How to Write a Privacy Policy (Free Template & Generator)
A practical guide to writing a privacy policy for a small site — what it must include, GDPR vs CCPA, where to link it, and a free generator to start from.
Last updated September 4, 2026 · 10 min read
If you run any kind of website — a hobby blog, a portfolio, a Shopify store, a small SaaS — you almost certainly need a privacy policy. Not because a lawyer told you to, but because the moment you drop in Google Analytics, embed a YouTube video, run AdSense, or add a Mailchimp signup form, you're collecting or transmitting personal data on behalf of a third party. That triggers disclosure requirements in most of the world, and the companies whose scripts you're using contractually require you to have a policy in place.
This guide walks through what a real privacy policy needs to say, how GDPR and CCPA change the picture for small sites, and where the policy actually has to be linked to count. It also points to a free generator that produces a solid starting-point template. To say it plainly upfront: a generated policy is a starting point, not attorney-drafted legal work. It'll get you a structurally correct first draft that covers the standard sections and adapts to what you actually collect, but it can't replace a lawyer who knows your business, your jurisdiction, and your specific data flows. Nothing in this article is legal advice.
When you actually need a privacy policy
Short version: almost always. The bar is lower than most site owners realize.
You need a policy if any of the following are true:
- You use Google Analytics, Plausible with any identifying setup, or any analytics tool that sets cookies or logs IPs.
- You embed AdSense, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, or any ad-network script.
- You have a contact form, comment form, newsletter signup, or account registration.
- You sell anything and process payments (Stripe, PayPal, Shopify Payments — they all pass personal data).
- You embed YouTube, Vimeo, Instagram, Twitter/X, or Facebook widgets (they set cookies on load).
- Your visitors include anyone in the EU, UK, or California — which, if your site is reachable on the open web, is functionally always.
Even a static personal blog that uses only Cloudflare and Google Fonts is arguably in scope, because those services log IP addresses. Practically, the honest answer for most site owners is: assume yes, and get something in place. Google's own policies for AdSense and Analytics explicitly require a privacy policy that discloses their use.
What a privacy policy must include
A workable policy for a small site covers eight standard sections. If any of these are missing, reviewers, regulators, and platform enforcement bots will flag it.
1. What personal data you collect. Be specific. Name the categories: contact information (email, name), account credentials, payment details (usually handled by a processor, not stored by you), usage data (IP, browser, pages viewed), and any data submitted through forms. If you collect nothing beyond what analytics captures, say that.
2. How you collect it. Distinguish between data users give you directly (form submissions, account signups) and data collected automatically (cookies, log files, tracking pixels). Regulators care about this distinction because consent works differently for each.
3. How you use it. Match each data category to a purpose: "email addresses submitted through the newsletter form are used to send the weekly newsletter and nothing else." Vague statements like "to improve our services" are red flags — they're the reason so many policies get called out as meaningless. Concrete is better.
4. Who you share it with. This is where you list every third-party service that receives user data. Google Analytics, Stripe, Mailchimp, Cloudflare, your email host, your CRM, any embed provider. Name them and link to their privacy policies. This list is called your subprocessors, and it's the single section reviewers scrutinize most.
5. Cookies and tracking. A separate section (or a linked cookie policy) explaining what cookies you set, which are essential vs. analytics vs. advertising, and how users can opt out. If you're in scope for GDPR, this ties into your cookie banner.
6. User rights. What people can ask you to do with their data. At minimum: access it, correct it, delete it, and receive a copy. GDPR and CCPA add specific rights beyond these — more on that below.
7. How to contact you. A working email address for privacy requests. privacy@yourdomain.com is the convention. A contact form alone isn't enough; regulators want a direct channel.
8. Effective date and update policy. When the current version took effect, and a sentence about how you'll notify users of material changes. Keeping an internal changelog is smart — if a regulator or user asks when you added a specific clause, you'll want a record.
Some jurisdictions add more: GDPR wants a lawful basis for each processing purpose, retention periods, and information about international data transfers. CCPA wants a specific "Do Not Sell or Share My Personal Information" section if you sell or share for advertising. The generator below adapts based on which regions you tick.
GDPR vs. CCPA vs. a general baseline
Three different regulatory frames matter for small sites. You'll typically need to cover more than one.
GDPR (EU and UK visitors). The strictest of the three. Requires a specific lawful basis for every processing purpose (consent, contract, legitimate interest, legal obligation, vital interests, or public task). Gives users the right to access, correct, delete, restrict, port, and object to processing, plus the right to complain to a supervisory authority. Requires a Data Protection Officer in some cases (large-scale monitoring, sensitive data). Consent must be opt-in, granular, and as easy to withdraw as to give — pre-ticked boxes and cookie walls generally don't qualify. If any of your visitors are in the EU or UK, you're in scope, regardless of where you're based.
CCPA/CPRA (California visitors). Grants access, deletion, correction, and portability rights, plus the specific right to opt out of the sale or sharing of personal information for cross-context behavioral advertising. If you run any ad network that uses tracking data to build audiences (AdSense, Meta Pixel, most retargeting), you're likely "sharing" under CCPA and need a visible "Do Not Sell or Share" link and a mechanism to honor it — including Global Privacy Control signals. Applies to for-profit businesses meeting a size threshold, but many small sites meet it via the "50,000 California consumers per year" bar.
A general baseline. For visitors in Canada (PIPEDA), Brazil (LGPD), Australia (Privacy Act), and most of the rest of the world, a general policy covering the eight sections above with reasonable defaults will handle the standard cases. It won't make you fully compliant in every specific regime, but it establishes disclosure, gives users a channel to exercise their rights, and shows good faith.
For most small site owners the sensible default is: cover GDPR + CCPA + general baseline, on the same page, and let a lawyer trim once you know your real user distribution. That's what the generator defaults to.
The three places a privacy policy has to be linked
A policy nobody can find doesn't count. Three placements are non-negotiable:
- Footer of every page. A persistent link in the site footer is the standard convention and what regulators check for. Label it plainly: "Privacy Policy" or "Privacy." Not "Legal" as a dropdown, not buried under an About page.
- Every form that collects personal data. Under the signup form, the contact form, the newsletter box, the account registration. A short line near the submit button: "By signing up, you agree to our [Privacy Policy]." This creates the contract moment where the user acknowledges the terms.
- The cookie banner. If you use one (and if you're in EU scope you should), the banner needs a link to the full policy and to a cookie policy if you have a separate one.
Missing any of these is the most common enforcement trigger for small sites — it's the easiest thing for a regulator or complainant to check.
Skip the writing: use the free privacy-policy generator
Writing a policy from scratch means either paying $200-$500 for a template site's premium tier, or spending a full afternoon adapting someone else's policy (which, as noted below, is a bad idea). The free alternative: the privacy-policy generator on this site.
You enter your business name and URL, tick which data-collection categories apply (contact forms, analytics, cookies, newsletter, payments, third-party embeds), and choose your region coverage — GDPR, CCPA, both, or general. The generator assembles a plain-language template with only the sections you need. If you didn't tick "cookies," the cookie clauses don't appear. If you picked GDPR-only, the CCPA "Do Not Sell" section is left out.
The output is broken into numbered sections you can copy straight into a Privacy Policy page. You still need to fill in your specific subprocessors, your business address, your privacy contact email, and any retention periods you commit to. The generator does the structural and language work; the specifics are yours.
Again, and this bears repeating: this is not legal advice, and the output is not attorney-drafted. It's a starting template designed to cover the standard sections most policies share. For a hobby blog or side project, that's often enough. For anything meaningful — a real business, a paying customer base, sensitive data — treat it as a first draft to hand to counsel.
If you also need a terms disclaimer for opinion or advice content, the disclaimer generator covers that separately. If you're selling subscriptions or services, the cancellation policy generator produces a matching cancellation and refund policy that pairs with the privacy policy in your site footer.
When it's worth spending money on an attorney
A generated template genuinely isn't enough in several cases. If any of these apply, budget for real legal help:
- Health data. Anything touching HIPAA in the US, medical information under GDPR's special categories, or similar in other regimes. The compliance surface is much larger than a standard policy.
- Kids under 13. COPPA in the US and GDPR-K in the EU add specific consent, disclosure, and parental rights requirements. Get this wrong and fines are steep.
- Cross-border SaaS with EU data. If you're a US company processing EU personal data, you need to address international data transfers (Standard Contractual Clauses, adequacy decisions, transfer impact assessments). A template glosses over this.
- Financial data. Payment card data (PCI DSS scope), bank account details, credit information — these come with sector-specific rules.
- You've hit real scale. Once you have thousands of paying customers or you've raised institutional funding, "we used a generator" stops being a good answer during a due diligence review.
For everything else — most personal blogs, portfolios, small ecommerce stores, and early-stage SaaS with standard integrations — a generated template plus a careful pass to fill in specifics is a reasonable starting position. Revisit when your business grows or your data practices change.
Frequently asked questions
Do I need a privacy policy for a hobby blog? If it uses Google Analytics, embeds YouTube videos, has a comment form, or runs any ads, yes. Even a static blog on Netlify with a Google Fonts embed technically transmits IPs to Google. The realistic answer for almost any modern blog is yes.
Can I copy a privacy policy from another site? No, and for two reasons. Copyright — most policies are copyrighted text and copying them verbatim is plagiarism. And accuracy — their subprocessors, data flows, and jurisdictions almost certainly don't match yours, so the policy will misrepresent what your site actually does. Regulators and users can spot a copy-pasted policy quickly, and it's arguably worse than no policy because it documents commitments you're not actually keeping.
How often should I update my privacy policy? Whenever your data practices change. That includes adding a new analytics tool, a new email provider, a new payment processor, or starting to run ads. Also update if the underlying law changes materially (major GDPR guidance, new state laws in the US). At minimum, review annually. Update the effective date every time you make a material change and, ideally, notify existing users by email if the change affects their rights.
Do I need to comply with GDPR if I'm not in the EU? Yes, if any of your users are. GDPR applies extraterritorially — the question isn't where you're based, it's whether you're processing data from people in the EU or UK. For a public website, functionally you always are. This isn't legal advice; if you're serious about limiting scope (blocking EU traffic, for example) talk to a lawyer.
Does Google AdSense require a specific privacy policy format? AdSense's program policies require you to have a privacy policy that discloses your use of AdSense, that third-party vendors including Google use cookies to serve ads, and that users can opt out through Google's ad settings. There's no specific template AdSense mandates, but those disclosures must be present. Most generators — including this one — include the standard AdSense language when you tick the advertising box.