Generate ↓
Free · No sign-up · App-store ready

Free UK GDPR privacy policy

Answer a few questions and get a ready-to-use privacy policy and terms of service — required by Google, Apple and the law. Copy or download, no sign-up.

Templates for general guidance, not legal advice. Review before publishing.

Privacy Policy
Terms of Service

Popular

Privacy policy for app storeFree privacy policy generator Terms of service templateGDPR privacy policyPrivacy policy for website
Recommended next step
Launching your site? Get hosting + a free domain.
You’ve got the legal pages — now put your site online with Hostinger’s fast, affordable hosting.
Get hosting with Hostinger →

What a privacy notice must tell people

UK GDPR does not require a document called a privacy policy. It requires that you tell people certain things about what you do with their data, in clear language, at the point you collect it. A privacy policy is simply the usual way of doing that.

You must tell people:

Lawful basis is the part people skip

Every use of personal data needs one of six lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Most small businesses rely on contract for fulfilling orders, legal obligation for keeping accounts, and legitimate interests for things like fraud prevention.

Consent is the hardest basis to rely on, not the easiest. It must be freely given, specific, informed and as easy to withdraw as to give. Pre-ticked boxes are not consent, and neither is burying it in terms and conditions.

Do you need to register with the ICO?

Most organisations processing personal data must pay the ICO data protection fee, which is tiered by size and turnover — the lowest tier costs £40 a year. There are exemptions, including for some processing limited to staff administration, accounts and marketing your own goods. The ICO publishes a self-assessment tool that takes a couple of minutes.

Cookies are a separate rulebook

Cookies are governed by PECR, not just UK GDPR. Non-essential cookies — analytics and advertising — need consent before they are set, not after. A banner that drops analytics on page load and then asks permission is not compliant, however carefully the policy is written.

A generated policy is a solid starting point that covers the standard requirements. If you handle health data, children’s data, or transfer data outside the UK at scale, get it reviewed.

Common questions

Do I legally need a privacy policy in the UK?

If you collect any personal data — including names and email addresses — UK GDPR requires you to tell people what you do with it. A privacy policy is the standard way of meeting that duty.

What is a lawful basis?

One of six legal grounds for using personal data: consent, contract, legal obligation, vital interests, public task, or legitimate interests. You need one for each purpose and should state it in your policy.

Do I need to register with the ICO?

Most organisations processing personal data must pay the data protection fee, starting at £40 a year. The ICO has a short self-assessment tool to check whether an exemption applies.

Do cookies need consent?

Non-essential cookies need consent before they are set, under PECR. Strictly necessary cookies do not.