⚡ Promptolis Original · Legal

🔒 Privacy Policy Builder — GDPR + CCPA Compliant

The structured privacy policy for 2026 — covering GDPR + CCPA + state privacy laws, data collection disclosure, cookie policy, rights statements, and the non-boilerplate language that builds trust vs. generic template theater.

⏱️ 3 hours + attorney review 🤖 ~2 min in Claude 🗓️ Updated 2026-04-20

Why this is epic

Most privacy policies are unreadable boilerplate with compliance gaps. This Original produces GDPR + CCPA + state-law compliant privacy policy: specific data disclosures, cookie policy, user rights, retention periods. NOT legal advice — final privacy policy requires attorney review.

Names the 7 critical privacy policy sections + 2026 regulatory landscape (GDPR, CCPA, Colorado/Connecticut/Virginia laws, children's data, cookie rules).

Produces complete policy: each section specific + plain-language, cookie policy integration, DPA-readiness, data subject request process, breach notification language. Based on GDPR + CCPA + emerging state privacy frameworks.

The prompt

Promptolis Original · Copy-ready
<role> You are a privacy + data protection specialist with 12 years of experience. You've authored 200+ privacy policies + advised on GDPR/CCPA compliance. NOT a lawyer — provide structured framework, attorney review required for final. You draw on GDPR (EU Regulation 2016/679), CCPA (California Civil Code 1798.100+), Colorado Privacy Act, Virginia Consumer Data Protection Act, and 2026 regulatory landscape. </role> <principles> 1. NOT legal advice. Attorney review mandatory for final policy. 2. Plain language > legalese. 3. Specific data disclosures, not 'any information.' 4. List third parties, not vague 'partners.' 5. User rights must be usable. 6. Cookie banner + preferences required. 7. Children's data parental consent. 8. Update when practices change. </principles> <input> <business-context>{company + data collected}</business-context> <customer-regions>{EU, US, specific states}</customer-regions> <data-collected>{types of data}</data-collected> <third-parties>{who you share with}</third-parties> <purposes>{why you collect}</purposes> <retention>{how long kept}</retention> <children-data>{collect from under-18?}</children-data> <current-policy>{if exists}</current-policy> </input> <output-format> # Privacy Policy: [Company] ## Overview Summary What policy must cover. ## Section 1: Data We Collect Specific categories. ## Section 2: How We Use Data Purposes. ## Section 3: Third-Party Sharing Who + why. ## Section 4: User Rights Access, deletion, portability. ## Section 5: Cookies + Tracking Cookie policy. ## Section 6: Data Retention How long + why. ## Section 7: Children's Data COPPA/GDPR compliance. ## Section 8: Security + Breach Notification Your obligations. ## Contact + Data Subject Requests How to reach you. ## Attorney Review Triggers When to escalate. ## Key Takeaways 5 bullets. </output-format> <auto-intake> If input incomplete: ask for business, regions, data collected, third parties, purposes, retention, children's data, current policy. </auto-intake> Now, draft:

Example: input → output

Here's how this prompt actually performs. Real input below, real output from Claude Opus 4.

📝 Input
<business-context>B2B SaaS, marketing analytics platform. Customer data platform. Handle data on customers of customers (our customers' end users).</business-context>
<customer-regions>US (all states), EU (France, Germany, UK primary), Canada.</customer-regions>
<data-collected>Customer employee accounts (email, name, role). End-user data our customers feed in (names, emails, behavior data from their products). Usage analytics from our platform.</data-collected>
<third-parties>AWS (hosting), Stripe (billing), HubSpot (our CRM), Sendgrid (emails), Mixpanel (product analytics), Slack (support).</third-parties>
<purposes>Product functionality, billing, customer support, product improvement, security, legal compliance.</purposes>
<retention>Active customer: indefinite. Inactive 90 days: deletion unless legal hold. End-user data: per customer contract.</retention>
<children-data>Not intentionally. Customers should not feed child data.</children-data>
<current-policy>Exists but 3 years old. Missing 2024+ regulations.</current-policy>
🤖 Output

Privacy Policy: B2B SaaS Customer Data Platform

A privacy policy structure produces GDPR + CCPA + state-law compliant document. NOT legal advice. Your situation — B2B SaaS with multi-region customer base, handling both customer + end-user data — requires comprehensive 8-section policy with DPA-readiness. This draft covers essential sections; FINAL policy requires privacy attorney review (est. $2-5K for compliance attorney, worth it given GDPR fines up to 4% of global revenue).

Overview Summary

Privacy policy must cover:

  • What data collected + why
  • How data used + shared
  • User rights + how to exercise them
  • Security measures + breach notification
  • Multi-jurisdiction compliance (GDPR, CCPA, state laws)
  • Children's data protection
  • Cookie usage + consent
  • DPA addendum for B2B customers

Section 1: Data We Collect

Customer Account Data:

  • Names, email addresses of customer employees
  • Job titles, company affiliations
  • Account credentials (password hashes, not plaintext)
  • Communication preferences

End-User Data (Our Customers' Data):

  • Data our customers upload to our platform (names, emails, behavior data)
  • We process this as a Data Processor under GDPR (our customers are the Data Controller)
  • DPA addendum governs this relationship

Usage Data:

  • Platform usage analytics (feature adoption, session data)
  • IP addresses (de-identified within 30 days)
  • Browser + device information
  • Error logs

Marketing Data:

  • Email engagement (opens, clicks)
  • Website interaction
  • Lead source attribution

Section 2: How We Use Data

Service Provision:

  • Provide platform functionality
  • Authenticate user access
  • Customer support

Billing + Payment:

  • Process subscription payments
  • Invoice generation
  • Tax reporting

Product Improvement:

  • Analyze aggregated usage patterns
  • Identify bugs + performance issues
  • Feature development

Communication:

  • Service announcements
  • Support responses
  • Marketing communications (with consent, unsubscribe available)

Legal + Security:

  • Compliance with laws
  • Fraud prevention
  • Dispute resolution

Section 3: Third-Party Sharing

Service Providers (Sub-Processors):

ProviderPurposeData SharedLocation
AWSHosting + infrastructureAll data (encrypted)US + EU regions
StripePayment processingBilling data onlyUS
HubSpotCRMCustomer contact dataUS
SendgridEmail deliveryEmail addresses + contentUS
MixpanelProduct analyticsAnonymized usage dataUS
SlackCustomer supportSupport interaction dataUS

Legal Compliance:

  • Responses to legal requests (subpoenas, warrants)
  • Enforcement of terms of service
  • Protection of rights + safety

Business Transfers:

  • Mergers, acquisitions, asset sales (with 30-day notice to users)

Does NOT sell data to third parties for advertising. GDPR + CCPA compliance.

Section 4: User Rights

GDPR + CCPA + State Law Rights:

Access: Request what data we hold about you. Response within 30 days.

Correction: Fix inaccurate data. Response within 30 days.

Deletion: Request data deletion. Exceptions for legal/compliance retention.

Portability: Receive your data in machine-readable format (CSV, JSON).

Object: Opt-out of processing (marketing, etc.).

Restriction: Limit how we process your data while concerns resolved.

Automated decision-making: Human review of automated decisions if significant.

How to exercise:

  • Email: privacy@[company].com
  • In-app: Settings → Privacy → Data Requests
  • Written: [Physical address]

Verification: We verify identity before processing requests.

Timeline: 30 days standard (GDPR). Up to 45 days for complex requests.

Section 5: Cookies + Tracking

Essential Cookies (no consent required):

  • Session management
  • Authentication
  • Security

Functional Cookies (consent required):

  • User preferences
  • Language settings
  • Remember-me functionality

Analytics Cookies (consent required):

  • Product usage analytics (Mixpanel)
  • Performance monitoring
  • A/B testing

Marketing Cookies (consent required):

  • Lead attribution
  • Email engagement tracking
  • Advertising attribution

Consent management:

  • Cookie banner on first visit
  • Granular consent (accept all / reject all / customize)
  • Preferences can be changed anytime (Settings → Cookies)
  • EU users: no tracking cookies without explicit consent
  • California users: 'Do Not Sell My Info' link

Section 6: Data Retention

Active Customer Data: retained for duration of customer relationship.

Inactive Accounts (90+ days no login):

  • Warning email at 60 days
  • Account deletion at 90 days unless legal hold
  • Backups retained 30 days post-deletion

End-User Data (customer-uploaded):

  • Governed by customer contract + DPA
  • Deleted per customer instructions
  • Default: 90 days post-contract termination

Billing Records: 7 years (legal/tax requirement).

Logs:

  • Security logs: 1 year
  • Access logs: 90 days
  • Error logs: 30 days

Marketing Data:

  • Until unsubscribe or 3 years of inactivity
  • Whichever earlier

Section 7: Children's Data

Policy: Service not intended for individuals under 16.

If we learn we've collected child data:

  • Delete immediately
  • Parental notification if feasible
  • Customer notification (B2B context)

Customer responsibility:

  • Customers must not upload child data without parental consent
  • Violation of customer agreement

COPPA compliance (under 13): not applicable to our B2B service but customers should implement on their end.

Section 8: Security + Breach Notification

Security Measures:

  • Encryption at rest (AES-256) + in transit (TLS 1.3)
  • SOC 2 Type II audit (annually)
  • Access controls (role-based, SSO)
  • Regular security assessments
  • Employee privacy training
  • Vendor security reviews

Breach Notification (GDPR):

  • Regulatory notification within 72 hours of discovery
  • User notification 'without undue delay' if high risk
  • Notification includes: what happened, data affected, mitigation steps

Breach Notification (US state laws):

  • Per applicable state requirements (usually within 30-60 days)
  • Notification methods per state law

Contact + Data Subject Requests

Data Protection Officer (DPO):

  • Name: [DPO Name]
  • Email: dpo@[company].com
  • Required under GDPR for processing EU data at scale

Privacy Team:

  • Email: privacy@[company].com
  • Typical response: 30 days
  • Complex requests: up to 45 days

Regulatory Contact:

  • EU data subjects: [Applicable supervisory authority]
  • CA residents: California Attorney General
  • Other states: relevant state attorney general

Physical Address:

  • [Company legal address]

Attorney Review Triggers

Require legal review for:

1. Any multi-jurisdiction compliance — GDPR + CCPA + state laws interact

2. DPA language (Data Processing Agreement for B2B)

3. Cookie consent mechanism — technical + legal implications

4. Children's data — specific rules complex

5. Automated decision-making — Article 22 GDPR

6. International data transfers — SCCs (Standard Contractual Clauses)

7. Any breach notification language — timing + content critical

Cost: $2,000-5,000 for comprehensive privacy attorney review.

Budget justification: GDPR fines up to 4% of annual global revenue (€20M floor). Worth the review.

Key Takeaways

  • Privacy policy is NOT set-and-forget. Update annually at minimum + when practices change. Your 3-year-old policy needs 2024+ regulations added (Colorado, Virginia, Connecticut, Texas laws).
  • B2B SaaS with EU customers needs DPO + DPA capability. Your handling of customers' end-user data = Data Processor role (customers are Data Controllers). DPA addendum mandatory.
  • List specific third parties + sub-processors. Vague 'partners' fails audits. Table format showing AWS + Stripe + HubSpot + etc with purposes + locations.
  • User rights must be usable, not theoretical. Email + in-app request paths + 30-day response SLA. GDPR + CCPA both require real access.
  • Attorney review mandatory before publishing. $2-5K investment prevents fines up to 4% of global revenue. NOT optional for compliant privacy policy.

Common use cases

  • SaaS companies needing GDPR/CCPA compliance
  • DTC brands collecting customer data
  • Startups establishing first privacy policy
  • Companies expanding to EU/California markets
  • Privacy policy refreshes for 2026 regulations
  • B2B services requiring DPA capability

Best AI model for this

Claude Opus 4 or Sonnet 4.5. Privacy policy requires legal + technical understanding. Top-tier reasoning matters. NOT legal advice.

Pro tips

  • NOT legal advice. Attorney review for final policy. Privacy breaches have 4% of global revenue fines under GDPR.
  • Plain language beats legalese. 'We collect X because Y' beats '[data] processing activities shall be governed by...'
  • Be specific about data collected. 'Any information' is weak. List categories.
  • List third parties you share data with. Vague 'partners' won't pass audit.
  • User rights (access, deletion, correction, portability) must be real + usable.
  • Cookie banner + preferences not optional — compliance + trust.
  • Children's data requires parental consent if under 13 (COPPA) or 16 (GDPR).
  • Update policy when practices change. Stale policies = compliance gaps.

Customization tips

  • Don't copy competitors' privacy policies. They may be outdated or wrong for your specific situation. Generate from your practices.
  • Review privacy policy annually + after any data practice changes. Version track (v2.1, v2.2 etc). Include 'last updated' date.
  • Build cookie banner properly. GDPR requires prior consent (not 'by using our site you agree'). Solutions: OneTrust, Cookiebot, TrustArc.
  • For B2B: DPA (Data Processing Agreement) is separate document. Have template ready for enterprise customers requesting it.
  • Privacy policy is only one compliance element. Internal data handling, access controls, employee training all matter. Policy reflects reality.

Variants

B2B SaaS

For B2B services with enterprise DPA needs.

DTC Consumer

For consumer brands with retail + marketing.

EU-First

GDPR-primary with other compliance overlay.

Multi-Jurisdiction

US + EU + UK + CA + AU etc.

Frequently asked questions

How do I use the Privacy Policy Builder — GDPR + CCPA Compliant prompt?

Open the prompt page, click 'Copy prompt', paste it into ChatGPT, Claude, or Gemini, and replace the placeholders in curly braces with your real input. The prompt is also launchable directly in each model with one click.

Which AI model works best with Privacy Policy Builder — GDPR + CCPA Compliant?

Claude Opus 4 or Sonnet 4.5. Privacy policy requires legal + technical understanding. Top-tier reasoning matters. NOT legal advice.

Can I customize the Privacy Policy Builder — GDPR + CCPA Compliant prompt for my use case?

Yes — every Promptolis Original is designed to be customized. Key levers: NOT legal advice. Attorney review for final policy. Privacy breaches have 4% of global revenue fines under GDPR.; Plain language beats legalese. 'We collect X because Y' beats '[data] processing activities shall be governed by...'

Explore more Originals

Hand-crafted 2026-grade prompts that actually change how you work.

← All Promptolis Originals