A lawful basis is per purpose, not per business
This is the thing nearly every privacy policy template gets wrong, and it is structural rather than cosmetic.
You do not "rely on legitimate interests". You rely on contract to carry out the work somebody ordered. Legal obligation to keep the invoice for six years, because HMRC says so. Consent for the newsletter. Possibly legitimate interests for the camera in the yard.
Four things you do, four different answers. A policy with one lawful basis at the top is describing a business that does one thing, and it is the first thing that falls apart if anybody looks.
So this tool asks per purpose and will not let a purpose exist without one.
Article 13 is a list and two items always go missing
The requirement is not vague. It is an enumerated list, and you can check a policy against it in five minutes. The two that disappear from shortened templates are always the same:
- The retention period. Article 13 wants the period, or the criteria used to determine it. "As long as necessary" is neither, and it is the most common filler in the genre. A real answer is "six years after the job, because that is how long a claim can be brought", and it takes no longer to write.
- The lawful basis. Covered above. It goes missing because it cannot be written once and reused, which is exactly what a template is for.
An inaccurate policy is worse than a short one
A generated policy that mentions cookies you do not set, international transfers you do not make, and a data protection officer you have never appointed is a document about somebody else's business with your name at the bottom.
It is also the first thing read back to you if anybody ever complains, and being unable to recognise your own published policy is a bad position to argue from.
Every section here comes off a question you answered. Nothing is included by default, which is why a small business ends up with a shorter document than the generators produce, and a more truthful one.
Three answers people get wrong by reflex
"Nothing leaves the UK." Probably it does. Ordinary cloud email, cloud accounting, website hosting and offsite backup very often store data abroad. Doing it is fine. Not mentioning it is not, because both the transfer and the safeguard are Article 13 items.
"We have a DPO." Almost no small business needs one. It is required for public authorities and for large scale monitoring or special category processing. If you have not appointed one, do not publish a document that says you have.
"We rely on legitimate interests." That one comes with homework. You have to identify the interest, show the processing is necessary for it, and balance it against the rights of the person whose data it is. That balancing test is meant to be written down somewhere, and the ICO will ask to see it.
What consent requires
If you pick consent, it has to be capable of being withdrawn, and withdrawing has to be as easy as giving.
A pre-ticked box is not consent. Silence is not consent. "By using this website you agree" is not consent. And if unsubscribing means emailing somebody and waiting for them to get round to it, you do not have a working mechanism.
Where another basis genuinely fits the activity, it is usually the sturdier choice, because it cannot be withdrawn from underneath you.
The paywall, which is the actual complaint
The problem with free privacy policy generators is rarely the wording. It is that you answer twenty questions, see a preview with the useful half greyed out, and discover the download is the paid step.
This one produces the whole document, on screen and as a PDF, for nothing, with no account and no email address. That is not a promotion. There is no paid tier for it to be a promotion for.
Common questions
What has to be in a UK privacy policy?
Article 13 of the UK GDPR is a list, and it is short enough to check against. Who you are and how to contact you. What you do with personal data and why. Your lawful basis. How long you keep it. Who else sees it. Whether it leaves the UK and what protects it if so. The rights people have. The right to complain to the ICO. Automated decision making, if you do any. This page produces one section per item and prints the Article beside each.
What is a lawful basis and do I need one?
Yes, and here is the thing almost every template gets wrong: you need one per purpose, not one for the business. You rely on contract to carry out the work somebody ordered, legal obligation to keep the invoice for six years, and consent for the newsletter. Three activities, three bases. A policy with a single lawful basis at the top is describing a business that only does one thing.
Can I just say I keep data "as long as necessary"?
No. Article 13 wants the period, or the criteria you use to work it out, and "as long as necessary" is neither. It is the commonest filler in a template policy. A real answer looks like "six years after the job, because that is how long a claim can be brought" and it takes about as long to write.
Do I need a data protection officer?
Almost certainly not. It is required for public authorities and for organisations doing large scale monitoring or large scale special category processing, which is not most small businesses. That matters here because most templates include a DPO section by default, so you end up publishing a document naming a role you have never appointed. Naming somebody who does not exist is worse than saying nothing.
Does my data leave the UK?
Probably, and most people say no by reflex. Ordinary cloud email, cloud accounting software, website hosting and offsite backups very often store data outside the UK. It is not a problem to do it. It is a problem not to mention it, because the transfer and the safeguard you rely on are both Article 13 items.
Is a free privacy policy generator any good?
The usual problem is not the wording, it is the paywall: you answer twenty questions, see a preview, and the download is the paid step. The second problem is that generated policies describe a generic business rather than yours, so they mention cookies you do not set and transfers you do not make. This one downloads in full for nothing, and includes only the sections your answers produced.
Do I need to register with the ICO?
Most controllers do, and it is an annual fee rather than an application. The ICO runs its own free self-assessment that tells you whether you have to pay and how much, which takes about ten minutes and is not something this site would try to replicate.