Privacy Policy Analyzer
Paste your privacy policy and receive a compliance gap analysis against GDPR, CCPA/CPRA, and general best practices. Identifies missing required disclosures, incomplete sections, and priority fixes. Adapted from Anthropic's claude-for-legal privacy skill.
Drag & drop a file here, or click to browse
Your content stays private. What you paste or upload is sent directly to Claude (Anthropic's AI) to generate the analysis — it is never stored on our servers, logged to a database, or seen by our team. Anthropic processes it under their Privacy Policy. Treat this like any Claude.ai session: confidential documents are safe to use, but for highly sensitive matters we always recommend consulting your firm's AI use policy.
Not legal advice. This tool is for informational and research purposes only. AI outputs must be reviewed by a licensed attorney before any reliance. Do not input confidential client information. Outputs are generated by Claude and may contain errors.
What Is the Privacy Policy Analyzer?
Privacy regulations have created a complex web of disclosure requirements that privacy policies must satisfy. The GDPR requires companies to disclose the lawful basis for processing, data subject rights, international transfer safeguards, and retention periods. CCPA/CPRA adds California-specific requirements including the right to opt out of sale, the right to limit use of sensitive personal information, and mandatory disclosures about data sharing. A privacy policy that was adequate in 2020 may be materially non-compliant today.
This tool analyzes your privacy policy against the key requirements of GDPR (for EU/UK operations), CCPA/CPRA (for California residents), and general privacy best practices. It produces a gap analysis identifying: sections that are missing entirely, sections that are present but incomplete, disclosures that are legally required but absent, and specific priority fixes ranked by regulatory risk.
The analysis covers the major required disclosures: what data you collect and why, the legal basis for processing (GDPR), how data is used and shared, data retention periods, user/consumer rights (access, deletion, correction, portability, opt-out), how to exercise rights, contact information for a privacy officer or DPO, international data transfer mechanisms, and cookie and tracking disclosures.
This tool was adapted from Anthropic's open-source claude-for-legal privacy skill library (Apache 2.0). It provides a preliminary gap analysis and is not a substitute for review by a qualified privacy attorney or certified privacy professional (CIPP). Privacy law varies by jurisdiction and is rapidly evolving. Do not paste privacy policies containing real user data.
Example Output
How to Use This Tool
- 1Paste your current privacy policy text (or a draft policy if you are writing one from scratch)
- 2Optionally note which regulations are most relevant to your business (GDPR, CCPA, both, or other) and whether you process sensitive categories of personal data
- 3Click 'Generate Compliance Gap Report' and allow 25–40 seconds
- 4Review the gap analysis section by section, prioritize the 'critical' and 'high priority' fixes, and work with a privacy attorney to implement the required changes
Who This Tool Is For
- ✓Startups conducting a pre-launch privacy policy review before going live
- ✓In-house legal and privacy teams auditing an existing privacy policy for GDPR or CCPA compliance gaps
- ✓Small businesses assessing whether their privacy policy meets basic legal requirements
- ✓Product managers and engineers reviewing data practices against policy disclosures
- ✓Compliance teams preparing for privacy audits or regulatory inquiries
- ✓Legal counsel reviewing a target company's privacy posture during M&A due diligence
Frequently Asked Questions
What privacy laws does this tool check against?
The tool primarily checks against GDPR (EU/UK General Data Protection Regulation) and CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act). It also applies general privacy best practices relevant across most jurisdictions.
My business is small. Do I really need to comply with GDPR?
GDPR applies to any organization that processes personal data of EU/UK residents, regardless of where the organization is based. If your website or service is accessible to EU/UK users and collects any personal data (including IP addresses via cookies), GDPR requirements may apply. Consult a privacy attorney if you are unsure.
What is the difference between CCPA and CPRA?
The CCPA (effective 2020) established foundational California consumer privacy rights. The CPRA (effective 2023) significantly expanded those rights, adding the right to correct data, the right to limit use of sensitive personal information, and creating the California Privacy Protection Agency (CPPA) as a dedicated enforcement body. The tool accounts for CPRA requirements.
Does this tool check for cookie consent compliance?
Yes — the tool reviews cookie and tracking disclosures in your privacy policy, including whether you disclose the categories of cookies used, provide an opt-out mechanism, and comply with GDPR consent requirements for non-essential cookies. However, a full cookie compliance review requires assessment of your actual cookie implementation, not just your policy text.
Is this tool free?
Yes — completely free, no signup required. Powered by Claude AI.
