🧰 Free Templates & Tools

Compliance Toolkit

Templates, checklists, and step-by-step guides for privacy compliance. From cookie banners to breach notification letters β€” everything you need to meet FTC, GDPR, CCPA, HIPAA, and PDPA requirements.

Building a compliant privacy program does not require a law firm retainer. For most small businesses, the gap analysis, policy creation, consent setup, and response templates can be done with the resources below β€” at no cost beyond your time.

1. Privacy Policy Generator

Your privacy policy is the most important compliance document you have. It must be accurate, complete, and written in plain language. Here is a structured template covering the essential sections required by GDPR, CCPA/CPRA, FTC Safeguards Rule, and PDPA:

Privacy Policy Structure (Template)

  1. 1. Who We Are: Company name, location, contact information, DPO contact if applicable
  2. 2. What Data We Collect: Categories β€” names, emails, payment info, IP addresses, cookies, analytics data
  3. 3. How We Collect It: Direct (forms, checkout), automatic (cookies, analytics), third-party sources
  4. 4. Why We Collect It (Legal Basis): For each purpose β€” consent, contractual necessity, legitimate interest, legal obligation
  5. 5. Who We Share It With: Service providers, payment processors, analytics, advertising networks, legal/regulatory
  6. 6. International Data Transfers: Where data goes, what safeguards apply (SCCs, adequacy decisions)
  7. 7. How Long We Keep It: Retention periods by data category and purpose
  8. 8. Your Rights: Access, correction, deletion, portability, opt-out of sale (specify which apply under which laws)
  9. 9. How to Exercise Your Rights: Contact email, web form, verification process, response timeline
  10. 10. Cookie Policy: What cookies are used, how to control them, link to consent preferences
  11. 11. Security Measures: What you do to protect data (encryption, access controls, monitoring)
  12. 12. Children's Privacy: COPPA and age-gating if applicable
  13. 13. Changes to This Policy: How you will notify users of updates
  14. 14. Contact / Complaints: How to reach you and relevant supervisory authorities

Pro tip: Do not copy-paste someone else's privacy policy. It will be inaccurate for your business β€” and an inaccurate privacy policy is worse than no privacy policy in the eyes of regulators. Use the template above as a checklist and fill it in honestly.

See Our Privacy Policy as an Example

We publish our own privacy policy as a real-world example of a small business privacy page covering GDPR, CCPA, and cookie disclosures.

View Privacy Policy Example β†’

2. Cookie Consent Banner Setup

Most privacy laws require you to obtain consent before setting non-essential cookies. Your consent banner must:

  • βœ… Block non-essential cookies until user makes a choice (not just inform)
  • βœ… Offer clear Accept All / Reject All / Customize options at equal prominence
  • βœ… Never pre-check consent boxes (invalid under GDPR)
  • βœ… Log consent with timestamp for audit purposes
  • βœ… Allow users to change their preferences easily
  • βœ… Renew consent periodically (typically every 6-12 months)

Implementation Options for Small Business

  • Free: CookieYes (free tier for < 25,000 pageviews/month), Osano (free tier)
  • Self-hosted: Build a simple consent banner with Google Consent Mode v2 (what we use on this site)
  • Google-certified CMP: If you plan to run Google AdSense, use a Google-certified Consent Management Platform (full list at Google's CMP directory)

3. Data Breach Notification Checklist

When You Discover a Breach β€” Do This Immediately:

  1. 1
    Contain. Disconnect affected systems. Reset compromised credentials. Stop the bleeding.
  2. 2
    Document. What happened, when, what data was affected, how many individuals, what you are doing about it. This will go into every notification.
  3. 3
    Notify individuals. GDPR: 72 hours to notify DPA; without undue delay if high risk. CCPA: no specific deadline but "most expedient time possible." HIPAA: 60 days to notify individuals. State breach laws: typically 30-60 days.
  4. 4
    Notify regulators. Know which regulators need to be notified and their deadlines. Map this out before a breach happens.
  5. 5
    Review. After the immediate crisis, conduct a root cause analysis. Update your security measures. Document lessons learned.

4. Data Breach Notification Letter Template

[Date]

[Recipient Name]
[Recipient Address]

RE: Notice of Data Breach

Dear [Name],

We are writing to inform you of a data security incident that may have involved your personal information. We take the protection of your data very seriously, and we sincerely apologize for any concern this may cause.

What Happened: On [date], we discovered that [describe incident in plain language β€” unauthorized access, lost device, vendor breach, etc.].

What Information Was Involved: The following types of your personal data may have been affected: [list specific data types β€” name, email, address, payment card number, SSN, etc. β€” be specific, not vague].

What We Are Doing: [List specific remedial actions β€” reset passwords, engaged cybersecurity forensics firm, reported to law enforcement, enhanced security measures].

What You Can Do: [List specific recommended actions β€” monitor your credit reports, change your password, enable MFA, place a fraud alert]. We are offering [number] months of complimentary credit monitoring through [provider]. Instructions for enrollment are attached.

For More Information: If you have any questions, please contact us at [phone] or [email], or visit [URL] for updates.

We deeply regret that this incident occurred and are committed to preventing it from happening again.

Sincerely,
[Name]
[Title]
[Company]
        

Complete Incident Response Guides

Detailed step-by-step guides for ransomware, website hacks, phishing incidents, and data breaches.

View Incident Response Center β†’

5. Regulatory Gap Analysis Worksheet

Use this worksheet to quickly assess which regulations apply to your business and where your gaps are:

Requirement FTC GDPR CCPA HIPAA Your Status
Privacy Policy postedβœ“βœ“βœ“βœ“β˜
Consent management (cookies)β€”βœ“βœ“β€”β˜
Data inventory documentedβœ“βœ“β€”βœ“β˜
Written security plan (WISP)βœ“β€”β€”β€”β˜
Risk analysis completedβœ“β€”β€”βœ“β˜
MFA on all critical systemsβœ“β€”β€”βœ“β˜
Encryption at rest and in transitβœ“βœ“β€”βœ“β˜
Data Processing Agreements / BAAsβœ“βœ“β€”βœ“β˜
Breach notification planβœ“βœ“β€”βœ“β˜
Staff security trainingβœ“β€”β€”βœ“β˜