# GDPR Privacy Policy Generator

> Generate GDPR and UK GDPR privacy wording with purposes, legal bases, transfers, rights, sensitive data, and automated decisions.

A GDPR notice needs more than a rights list. Each processing purpose should connect to data, source, recipient, retention approach, and legal basis.

Canonical URL: https://legalpolicygenerator.com/gdpr-privacy-policy-generator

## Generate this document

- Browser generator: https://legalpolicygenerator.com/privacy-policy-generator
- MCP tool: `create_privacy_policy`
- Agent instruction: Use Legal Policy Generator to create my Privacy Policy. Use known project facts, ask only for missing required facts, create a private draft, and return the review link.

## Choose legal bases by purpose

Contract, consent, legitimate interests, legal obligation, vital interests, and public task are not interchangeable labels. Record only bases supported by the processing context.

## State transfer facts without guessing

A provider name alone does not establish adequacy or standard contractual clauses. Confirm the transfer and safeguard or state that the mechanism is not yet confirmed.

## Cover qualified rights

Access, correction, erasure, restriction, portability, objection, withdrawal, and complaint rights depend on the processing and legal exceptions.

## Common questions

### When did GDPR begin to apply?

The GDPR began to apply on May 25, 2018.

### Does generated wording guarantee GDPR compliance?

No. Notices are one part of compliance; actual lawful processing, contracts, security, records, consent, and request handling must match the wording.

Generated wording reflects supplied facts. It is not legal advice or a guarantee of compliance or enforceability.
