PPolicy Generatorby Philip George Advisory
Free SnapshotSign in

Help

How the Policy Generator works, and a plain-English glossary of the terms it uses. Everything here is guidance, not legal advice.

Getting started

What does this tool do?
It turns a short set of plain-English questions into tailored EU AI Act and GDPR policies, and — behind each policy — a compliance assessment that tracks the steps you still need to take. You keep a living register of your AI tools, and everything updates as your tools and the rules change.
How do I start?
Add the AI tools your team uses to the Tool Register (start typing — common tools pre-fill). Then choose a policy and answer the wizard. Your document builds live as you go; you only pay when you download.
What do I actually get?
A staff-facing policy in plain English (Word + PDF), a plain-English summary of what you've committed to, and — for the AI Usage pack — an EU AI Act compliance assessment with a prioritised action plan.
I don't know how to answer a question.
Look for the ⓘ icon next to a term for a plain-English explanation. On the harder questions you can request a fixed-fee human review from Philip George Advisory — the answers are guidance, not legal advice.
Is my data safe?
Your data is hosted in the EU/EEA. The tool only asks for what a policy needs, and you can export or delete your account data.

Step-by-step guides

Add a tool to your register
  1. Open Tool Register from the left menu and click Add tool.
  2. Start typing the tool's name — common tools pre-fill their details for you.
  3. Confirm or edit the department, data it touches, and — for your own contract — whether a DPA is in place and where the data is hosted.
  4. Click Add to register. It now feeds your policies and assessment automatically.
Generate a policy
  1. Click Generate policy and choose the policy you need (start with the AI Usage Policy).
  2. Answer the plain-English questions one at a time — the document builds live on the right.
  3. Look for the ⓘ icon beside any term you're unsure about for a plain-English explanation.
  4. Your progress saves automatically, so you can leave and come back. Click Finish when you're done.
Read and close your gap actions
  1. Open Gap Actions to see the compliance steps found from your answers.
  2. Each action has a severity, a plain-English recommendation, and the legal basis behind it.
  3. Set an action's status as you work through it: open, in progress, or done.
  4. Clearing every high-severity action returns you to an AI-safe status on your dashboard.
Download and adopt your policy
  1. Open a policy and pay once to unlock the download (the preview and summary are free).
  2. Download the Word and PDF, plus the plain-English summary of what you've committed to.
  3. Circulate the policy to staff and keep a record that they've read it.
  4. Revisit every six months — or sooner if your tools change — and regenerate to a new version.

Glossary (29)

Plain-English definitions of the compliance terms
72-hour breach rule
If a data breach risks harm to people, you must tell the Data Protection Commission within 72 hours of becoming aware of it.
GDPR Art. 33
AI literacy (Article 4)
Making sure staff who use AI understand what it can and can't do, and its risks — with a record that you trained them.
Why it matters — In force since February 2025 and applies to every organisation using AI.
EU AI Act Art. 4
Annex III category
The EU AI Act lists specific high-risk uses in its Annex III — for example recruitment, credit scoring, or education. This records which one applies.
EU AI Act Annex III
Article 9(2) condition
The specific extra permission you need to handle special-category data — for example explicit consent, or providing health care. A normal lawful basis alone isn't enough.
GDPR Art. 9(2)
Automated decision-making
A decision about a person made by software with no meaningful human involvement — for example auto-rejecting an application.
Why it matters — People have a right to human review of such decisions.
GDPR Art. 22
CE mark
A stamp the maker puts on a product to say it meets EU rules. For a high-risk AI tool you should see it before you rely on it.
Why it matters — The Act asks deployers to check it before using a high-risk system.
EU AI Act Art. 13
Data-subject request
When someone asks to see, correct, or delete the personal data you hold about them. You must respond within one month.
GDPR Art. 12–22
Declaration of conformity
A document from the tool's maker formally stating it meets the EU AI Act's requirements. You obtain and keep a copy.
Why it matters — It is the maker's evidence that a high-risk system is compliant.
EU AI Act Art. 13
DPA (Data Processing Agreement)
The contract GDPR requires with any supplier that handles personal data for you. It binds them to protect it and only use it as you instruct.
Why it matters — Processing personal data through a tool with no DPA is a live GDPR gap.
GDPR Art. 28
DPIA
A Data Protection Impact Assessment — a structured check you do before high-risk data processing, to find and reduce risks to people.
Why it matters — Mandatory for certain processing, such as large-scale health data.
GDPR Art. 35
EU AI Act risk tier
How risky a use is under the EU AI Act: minimal, limited (needs transparency), or high (strict obligations).
EU/EEA data residency
Whether the tool stores and processes your data inside the EU/European Economic Area. Data leaving the EEA needs a legal safeguard.
GDPR Art. 44–49
FRIA
A Fundamental Rights Impact Assessment — a check of how a high-risk AI system could affect people's rights, done before you deploy it. Mainly for public bodies and similar.
Why it matters — Required for some deployers before a high-risk system goes live.
EU AI Act Art. 27
GPAI
A general-purpose AI model — a broad model like the one behind ChatGPT or Copilot that can do many things, rather than one narrow task.
Why it matters — Using a GPAI tool brings extra transparency and literacy duties.
EU AI Act Art. 52
High risk
Uses the EU AI Act treats as high-risk — recruitment, credit, health, education, biometrics. They carry the strictest obligations.
EU AI Act Annex III
Human oversight
A named person with the authority to watch over a high-risk AI system and step in — no important decision is left to the machine alone.
EU AI Act Art. 26(2)
Impact
How bad it would be if the risk happened, from 1 (negligible) to 5 (severe — a serious fine or real harm).
Instructions for use
The maker's official guidance on how to run the tool safely and correctly. You must obtain them and follow them.
EU AI Act Art. 26(1)
Lawful basis
The legal reason you're allowed to use someone's personal data — such as their consent, a contract, or a legitimate interest. Every use needs one.
GDPR Art. 6
Likelihood
How probable the risk is, from 1 (rare) to 5 (almost certain). Your best judgement is fine.
Limited risk
Customer-facing AI like chatbots or AI-written content. The main duty is transparency — telling people they're dealing with AI.
EU AI Act Art. 50
Logs
Records the AI system keeps of how it operated. For high-risk systems you retain these, as far as you technically can.
EU AI Act Art. 26(6)
Prohibited practices
A short list of AI uses the EU bans outright — such as manipulative systems, social scoring by authorities, or untargeted biometric surveillance. You confirm you use none.
EU AI Act Art. 5
Record of Processing Activities
A written record of what personal data you hold, why, and who you share it with. Think of it as an inventory of your data use.
GDPR Art. 30
Risk score
Likelihood multiplied by Impact, from 1 to 25. Higher scores need faster action: 16+ is Critical, 10–15 High, 5–9 Medium.
Sanctioned
Whether IT has formally approved the tool for work use. 'Unknown' is common — and itself worth flagging.
Special-category data
Extra-sensitive personal data — health, biometrics, race, religion, sexuality and the like. It needs stronger protection and an extra legal condition.
GDPR Art. 9
Standard Contractual Clauses
EU-approved contract terms that let you send personal data outside the EEA lawfully. One of the accepted safeguards for a transfer.
GDPR Art. 46
Subprocessor
A supplier your supplier uses to help handle your data — for example the cloud host behind a SaaS tool. They need to be covered too.
GDPR Art. 28

Still stuck? Philip George Advisory offers a fixed-fee review — philip@pgadvisory.io. Or sign in to get started.