on where the person is. Accepting euros, shipping to EU addresses or running EU-targeted ads are the facts regulators look at.
Which supervisory authority do I name?
If you have an EU main establishment, your lead authority. If not, tell users they may complain to the authority in their own member state, and name your Article 27 representative.
Is one policy enough for all 27 member states?
For GDPR, generally yes. For cookies, marketing, minors and consumer terms it needs national variations, because those are governed by national implementations rather than the regulation itself.
Do I need an EU representative?
If you are established outside the EU and Article 3(2) catches you, yes - unless your processing is occasional, low-risk and excludes special category data. Most e-commerce and SaaS businesses do not fit that exemption.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator EU
Answer a short questionnaire and get a draft written for the EU. Free to start, no card required.
Generate your privacy policyOther documents for the EU
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.