Answer a few questions and get a ready-to-use privacy policy and terms of service — required by Google, Apple and the law. Copy or download, no sign-up.
Templates for general guidance, not legal advice. Review before publishing.
UK GDPR does not require a document called a privacy policy. It requires that you tell people certain things about what you do with their data, in clear language, at the point you collect it. A privacy policy is simply the usual way of doing that.
You must tell people:
Every use of personal data needs one of six lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Most small businesses rely on contract for fulfilling orders, legal obligation for keeping accounts, and legitimate interests for things like fraud prevention.
Consent is the hardest basis to rely on, not the easiest. It must be freely given, specific, informed and as easy to withdraw as to give. Pre-ticked boxes are not consent, and neither is burying it in terms and conditions.
Most organisations processing personal data must pay the ICO data protection fee, which is tiered by size and turnover — the lowest tier costs £40 a year. There are exemptions, including for some processing limited to staff administration, accounts and marketing your own goods. The ICO publishes a self-assessment tool that takes a couple of minutes.
Cookies are governed by PECR, not just UK GDPR. Non-essential cookies — analytics and advertising — need consent before they are set, not after. A banner that drops analytics on page load and then asks permission is not compliant, however carefully the policy is written.
A generated policy is a solid starting point that covers the standard requirements. If you handle health data, children’s data, or transfer data outside the UK at scale, get it reviewed.
If you collect any personal data — including names and email addresses — UK GDPR requires you to tell people what you do with it. A privacy policy is the standard way of meeting that duty.
One of six legal grounds for using personal data: consent, contract, legal obligation, vital interests, public task, or legitimate interests. You need one for each purpose and should state it in your policy.
Most organisations processing personal data must pay the data protection fee, starting at £40 a year. The ICO has a short self-assessment tool to check whether an exemption applies.
Non-essential cookies need consent before they are set, under PECR. Strictly necessary cookies do not.