Privacy Policy Generator
Generate a privacy policy covering GDPR, UK GDPR and CCPA: data collected, legal basis, retention, processors and data subject rights. Free, no signup.
Last reviewed by the Radiatus Cloud team
Privacy Policy Generator
Generate a basic privacy policy for your website.
Want this done for your business?
Radiatus delivers cloud, security & automation for growing teams.
A privacy policy is a factual disclosure
A privacy policy describes what your organisation actually does with personal data. Generators get a bad reputation because they produce something that reads well and describes nothing real. This one is structured around the disclosures GDPR Articles 13 and 14 require, and it asks you what you actually collect rather than assuming a template.
The sections that matter
Identity and contact details of the controller. The categories of personal data you collect and where they come from. The purpose of each processing activity and the lawful basis you rely on for it. Who you share data with, including named processors. Whether data leaves the country and under what transfer mechanism. How long you keep each category. The data subject rights available and how to exercise them. The right to complain to a supervisory authority.
Legal basis is per purpose, not per site
The most common defect in a generated policy is claiming a single legal basis for everything. In practice a typical site relies on several: contract for delivering the service a customer signed up for, legitimate interests for security logging and fraud prevention, consent for marketing email and non-essential cookies, and legal obligation for retaining invoices. Stating the basis per purpose is what makes a policy credible, and it is what a regulator will look for first.
Name your processors
Vague references to "trusted third parties" are not adequate. If you use a specific analytics provider, email service, payment processor or hosting company, name it and say what it receives. The generated policy produces a processor table for exactly this. It also prompts you for international transfers, because if your processors are outside the EEA you need to state the safeguard you rely on, such as Standard Contractual Clauses or an adequacy decision.
Retention periods
"As long as necessary" is not a retention period. GDPR expects either a defined duration or the criteria used to determine it. Being concrete here is genuinely useful internally too, since it forces a decision about when data actually gets deleted.
This is a starting point
A generated policy is a structured first draft that captures the required disclosures. It is not legal advice, and it cannot know your internal practices. If you process special category data, handle children's data, operate in multiple jurisdictions, or make automated decisions with legal effects, have a practitioner review the result.
Related tools
- Incident Impact Calculator — Estimate the cost of a security incident from severity, affected users and downtime hours, with a compliance and trust rating and the response actions each severity level demands.
- Third-Party Risk Assessor — Assess vendor risk based on data access and type.
- Data Breach Cost Estimator — Estimate what a data breach would cost from records exposed, cost per record, days to detect and hours of downtime, split into direct and indirect costs.
- SaaS Risk Heatmap — Pick the SaaS apps your company runs, add your own, and get a heatmap ranking each by data criticality times access scope, with the risk each carries.
Frequently Asked Questions
Is a generated privacy policy legally valid?
A privacy policy is valid when it accurately describes what you do. A generator gives you the correct structure and prompts for the required disclosures, but accuracy depends entirely on the answers you provide. It is a solid first draft, not a substitute for review if your processing is complex.
Do I need a privacy policy for a small personal site?
If you collect any personal data, including via a contact form, analytics or server logs that retain IP addresses, then yes under GDPR. Server logs alone are enough to trigger the requirement, which surprises most site owners.
What is the difference between a privacy policy and a cookie policy?
The privacy policy covers all personal data processing: accounts, forms, payments, support, marketing. The cookie policy covers what is stored on the visitor's device specifically, with a per-cookie table. They overlap but serve different disclosure requirements, and it is common to keep them as separate linked pages.
Do I need to name every third-party service?
You need to identify recipients or at minimum the categories of recipients, and regulators increasingly expect named processors. Naming them is clearer for users and easier to keep accurate than a vague category list.
How do I handle international data transfers?
State which processors are outside the EEA or UK and what safeguard applies, usually Standard Contractual Clauses or an adequacy decision such as the EU-US Data Privacy Framework. The generator includes a transfers section that prompts for this.
How often should I update it?
Whenever your processing changes: a new analytics tool, a new payment provider, a new marketing channel. Also review annually. Material changes affecting how you use existing data should be communicated to users, not just quietly published.
Privacy & Security
Local processing.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Incident Impact Calculator
BusinessEstimate the cost of a security incident from severity, affected users and downtime hours, with a compliance and trust rating and the response actions each severity level demands.
Third-Party Risk Assessor
BusinessAssess vendor risk based on data access and type.
Data Breach Cost Estimator
BusinessEstimate what a data breach would cost from records exposed, cost per record, days to detect and hours of downtime, split into direct and indirect costs.