GDPR (EU & UK)

GDPR Privacy Policy Generator

If you have a single EU or UK visitor, GDPR applies. Generate a fully GDPR-compliant policy in under a minute.

Free · No signup · PDF & DOCX export · GDPR / CCPA / UK / CA / AU / LGPD / DPDP

No account or signup required
GDPR & CCPA clauses included
Clauses for AI tools & SaaS
Free PDF & DOCX export
Page last updated · May 2026

The GDPR has the broadest reach of any privacy law — it applies to any business worldwide that handles EU/UK personal data. Our generator covers all required disclosures: legal basis, data subject rights, transfers, and retention.

What's included

  • Lawful basis for processing (Article 6)
  • All data subject rights (Articles 15–22)
  • International data transfer disclosures
  • Retention periods
  • DPO and EU representative fields
  • UK GDPR + EU GDPR coverage

Why you need this

  • Fines up to €20M or 4% of global revenue
  • Required for any site with EU/UK visitors
  • Required by Stripe, Mailchimp, and most SaaS
  • Demonstrates accountability under Article 5(2)

What GDPR Articles 13 and 14 actually require

The GDPR does not ask for a 'privacy policy' by name — it lists information you must give people when you collect their data. That list is concrete, which is good news: you can check your document against it line by line. Missing a lawful basis or omitting retention periods are the two most common gaps.

  • Identity and contact details of the controller (and DPO or EU representative if you have one)
  • Purposes of processing and the lawful basis for each
  • Recipients or categories of recipients
  • Transfers outside the EEA and the safeguard relied on
  • Retention periods, or the criteria used to set them
  • Data subject rights, including withdrawal of consent and complaints to a supervisory authority
  • Whether automated decision-making with legal or similarly significant effects takes place

Consent, legitimate interests, and cookie banners

Analytics and advertising cookies generally require consent under the ePrivacy rules before they are set, which is a separate requirement from the policy itself. A policy that describes cookies while the site drops them on load is a mismatch regulators notice. Pair the document with a consent tool, and make sure declining is as easy as accepting.

Not legal advice. PolicyGenie is a self-help document tool, not a law firm. The templates and articles here are general information only and may not fit your circumstances or reflect the most recent changes in the law. Review anything you publish, and get advice from a qualified lawyer in your jurisdiction if your business handles sensitive data or operates in a regulated industry. See our full disclaimer.

Advertisement

Generate your policy now

Free • PDF & DOCX • No signup

Start the generator

Frequently asked questions

Everything you need to know before publishing your policy.