Philip George AdvisoryPolicy Generator

Help

How the Policy Generator works, and a plain-English glossary of the terms it uses. Everything here is guidance, not legal advice.

Getting started

What does this tool do?
It turns a short set of plain-English questions into tailored EU AI Act and GDPR policies, and — behind each policy — a compliance assessment that tracks the steps you still need to take. You keep a living register of your AI tools, and everything updates as your tools and the rules change.
How do I start?
Add the AI tools your team uses to the Tool Register (start typing — common tools pre-fill). Then choose a policy and answer the wizard. Your document builds live as you go; you only pay when you download.
What do I actually get?
A staff-facing policy in plain English (Word + PDF), a plain-English summary of what you've committed to, a Dos & Don'ts staff guide written around the specific AI tools you've registered, and — for the AI Usage pack — an EU AI Act deployer compliance assessment with a prioritised action plan.
What's the difference between the one-off packs and the subscription?
Two different questions. A one-off pack (AI Act Essentials €197, or the Complete Pack €249) gets you compliant: a full set of documents dated today, yours to download and keep for good. You can edit and regenerate them for 30 days while you settle in, after which that version is fixed. The subscription (€49/month) keeps you compliant: regenerate any time, and when the rules behind a policy change we flag it so you can bring it current, with gap tracking and alerts. Compliance is a state you maintain, not a document you file.
How many policies and versions can I have?
Version history is never capped — every version is retained as audit evidence, and you can re-download anything you're entitled to as often as you like. Documents are licensed to your organisation, so the company name on them comes from your Settings and can't be changed per policy.
I can't sign in.
Open the link in the newest sign-in email — that's the quickest way, and it signs you in on whichever device you open it on. Three things catch people out: only the most recent email works (older ones are dead), codes and links expire after a short time, and if you open the link on your phone you'll be signed in on the phone, not on a laptop waiting elsewhere. If the link says it has expired, some mail providers open links automatically to scan them, which uses the link up — request a fresh email and enter the code from it straight away.
I didn't get my sign-in email.
Check your junk folder — new sending domains often land there at first, and marking it 'not junk' helps future emails arrive properly. If it still hasn't come, request another and check the address is spelled correctly.
I don't know how to answer a question.
Look for the ⓘ icon next to a term for a plain-English explanation. On the harder questions you can request a fixed-fee human review from Philip George Advisory — the answers are guidance, not legal advice.
Is my data safe?
Your data is hosted in the EU/EEA and is never used to train AI models. You can export everything your organisation holds, or delete your account and all its data, from Settings at any time.

Step-by-step guides

Add a tool to your register
  1. Open Tool Register from the left menu and click Add tool.
  2. Start typing the tool's name — common tools pre-fill their details for you.
  3. Confirm or edit the department, data it touches, and — for your own contract — whether a DPA is in place and where the data is hosted.
  4. Click Add to register. It now feeds your policies and assessment automatically.
Generate a policy
  1. Click Generate policy and choose the policy you need (start with the AI Usage Policy).
  2. Answer the plain-English questions one at a time — the document builds live on the right.
  3. Look for the ⓘ icon beside any term you're unsure about for a plain-English explanation.
  4. Your progress saves automatically, so you can leave and come back. Click Finish when you're done.
Read and close your gap actions
  1. Open Gap Actions to see the compliance steps found from your answers.
  2. Each action has a severity, a plain-English recommendation, and the legal basis behind it.
  3. Set an action's status as you work through it: open, in progress, or done.
  4. Clearing every high-severity action returns you to an AI-safe status on your dashboard.
Download and adopt your policy
  1. Open the policy and choose a plan — a one-off pack or the subscription (the preview and summary stay free).
  2. Download the Word and PDF for each document in the pack, plus the plain-English obligations summary.
  3. Circulate the Dos & Don'ts staff guide to your team — it names your actual tools — and keep a record that they've read it.
  4. Watch for the 'Update available' banner: it appears when the rules behind your policy change.
Keep your policy current
  1. When regulations or guidance change, affected policies are flagged with what changed and why.
  2. Subscribers are kept current: open the policy and click Update — your answers are reused and a new version is saved.
  3. Every version is retained as audit evidence; nothing is ever overwritten or deleted.
  4. Review your tool register quarterly and the policy annually, even when nothing is flagged.

Glossary (29)

Plain-English definitions of the compliance terms
72-hour breach rule
If a data breach risks harm to people, you must tell the Data Protection Commission within 72 hours of becoming aware of it.
GDPR Art. 33
AI literacy (Article 4)
Making sure staff who use AI understand what it can and can't do, and its risks — with a record that you trained them.
Why it matters — In force since February 2025 and applies to every organisation using AI.
EU AI Act Art. 4
Annex III category
The EU AI Act lists specific high-risk uses in its Annex III — for example recruitment, credit scoring, or education. This records which one applies.
EU AI Act Annex III
Article 9(2) condition
The specific extra permission you need to handle special-category data — for example explicit consent, or providing health care. A normal lawful basis alone isn't enough.
GDPR Art. 9(2)
Automated decision-making
A decision about a person made by software with no meaningful human involvement — for example auto-rejecting an application.
Why it matters — People have a right to human review of such decisions.
GDPR Art. 22
CE mark
A stamp the maker puts on a product to say it meets EU rules. For a high-risk AI tool you should see it before you rely on it.
Why it matters — The Act asks deployers to check it before using a high-risk system.
EU AI Act Art. 13
Data-subject request
When someone asks to see, correct, or delete the personal data you hold about them. You must respond within one month.
GDPR Art. 12–22
Declaration of conformity
A document from the tool's maker formally stating it meets the EU AI Act's requirements. You obtain and keep a copy.
Why it matters — It is the maker's evidence that a high-risk system is compliant.
EU AI Act Art. 13
DPA (Data Processing Agreement)
The contract GDPR requires with any supplier that handles personal data for you. It binds them to protect it and only use it as you instruct.
Why it matters — Processing personal data through a tool with no DPA is a live GDPR gap.
GDPR Art. 28
DPIA
A Data Protection Impact Assessment — a structured check you do before high-risk data processing, to find and reduce risks to people.
Why it matters — Mandatory for certain processing, such as large-scale health data.
GDPR Art. 35
EU AI Act risk tier
How risky a use is under the EU AI Act: minimal, limited (needs transparency), or high (strict obligations).
EU/EEA data residency
Whether the tool stores and processes your data inside the EU/European Economic Area. Data leaving the EEA needs a legal safeguard.
GDPR Art. 44–49
FRIA
A Fundamental Rights Impact Assessment — a check of how a high-risk AI system could affect people's rights, done before you deploy it. Mainly for public bodies and similar.
Why it matters — Required for some deployers before a high-risk system goes live.
EU AI Act Art. 27
GPAI
A general-purpose AI model — a broad model like the one behind ChatGPT or Copilot that can do many things, rather than one narrow task.
Why it matters — Using a GPAI tool brings extra transparency and literacy duties.
EU AI Act Art. 52
High risk
Uses the EU AI Act treats as high-risk — recruitment, credit, health, education, biometrics. They carry the strictest obligations.
EU AI Act Annex III
Human oversight
A named person with the authority to watch over a high-risk AI system and step in — no important decision is left to the machine alone.
EU AI Act Art. 26(2)
Impact
How bad it would be if the risk happened, from 1 (negligible) to 5 (severe — a serious fine or real harm).
Instructions for use
The maker's official guidance on how to run the tool safely and correctly. You must obtain them and follow them.
EU AI Act Art. 26(1)
Lawful basis
The legal reason you're allowed to use someone's personal data — such as their consent, a contract, or a legitimate interest. Every use needs one.
GDPR Art. 6
Likelihood
How probable the risk is, from 1 (rare) to 5 (almost certain). Your best judgement is fine.
Limited risk
Customer-facing AI like chatbots or AI-written content. The main duty is transparency — telling people they're dealing with AI.
EU AI Act Art. 50
Logs
Records the AI system keeps of how it operated. For high-risk systems you retain these, as far as you technically can.
EU AI Act Art. 26(6)
Prohibited practices
A short list of AI uses the EU bans outright — such as manipulative systems, social scoring by authorities, or untargeted biometric surveillance. You confirm you use none.
EU AI Act Art. 5
Record of Processing Activities
A written record of what personal data you hold, why, and who you share it with. Think of it as an inventory of your data use.
GDPR Art. 30
Risk score
Likelihood multiplied by Impact, from 1 to 25. Higher scores need faster action: 16+ is Critical, 10–15 High, 5–9 Medium.
Sanctioned
Whether IT has formally approved the tool for work use. 'Unknown' is common — and itself worth flagging.
Special-category data
Extra-sensitive personal data — health, biometrics, race, religion, sexuality and the like. It needs stronger protection and an extra legal condition.
GDPR Art. 9
Standard Contractual Clauses
EU-approved contract terms that let you send personal data outside the EEA lawfully. One of the accepted safeguards for a transfer.
GDPR Art. 46
Subprocessor
A supplier your supplier uses to help handle your data — for example the cloud host behind a SaaS tool. They need to be covered too.
GDPR Art. 28

Still stuck? Philip George Advisory offers a fixed-fee review — philip@pgadvisory.io. Or sign in to get started.

Privacy Notice · Terms of Use · Data processing · Subprocessors