By business type

Privacy Policy Generator for small businesses

Written for a website, a contact form, a mailing list and a card machine - and nothing more elaborate.

Generate your privacy policy Read the privacy policy guide

The best small-business privacy policy is a short, specific one. It names the handful of things you actually do with personal data, states real retention periods, and does not describe a compliance function you do not have.

Small businesses are subject to the same transparency obligations as large ones, and they usually meet them with a copied policy that describes a company they are not. The result is a document that names cookies the site does not set, promises procedures nobody runs, and misses the one thing the business actually does with personal data.

The realistic processing set for a small business is short: enquiries through a form or an inbox, a customer list for invoicing, a mailing list if there is one, card payments through a terminal or gateway, and a website with analytics. Describing those five things accurately produces a better document than any template.

The obligations people underestimate are the ones outside the privacy policy: the ICO registration fee in the UK, retention of accounting records, and the fact that CCTV on business premises is processing with its own signage and access requirements.

What a privacy policy for a small business has to cover

How a small business actually moves personal data

Enquiries by form, email and phone

Name and contact details held in an inbox indefinitely unless someone decides otherwise.

Customer records and invoicing

Held in accounting software, retained for statutory periods.

Mailing lists

Often built informally from customers and enquiries, with no consent record behind them.

Card payments

Through a terminal or online gateway, with the provider handling card data.

Website analytics

Usually Google Analytics, installed once and never revisited.

CCTV on premises

Processing of images of identifiable people, with signage and retention duties attached.

Third parties the draft will ask you about

Xero, QuickBooks or Sage · SumUp, Zettle or Stripe · Google Workspace or Microsoft 365 · Mailchimp · a website host · a CCTV provider

The rules that apply

Transparency regardless of size

No small-business exemption in UK or EU data protection law. The obligations follow the processing.

ICO registration in the UK

Most businesses processing personal data by automated means must pay the annual data protection fee.

Marketing consent rules

PECR and equivalents apply to a mailing list of fifty as much as to one of fifty thousand.

CCTV and premises monitoring

Processing with its own signage, retention and subject access implications.

Accounting record retention

Statutory periods that justify keeping some customer data after the relationship ends.

What the generated privacy policy contains

A realistic small-business checklist

  1. List what you actually collect

    Enquiries, customers, mailing list, payments, website, CCTV. Five or six lines.

  2. Write the policy from that list

    Rather than editing someone else’s.

  3. Pay the ICO fee if you are UK-based

    And set an annual reminder.

  4. Fix the mailing list

    Suppress anything you cannot evidence and re-collect consent.

  5. Add a cookie notice if you run analytics

    And make it actually block until consent.

  6. Set retention for enquiries and CCTV

    And apply it.

Where this usually goes wrong

A copied policy describing tools you do not use

The most common small-business failure, and easy for anyone to spot.

A mailing list built without consent records

Adding customers to a newsletter because they bought something is only permitted under narrow soft opt-in conditions.

Not paying the ICO fee

A separate legal duty from anything in the policy, checked against a public register.

Enquiry emails kept forever

There is no purpose after the enquiry is closed and any follow-up window has passed.

CCTV with no notice or retention rule

Signage is required, and footage kept indefinitely is difficult to justify.

Analytics running with no cookie notice

A small site with GA4 and no banner is the single most common finding in the UK.

Frequently asked questions

Does a small business need a privacy policy?

Yes if it processes personal data, which a contact form or a customer list already does. There is no exemption based on size or turnover in the UK or EU.

Do I need to register with the ICO?

Most UK businesses processing personal data by automated means do. The fee is tiered by size and turnover and is enforced separately from other obligations.

Can I email past customers about offers?

Only under the soft opt-in - your own similar products, to someone who bought from you, with an opt-out offered at the time and in every message - or with consent.

Do I need a cookie banner for a small website?

If it runs analytics or any third-party embed, in the UK and EU yes, and it needs to hold those tags until consent is given.

Is a privacy policy legally required?

If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.

Can I copy another company’s privacy policy?

It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.

How often does a privacy policy need updating?

Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.

Does PolicifyAI give legal advice?

No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.

Privacy Policy Generator for small businesses

Answer a short questionnaire and get a draft written for a small business. Free to start, no card required.

Generate your privacy policy

Other documents a small business needs

Each one is written for the same context, not a generic template.

The same document, by business type

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.