Free Privacy Policy Generator for UK Small Business Websites
Generate a plain-English privacy policy covering UK GDPR essentials: what you collect, why, how long you keep it, and users' rights.
Free plan includes 30 credits, no card required
Documents are AI-generated drafts for you to review before use. Vizivo doesn't provide legal, financial or other professional advice.
What the generator produces
A UK GDPR privacy policy in plain English, covering what the regulation actually requires you to tell people:
| Section | What it covers |
|---|---|
| Who we are | Your business as data controller, and how to contact you |
| What we collect | The categories of personal data, tied to how your site collects them |
| Why, and our lawful basis | UK GDPR requires a lawful basis for each purpose, not simply a reason |
| Who we share it with | Your processors: email tools, analytics, payment providers, hosting |
| How long we keep it | Retention periods, rather than "as long as necessary" |
| Your rights | Access, correction, erasure, portability, objection, and how to exercise them |
| Cookies | What you set and how visitors control them, which is PECR rather than UK GDPR |
| Complaints | The right to complain to the ICO, with their details |
What it asks you
What your website does, what it collects (contact forms, mailing list, orders, accounts), which third-party tools you use, whether you run analytics or advertising cookies, and how long you keep records. Your business details come from your Business Memory.
The third-party question is the one people underestimate. Every tool that touches personal data, from your email provider to your analytics, is a processor you are expected to disclose.
What comes out
A formatted policy you can publish, export as PDF or Word, and revisit whenever you add a tool that collects something new. It costs 5 credits, and the free plan includes 30 a month.
What it does not do
It does not give legal advice, and it does not replace a professional review if you process special category data, children's data, or personal data at scale.
It also does not build your cookie banner. A policy explains what you collect; the banner is how you obtain consent before non-essential cookies are set. Most UK sites running analytics need both.
The ICO publishes plain-English guidance and runs a small business helpline, and it is genuinely good. If you want to work out whether you need a policy at all, our guide on UK privacy policies covers that.
Questions
- Is this legal advice?
- No. It is a strong, well-structured first draft. Have a professional review it if your data processing is complex.
- Does it cover cookies?
- Yes, a cookies section is included when you tell it your site uses them. The policy is not the same as a cookie banner though: most UK sites running analytics need both.
- Does a small UK website really need a privacy policy?
- If it collects any personal data, yes. A contact form, an email signup or analytics cookies all count as processing personal data under UK GDPR, which requires you to tell people what you collect and why.
- Can I copy a privacy policy from another website?
- It is a poor idea. The policy has to describe what your site actually collects, which tools you use and how long you keep data. A copied policy describes someone else's processing, which is worse than useless if a customer or the ICO asks.
- How often should I update it?
- Whenever you add something that collects or shares personal data: a booking widget, a chat box, a new email tool. The policy is meant to describe what you do now, not what you did at launch.
- How long does it take?
- A few minutes. The generator asks what your site collects and which tools you use, and takes your business details from your profile.