54 Free Generators Live — Privacy Policy, ToS, DPA, HIPAA BAA, CCPA Pack, LGPD Pack, NDA, InfoSec Policy, IRP, DPIA, RoPA, SOC 2 Gap, ISO 27001 Gap, ISO 27701 PIMS, NIS2 Checklist, HIPAA SRA, GDPR TIA, PCI DSS SAQ, TPRM Policy, Security Awareness Training, Cookie Consent Audit, GDPR LIA, AI Model Card, Whistleblower Policy, AI AUP, Children's Privacy, GDPR Breach Notification, SOC 2 Evidence Pack, Trust Centre, AI-PIA, DSAR Policy, AI Risk Register, GDPR Processor Security Policy, IT & BYOD Policy, Access Control Policy, Data Classification Policy, Vulnerability Management Policy, Cryptography Policy, Secure SDLC Policy, DORA ICT Risk Policy, Log Management Policy, Email Security Policy, Password & Auth Policy, Remote Work Security Policy & more

Compliance docs, drafted in minutes
not months

Generate AI-drafted GDPR & CCPA compliance documents tailored to your SaaS in minutes — a starting point for your lawyer to review, not a replacement for one.

⚠️ AI-generated drafts. Not legal advice. ComplyKit is not a law firm — have outputs reviewed by qualified counsel before publishing.

No credit card required
GDPR + CCPA + ePrivacy aware
46 free generators — no account needed

A faster first draft, not a substitute for counsel

Built for early-stage SaaS founders who need a structured starting point for their compliance docs — and the budget to spend on review, not drafting.

Minutes, Not Months

Answer a short questionnaire about your SaaS. We generate a customised privacy policy draft in seconds — ready to hand to your lawyer.

⚖️

Framework-Aware

Each output maps directly to current GDPR Articles 13–14 and CCPA §1798.100 disclosure requirements — so the structural pieces aren't missed.

📄

Draft Templates

Outputs are AI-generated draft templates — a starting point. ComplyKit is not a law firm and the drafts are not legal advice. Always have a qualified lawyer review before publishing.

🌍

Multi-Jurisdiction Awareness

Tell us where you operate (EU/EEA, UK, US, global) and we tailor the lawful-basis and rights sections to the regimes you mention.

🔒

Clean, Exportable Output

Markdown + browser print-to-PDF. Drop into your trust centre, security questionnaire, or hand to counsel for redlining.

💸

Cheaper Than Starting From Zero

Ballpark¹: full external GDPR + CCPA documentation drafting from a privacy lawyer runs $4k–$15k. Use ComplyKit to get a structured first draft, then pay your lawyer to review — not to type.

¹ Indicative range based on common privacy-counsel hourly rates of $250–$500 × an estimated 15–30 hours of drafting work for a multi-framework policy. Your actual costs will vary.

✅ Live today — 54 free generators

Generate your compliance docs

Fifty-four free AI-drafting tools live now. Answer a few questions, get a starting-point document your lawyer can finalize.

🔒

Privacy Policy

Free · Live now

GDPR & CCPA compliant privacy policy drafted from your actual data practices — subprocessors, retention, lawful bases, and user rights.

GDPRCCPACPRA
Generate free →
📄

Terms of Service

Free · Live now

Plain-English ToS covering acceptable use, payment, subscriptions, UGC, liability cap, and governing law — adapted to your business model.

Governing LawLiability CapUGC
Generate free →
🍪

Cookie Policy

Free · Live now

Cookie-category table with provider disclosures, opt-out links, and ePrivacy Directive notes — matched to your actual analytics and ad stack.

ePrivacyGDPRPECR
Generate free →
💸

Refund Policy

Free · Live now

Refund & cancellation policy for SaaS subscriptions. Covers pro-rata refunds, free trial terms, EU 14-day cooling-off rights, and governing law.

SubscriptionsEU Consumer LawCancellation
Generate free →
🚫

Acceptable Use Policy

Free · Live now

Define prohibited uses, enforcement actions, and user obligations for your platform. Covers spam, scraping, UGC, IP infringement, and enforcement procedures.

User ConductEnforcementUGC
Generate free →
🤝

GDPR Data Processing Agreement (DPA)

Free · Live now

Article 28 DPA ready to send to B2B customers. Sub-processor list, TOMs, breach notification, international transfer clauses, and audit rights included.

Art. 28B2B SaaSSub-processorsTOMs
Generate free →
🏥

HIPAA Business Associate Agreement (BAA)

Free · Live now

HIPAA BAA for US healthcare SaaS. Covers ePHI safeguards, breach notification, permitted uses, sub-contractor BAA chain, and state-specific addenda.

HIPAAePHIHealthcareBAA
Generate free →
🤝

NDA Generator

Free · Live now

Mutual or one-way NDAs for contractors, investors, and partnerships. Optional non-compete, non-solicitation, and liquidated damages clauses. Jurisdiction-specific.

Mutual NDAOne-Way NDANon-Compete
Generate free →
🔐

Information Security Policy

Free · Live now

SOC 2–aligned InfoSec policy covering access control, encryption, vulnerability management, incident response, and vendor risk. Tailored to your stack.

SOC 2ISO 27001GDPR Art. 32
Generate free →
🚨

Incident Response Plan

Free · Live now

Generate a NIST-structured Incident Response Plan. Covers severity classification, CSIRT roles, containment playbooks, GDPR 72-hour breach notification, and post-incident review.

SOC 2 CC7NIST 800-61GDPR Art. 33ISO 27035
Generate free →
🔍

DPIA Template Generator

Free · Live now

Generate a GDPR Article 35 Data Protection Impact Assessment. Covers necessity & proportionality test, risk assessment table with residual risk ratings, safeguards map, and Art. 36 DPA consultation check.

GDPR Art. 35Privacy by DesignRisk Assessment
Generate free →
🗂️

Data Retention Policy

Free · Live now

Generate a GDPR-compliant Data Retention Policy with per-category retention schedules, deletion procedures, legal basis table, backup retention, and legal hold process.

GDPR Art. 5Storage LimitationRight to Erasure
Generate free →
🇺🇸

CCPA / CPRA Compliance Pack

Free · Live now

Generate your CCPA/CPRA compliance pack: Notice at Collection, Do Not Sell or Share opt-out page, and California Consumer Privacy Rights summary.

CCPACPRANotice at CollectionDo Not Sell
Generate free →
📋

Sub-Processor List

Free · Live now

Generate a GDPR Art. 28(4) public sub-processor list with 40+ pre-loaded vendors, transfer mechanisms, processing countries, and DPA links.

GDPR Art. 28Sub-processorsInternational Transfers
Generate free →
🔄

BCP / DRP Plan

Free · Live now

Generate a Business Continuity & Disaster Recovery Plan with RTO/RPO objectives, recovery playbooks, and SOC 2 A1 / GDPR Art. 32 alignment.

SOC 2 A1ISO 27001 A.17GDPR Art. 32
Generate free →
🔍

Vendor Risk Assessment

Free · Live now

Generate a security questionnaire to send to new SaaS vendors before onboarding. Covers data handling, access controls, SOC 2, GDPR, and sub-processor obligations.

ISO 27001 A.15SOC 2 CC9.2GDPR Art. 28
Generate free →
📩

DSR Response Template

Free · Live now

Generate GDPR-compliant response letters for Data Subject Requests — access, erasure, portability, rectification, restriction, and objection. Covers all 8 rights under Art. 15–22.

GDPR Art. 15–22SAR / DSAR72h Acknowledgement
Generate free →
👤

Employee Privacy Notice

Free · Live now

GDPR Article 13/14 compliant privacy notice for employees, contractors, and job applicants. Covers HR data, lawful bases, monitoring, retention, and data subject rights.

GDPR Art. 13/14HR ComplianceEmployment Law
Generate free →
📊

GDPR Article 30 RoPA

Free · Live now

Form-based Records of Processing Activities builder. Document each processing activity with data subjects, lawful basis, retention periods, recipients, and international transfers.

GDPR Art. 30Controller ObligationsProcessing Register
Generate free →
🎯

SOC 2 Gap Assessment

Free · Live now

Evaluate your current security controls against SOC 2 Trust Service Criteria. Get a gap report with prioritised remediation roadmap and policy document checklist.

SOC 2 TSCCC / A / C / PI / PAudit Readiness
Generate free →
🔍

ISO 27001 Gap Assessment

Free · Live now

Assess readiness for ISO/IEC 27001:2022 certification across 28 Annex A controls in 14 domains. Gap report with phased remediation roadmap.

ISO 27001:2022Annex A ControlsISMS Certification
Generate free →
🤖

EU AI Act Declaration

Free · Live now

Generate Art. 50 transparency notices and provider/deployer compliance documentation for your AI system under Regulation (EU) 2024/1689.

EU AI Act Art. 50Provider ObligationsAI Transparency
Generate free →
🛡️

NIS2 Compliance Checklist

Free · Live now

Assess your organisation against all 10 NIS2 Art. 21 cybersecurity requirements. Get a scored gap report with prioritised remediation roadmap for EU digital service providers.

NIS2 Art. 21EU CybersecurityDigital Service Providers
Generate free →
🏥

HIPAA Security Risk Assessment

Free · Live now

Generate a HIPAA SRA covering all Administrative, Technical, and Physical Safeguards (45 CFR Part 164). Required for all covered entities and business associates.

HIPAA SRA45 CFR 164Business Associates
Generate free →
🌍

GDPR Transfer Impact Assessment (TIA)

Free · Live now

Generate a Schrems II-compliant TIA for all international data transfers. Covers SCCs, EU-US DPF, UK IDTA, BCRs, country risk analysis, and supplementary measures.

Schrems IIChapter VSCCsDPF
Generate free →
💳

PCI DSS SAQ Generator

Free · Live now

Generate a PCI DSS v4.0 Self-Assessment Questionnaire. Covers SAQ A, SAQ A-EP, SAQ C, and SAQ D for merchants and service providers.

PCI DSS v4SAQ ASAQ DCard Data
Generate free →
🇧🇷

LGPD (Brazil) Compliance Pack

Free · Live now

Generate a LGPD-compliant Aviso de Coleta, Data Subject Rights Summary, and Privacy Policy addendum for Brazil's Lei Geral de Proteção de Dados.

LGPD Art. 9ANPDBrazil Data Protection10 Lawful Bases
Generate free →
🔗

TPRM Policy Generator

Free · Live now

Generate a complete Third-Party Risk Management policy with vendor tiers, due diligence matrix, contract requirements, and monitoring controls.

ISO 27001 A.15SOC 2 CC9.2GDPR Art. 28Vendor Risk
Generate free →
🍪

Cookie Consent Audit

Free · Live now

Audit your CMP configuration, consent banner, consent records, and Google Consent Mode v2 against GDPR, ePrivacy, and CCPA requirements.

GDPR Art. 7ePrivacy DirectiveICO PECRCCPAGCM v2
Generate free →
⚖️

GDPR LIA Generator

Free · Live now

Generate a documented Legitimate Interests Assessment (LIA) for GDPR Art. 6(1)(f). 3-step balancing test with conclusion and privacy notice guidance.

GDPR Art. 6(1)(f)Art. 21 ObjectionBalancing TestEDPB
Generate free →
🧬

AI/ML Model Card Generator

Free · Live now

Generate an EU AI Act–compliant Model Card for your AI system. Covers GPAI Art. 53 technical documentation, risk classification, bias evaluation, training data governance, and safety measures.

EU AI Act Art. 53GPAI DocumentationAI Governance
Generate free →
🔔

Whistleblower Policy Generator

Free · Live now

Generate a Whistleblower (Speak Up) Policy compliant with EU Directive 2019/1937 and UK PIDA. Covers reporting channels, protected disclosures, anti-retaliation protections, and GDPR-compliant data handling.

EU Directive 2019/1937UK PIDAAnti-Retaliation
Generate free →
🤖

AI Acceptable Use Policy

Free · Live now

Generate an AI Acceptable Use Policy for your SaaS product. Covers EU AI Act obligations, prohibited AI inputs and outputs, bias and accuracy disclosures, human oversight levels, data training transparency, and enforcement mechanisms.

EU AI ActGDPR Art. 22DSA
Generate free →
👶

Children's Privacy Policy

Free · Live now

Generate a COPPA-compliant and GDPR Article 8 Children's Privacy Notice. Covers parental consent verification, age thresholds by jurisdiction, data minimisation for children, UK Children's Code obligations, and parental rights.

COPPAGDPR Art. 8UK Children's Code
Generate free →
🚨

GDPR Breach Notification Template

Free · Live now

Generate a GDPR Article 33 supervisory authority breach notification form, Article 34 individual notification letter, and Art. 33(5) breach register entry — with 72-hour deadline guidance and DPA-specific filing instructions.

GDPR Art. 33GDPR Art. 34Breach Register72-Hour Rule
Generate free →
📦

SOC 2 Evidence Pack Generator

Free · Live now

Get a personalised SOC 2 evidence collection checklist by Trust Service Criteria control area — with exact evidence items, auditor expectations, collection steps for AWS/GitHub/GCP, and PBC folder organisation guide.

SOC 2 Type IIEvidence CollectionPBCAudit Ready
Generate free →
🛡️

Trust Centre Page Generator

Free · Live now

Generate a complete security & compliance Trust Centre page for your SaaS website. Covers certifications, infrastructure, encryption, pen testing, bug bounty, sub-processors, privacy & a security FAQ for enterprise prospects.

Enterprise SalesSecurity PageTrust CenterSecurity FAQ
Generate free →
🤖

AI Privacy Impact Assessment (AI-PIA)

Free · Live now

Generate a GDPR Article 35 DPIA specifically for AI systems. Covers EU AI Act risk classification, Annex III use cases, automated decision-making (Art. 22), bias assessment, human oversight documentation, and DPA consultation analysis.

GDPR Art. 35EU AI ActArt. 22 ADMBias Assessment
Generate free →
🛡️

ISO 27701 PIMS Gap Assessment

Free · Live now

Assess your readiness for ISO/IEC 27701:2019 PIMS certification — the privacy extension to ISO 27001. 26 controls across 8 domains. Annex A (controllers) + Annex B (processors). Includes ISO 27701 ↔ GDPR alignment map and certification roadmap.

ISO 27701:2019PIMSGDPR MappingPrivacy Certification
Generate free →
🎓

Security Awareness Training Policy

Free · Live now

Generate a complete Security Awareness Training Policy for your SaaS. Training schedule, curriculum, phishing simulation programme, completion tracking, and graduated consequences. Mapped to SOC 2 CC1.4, ISO 27001 A.6.3, HIPAA §164.308(a)(5), NIS2 Art. 21(2)(g), PCI DSS Req 12.6, GDPR Art. 32.

SOC 2 CC1.4ISO 27001 A.6.3HIPAA §164.308(a)(5)NIS2PCI DSS 12.6
Generate free →
📬

DSAR Policy & Procedure

Free · Live now

Generate an internal GDPR data subject access request (DSAR) policy covering all 8 rights, identity verification, per-right procedures, timelines, refusal grounds, DSR register template, and escalation paths.

GDPR Art. 12–22UK GDPRDSR WorkflowAudit Trail
Generate free →
🤖

AI Risk Register

Free · Live now

Generate a comprehensive AI risk register covering EU AI Act compliance, GDPR Art. 22 ADM risks, algorithmic bias, prompt injection, model drift, and ISO 42001 — with inherent risk scores and mitigation plans.

EU AI ActISO 42001GDPR Art. 22NIST AI RMF
Generate free →
🔒

GDPR Processor Security Policy

Free · Live now

Generate Art. 28(3)(c) TOMs documentation — encryption, access control, incident response, audit rights, and sub-processor obligations.

GDPR Art. 28(3)(c)TOMsProcessorsEnterprise
Generate free →
💻

Internal IT & BYOD Policy

Free · Live now

Generate an employee IT acceptable use and BYOD policy covering device controls, network access, cloud apps, remote work, and monitoring disclosure.

SOC 2ISO 27001BYODGDPR Art. 32
Generate free →
🔐

Access Control Policy

Free · Live now

Generate a complete Access Control Policy covering RBAC, least privilege, MFA, privileged access management, user provisioning, access reviews, and remote access controls.

SOC 2 CC6ISO 27001 A.9HIPAAPCI DSS Req 7-8
Generate free →
🗂️

Data Classification Policy

Free · Live now

Generate a Data Classification Policy with tiered classification levels (Public/Internal/Confidential/Restricted), handling standards, storage controls, labelling, and disposal procedures.

ISO 27001 A.8SOC 2 C1GDPR Art. 5HIPAAPCI DSS
Generate free →
🔍

Vulnerability Management Policy

Free · Live now

Generate a Vulnerability Management & Patch Management Policy with scanning cadence, CVSS severity classification, remediation timelines, exception handling, and compliance mappings.

SOC 2 CC7.1ISO 27001 A.8.8PCI DSS Req 6NIS2NIST
Generate free →
🔐

Cryptography & Encryption Policy

Free · Live now

Generate a Cryptography & Encryption Policy with approved algorithms, at-rest and in-transit encryption requirements, key management lifecycle, TLS standards, and compliance mappings.

ISO 27001 A.10SOC 2 CC6.7GDPR Art. 32HIPAAPCI DSS
Generate free →
🚧 Coming next — join the waitlist

More frameworks on the roadmap

Join the waitlist to get notified when these ship. No promises on timelines.

SOC 2 Type II Policy Pack

🌐 Global Enterprise

Pre-written SOC 2 Type II policy bundle — access control, change management, incident response, vendor management, and more.

Policy BundleEvidence PackAudit Ready

ISO 27001 ISMS Documentation Pack

🌐 Global

Full ISMS documentation pack: Statement of Applicability, Risk Register template, internal audit checklist, management review agenda.

ISMSSoARisk Register

How it works

From zero to compliance package in an afternoon — not a quarter.

01

Describe your SaaS

Answer a plain-English questionnaire about what your product does, what data you collect, where you operate, and which subprocessors you use.

Takes ~5 minutes. No legal jargon.
02

AI drafts your privacy policy

ComplyKit sends your answers to OpenAI and gets back a structured Privacy Policy draft mapped to GDPR Articles 13–14 and CCPA disclosure requirements. It’s a draft, not legal advice.

Privacy Policy live today. More frameworks on the roadmap.
03

Copy, export, hand to counsel

Copy to clipboard, download as Markdown, or print to PDF. Hand the draft to a qualified privacy lawyer for review before publishing.

You always retain ownership of your generated draft.
04

Re-generate as you grow

Add a subprocessor? Open a new market? Re-run the generator and get an updated draft. Each generation is a fresh draft — always have it reviewed.

You stay in control of versioning and review.
🚀 Private Beta — Spots Are Limited

Be first in line

Join the waitlist and we'll let you know when more frameworks (Terms, DPA, Cookie Policy) ship. Founding members will get an early discount when paid plans launch.

We process your email under GDPR Art. 6(1)(a) (consent). Stored on Supabase (EU). You can withdraw consent or request deletion at any time: privacy@nocodelisted.com.

~5 min
Typical time to first draft
1
Generator live today (Privacy Policy)
Free
No credit card required