Privacy Policy Generator for small businesses
Written for a website, a contact form, a mailing list and a card machine - and nothing more elaborate.
The best small-business privacy policy is a short, specific one. It names the handful of things you actually do with personal data, states real retention periods, and does not describe a compliance function you do not have.
Small businesses are subject to the same transparency obligations as large ones, and they usually meet them with a copied policy that describes a company they are not. The result is a document that names cookies the site does not set, promises procedures nobody runs, and misses the one thing the business actually does with personal data.
The realistic processing set for a small business is short: enquiries through a form or an inbox, a customer list for invoicing, a mailing list if there is one, card payments through a terminal or gateway, and a website with analytics. Describing those five things accurately produces a better document than any template.
The obligations people underestimate are the ones outside the privacy policy: the ICO registration fee in the UK, retention of accounting records, and the fact that CCTV on business premises is processing with its own signage and access requirements.
What a privacy policy for a small business has to cover
Enquiries: what is collected, why, and how long it is kept
Customer and invoicing records with the statutory retention period
Mailing list processing and the consent basis behind it
Payment provider and website host as recipients
CCTV where you operate it, with retention and access
How a small business actually moves personal data
Enquiries by form, email and phone
Name and contact details held in an inbox indefinitely unless someone decides otherwise.
Customer records and invoicing
Held in accounting software, retained for statutory periods.
Mailing lists
Often built informally from customers and enquiries, with no consent record behind them.
Card payments
Through a terminal or online gateway, with the provider handling card data.
Website analytics
Usually Google Analytics, installed once and never revisited.
CCTV on premises
Processing of images of identifiable people, with signage and retention duties attached.
Third parties the draft will ask you about
Xero, QuickBooks or Sage · SumUp, Zettle or Stripe · Google Workspace or Microsoft 365 · Mailchimp · a website host · a CCTV provider
The rules that apply
Transparency regardless of size
No small-business exemption in UK or EU data protection law. The obligations follow the processing.
ICO registration in the UK
Most businesses processing personal data by automated means must pay the annual data protection fee.
Marketing consent rules
PECR and equivalents apply to a mailing list of fifty as much as to one of fifty thousand.
CCTV and premises monitoring
Processing with its own signage, retention and subject access implications.
Accounting record retention
Statutory periods that justify keeping some customer data after the relationship ends.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
A realistic small-business checklist
List what you actually collect
Enquiries, customers, mailing list, payments, website, CCTV. Five or six lines.
Write the policy from that list
Rather than editing someone else’s.
Pay the ICO fee if you are UK-based
And set an annual reminder.
Fix the mailing list
Suppress anything you cannot evidence and re-collect consent.
Add a cookie notice if you run analytics
And make it actually block until consent.
Set retention for enquiries and CCTV
And apply it.
Where this usually goes wrong
A copied policy describing tools you do not use
The most common small-business failure, and easy for anyone to spot.
A mailing list built without consent records
Adding customers to a newsletter because they bought something is only permitted under narrow soft opt-in conditions.
Not paying the ICO fee
A separate legal duty from anything in the policy, checked against a public register.
Enquiry emails kept forever
There is no purpose after the enquiry is closed and any follow-up window has passed.
CCTV with no notice or retention rule
Signage is required, and footage kept indefinitely is difficult to justify.
Analytics running with no cookie notice
A small site with GA4 and no banner is the single most common finding in the UK.
Frequently asked questions
Does a small business need a privacy policy?
Yes if it processes personal data, which a contact form or a customer list already does. There is no exemption based on size or turnover in the UK or EU.
Do I need to register with the ICO?
Most UK businesses processing personal data by automated means do. The fee is tiered by size and turnover and is enforced separately from other obligations.
Can I email past customers about offers?
Only under the soft opt-in - your own similar products, to someone who bought from you, with an opt-out offered at the time and in every message - or with consent.
Do I need a cookie banner for a small website?
If it runs analytics or any third-party embed, in the UK and EU yes, and it needs to hold those tags until consent is given.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator for small businesses
Answer a short questionnaire and get a draft written for a small business. Free to start, no card required.
Generate your privacy policyOther documents a small business needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.