← All Generators
πŸ”’

GDPR Processor Security Policy Generator

Document your Technical and Organisational Measures (TOMs) under GDPR Art. 28(3)(c). Cover encryption, access control, incident response, audit rights, and sub-processor obligations.

1
Organisation Info
2
Security Controls

Organisation Details

Typical Controller Types

Who are your typical customers (controllers)?

Certifications & Assessments

πŸ“¦ Build Your Full Compliance Stack

Generate all the documents your SaaS needs.

πŸ”’

Privacy Policy

GDPR, CCPA & global-compliant privacy policy for your SaaS.

πŸ“‹

Terms of Service

Limit liability, define usage rules, protect your IP.

πŸͺ

Cookie Policy

ePrivacy & GDPR compliant cookie disclosure.

πŸ’Έ

Refund Policy

Clear refund rules that reduce chargebacks & disputes.

πŸ›‘οΈ

Acceptable Use Policy

Prohibit abuse, define enforcement, meet DSA requirements.

πŸ‡ͺπŸ‡ΊEnterprise

GDPR Data Processing Agreement

Article 28 DPA for your processor relationships.

πŸ₯Healthcare

HIPAA Business Associate Agreement

Required before handling PHI on behalf of covered entities.

🀝

NDA Generator

Mutual or one-way NDAs for contractors, investors & partnerships.

πŸ”SOC 2

Information Security Policy

SOC 2–ready InfoSec policy covering access control, encryption, and incident response.

🚨SOC 2

Incident Response Plan

NIST-structured IRP with severity playbooks, CSIRT roles, and GDPR 72-hour breach notification.

πŸ”GDPR Art. 35

DPIA Template Generator

GDPR Art. 35 Data Protection Impact Assessment with risk table and necessity test.

πŸ—‚οΈGDPR Art. 5

Data Retention Policy

GDPR-compliant retention schedule with per-category periods, deletion procedures, and legal basis table.

πŸ‡ΊπŸ‡ΈCCPA / CPRA

CCPA / CPRA Compliance Pack

Notice at Collection, Do Not Sell or Share opt-out page, and California Consumer Privacy Rights summary.

πŸ“‹GDPR Art. 28

Sub-Processor List

GDPR Art. 28(4) public sub-processor list with 40+ pre-loaded vendors, transfer mechanisms, and DPA links.

πŸ”„SOC 2 A1

BCP / DRP Plan

Business Continuity & Disaster Recovery Plan covering RTO/RPO, SOC 2 A1, GDPR Art. 32, and recovery playbooks.

πŸ”ISO 27001 A.15

Vendor Risk Assessment

Security questionnaire to send to new SaaS vendors before onboarding β€” covers data security, privacy, and compliance.

πŸ“©GDPR Art. 15–22

DSR Response Template

GDPR-compliant response letters for Data Subject Requests β€” access, erasure, portability, rectification, restriction, and objection.

πŸ‘€GDPR Art. 13

Employee Privacy Notice

GDPR Art. 13 compliant privacy notice for employees, contractors, and job applicants β€” covering HR data and lawful bases.

πŸ“ŠGDPR Art. 30

GDPR Article 30 RoPA

Form-based Records of Processing Activities builder. Document each processing activity with lawful basis, retention, recipients, and transfers.

🎯SOC 2

SOC 2 Gap Assessment

Evaluate your security controls against SOC 2 Trust Service Criteria. Get a gap report with prioritised remediation roadmap.

πŸ”ISO 27001

ISO 27001 Gap Assessment

Assess your readiness for ISO/IEC 27001:2022 certification across 28 Annex A controls. Gap report + remediation roadmap.

πŸ€–EU AI Act

EU AI Act Declaration

Generate an Art. 50 transparency declaration and provider/deployer compliance documentation for your AI system.

πŸ›‘οΈNIS2

NIS2 Compliance Checklist

Assess all 10 NIS2 Art. 21 cybersecurity requirements and get a scored gap report for EU digital service providers.

πŸ₯HIPAA SRA

HIPAA Security Risk Assessment

Generate a HIPAA SRA covering all Administrative, Technical, and Physical Safeguards. Required for CEs and BAs.

🌍Chapter V

GDPR Transfer Impact Assessment (TIA)

Generate a Schrems II-compliant TIA for international data transfers. Covers SCCs, DPF, UK IDTA, and country risk analysis.

πŸ’³PCI DSS v4

PCI DSS SAQ Generator

Generate a PCI DSS v4.0 Self-Assessment Questionnaire. Covers SAQ A, SAQ A-EP, SAQ C, and SAQ D.

πŸ‡§πŸ‡·LGPD

LGPD (Brazil) Compliance Pack

Generate Aviso de Coleta, Data Subject Rights Summary, and LGPD Privacy Policy addendum for Brazil compliance.

πŸ”—Enterprise

TPRM Policy Generator

Generate a complete Third-Party Risk Management policy with vendor tiers, due diligence, and monitoring controls.

πŸͺGDPR + ePrivacy

Cookie Consent Audit

Audit your CMP configuration, cookie banner design, consent records, and Google Consent Mode v2 against GDPR and ePrivacy requirements.

βš–οΈArt. 6(1)(f)

GDPR LIA Generator

Generate a documented Legitimate Interests Assessment (LIA) for GDPR Art. 6(1)(f) processing activities. 3-step balancing test.

🧬EU AI Act Art. 53

AI/ML Model Card Generator

Generate an EU AI Act Art. 53 Model Card for your AI system. Covers GPAI documentation, risk classification, bias evaluation, and safety measures.

πŸ””EU Directive 2019/1937

Whistleblower Policy Generator

Generate a Whistleblower Policy compliant with EU Directive 2019/1937 and UK PIDA. Anti-retaliation protections, reporting channels, GDPR data handling.

πŸ€–EU AI Act

AI Acceptable Use Policy

Generate an AI AUP covering EU AI Act obligations, prohibited inputs/outputs, bias disclosures, human oversight levels, and enforcement mechanisms.

πŸ‘ΆCOPPA Β· GDPR Art. 8

Children's Privacy Policy

COPPA & GDPR Art. 8 children's privacy notice with parental consent framework, age verification, data minimisation, and UK Children's Code compliance.

🚨GDPR Art. 33 & 34

GDPR Breach Notification

Generate an Art. 33 DPA supervisory authority notification form, Art. 34 individual notification letter, and Art. 33(5) breach register entry.

πŸ“¦SOC 2 Audit Prep

SOC 2 Evidence Pack

Personalised SOC 2 evidence collection checklist by Trust Service Criteria control area β€” with exact evidence items, auditor expectations, and how to collect using AWS, GitHub, and common SaaS tools.

πŸ›‘οΈEnterprise Sales

Trust Centre Page

Generate a complete security & compliance Trust Centre page for your SaaS website β€” certifications, infrastructure, encryption, pen testing, privacy, and a security FAQ for enterprise prospects.

πŸ€–GDPR + EU AI Act

AI Privacy Impact Assessment

Generate a GDPR Art. 35 DPIA specifically for AI systems β€” EU AI Act risk classification, automated decision-making analysis (Art. 22), bias assessment, and human oversight documentation.

πŸ›‘οΈISO 27701 PIMS

ISO 27701 PIMS Gap Assessment

Assess readiness for ISO/IEC 27701:2019 PIMS certification β€” the privacy extension to ISO 27001. 26 controls, Annex A (controller) + Annex B (processor), GDPR alignment map.

πŸŽ“SOC 2 Β· ISO 27001 Β· HIPAA

Security Awareness Training Policy

Generate a complete Security Awareness Training Policy mapped to SOC 2 CC1.4, ISO 27001 A.6.3, HIPAA Β§164.308(a)(5), NIS2 Art. 21(2)(g), PCI DSS Req 12.6 β€” training schedule, phishing simulation, tracking, consequences.

πŸ“¬GDPR Β· UK GDPR

DSAR Policy & Procedure

Generate an internal GDPR data subject access request policy β€” intake channels, identity verification, per-right procedures, timelines, refusal grounds, DSR register, escalation, and audit logging.

πŸ€–EU AI Act Β· ISO 42001

AI Risk Register

Generate a comprehensive AI risk register covering EU AI Act compliance, GDPR Art. 22, algorithmic bias, prompt injection, model drift, and ISO 42001 β€” with inherent risk scores and mitigation plans.

πŸ’»SOC 2 Β· ISO 27001

Internal IT & BYOD Policy

Generate an Internal IT Acceptable Use and BYOD Policy. Covers device controls, network access, cloud apps, remote work, monitoring disclosure, and SOC 2 / ISO 27001 compliance.

πŸ”SOC 2 CC6 Β· ISO 27001 A.9

Access Control Policy

Generate a complete Access Control Policy covering RBAC, least privilege, MFA, privileged access management, user provisioning/deprovisioning, access reviews, and remote access controls.

πŸ—‚οΈISO 27001 A.8 Β· SOC 2

Data Classification Policy

Generate a Data Classification Policy with tiered classification levels (Public/Internal/Confidential/Restricted), handling standards, storage controls, labelling guidance, and disposal procedures.

πŸ”SOC 2 CC7.1 Β· ISO 27001 A.8.8

Vulnerability Management Policy

Generate a Vulnerability Management & Patch Management Policy with scanning cadence, CVSS severity classification, remediation timelines, exception handling, and compliance framework mappings (SOC 2 CC7.1, ISO 27001 A.8.8, PCI DSS, NIS2).

πŸ”ISO 27001 A.10 Β· SOC 2 CC6.7

Cryptography & Encryption Policy

Generate a Cryptography & Encryption Policy with approved algorithms, encryption at rest and in transit, key management lifecycle, TLS standards, and compliance mappings (ISO 27001 A.10, SOC 2 CC6.7, GDPR Art. 32, HIPAA, PCI DSS).

πŸ”§SOC 2 CC8.1 Β· ISO 27001 A.8.25

Secure SDLC Policy

Generate a Secure Software Development Lifecycle (SDLC) Policy covering code review requirements, CI/CD security scanning, secrets management, environment separation, and deployment authorisation controls.

🏦DORA Art. 5–16 Β· Fintech

DORA ICT Risk Management Policy

Generate a DORA-compliant ICT Risk Management Policy covering identification, protection, detection, response, recovery, and resilience testing for financial entities and ICT third-party service providers.

View all generators β†’