Every employer must inform staff about how their personal data is processed. Most businesses have a decent privacy policy on their website, but the staff version is often forgotten, outdated, or an unfilled template from an HR provider. The free Staff Policy Checker tells you in two minutes where your document actually stands.
How it works
Upload your staff privacy policy as a PDF (5 MB max), that is all. The checker extracts the text, replaces email addresses and phone numbers with pseudonyms, and grades the document against 12 GDPR checks. For each check you get a verdict (pass, warning or fail), a short explanation, and verbatim quotes from your own text as evidence. No generic checklist advice: you see exactly which sentence in your document does or does not cover a requirement. The full report is usually on screen within two minutes, and you can download it as a PDF to share internally.
The 12 checks
The checks cover what a staff privacy policy must contain under the GDPR:
- Controller and scope: who is responsible, and who the policy applies to
- Categories of personal data: which employee data you process
- Processing purposes: why you process each category
- Legal bases: the correct basis per purpose (consent rarely works in employment)
- Special categories of data: health data, and the stricter rules around them
- Recipients and processors: payroll provider, insurers, IT vendors
- Transfers outside the EEA: where data goes and under which safeguards
- Retention periods: how long each category is kept
- Employee rights: access, rectification, erasure, objection, and how to exercise them
- Security and contact point: measures taken and who to contact
- Clarity and readability: can a non-lawyer understand it
- Finished and consistent document: a real policy, not a template with blanks
For the background on each of these requirements, read our guide on what an employee privacy policy must contain.
What the verdict means
No issues at all: pass. Warnings but no fundamental gaps: pass with warnings. If a core check fails, such as legal bases or employee rights, the overall verdict is fail. It remains an automated assessment by AI, not legal advice; treat it as a structured second pair of eyes, not a court-proof certificate.
What happens to your document
The PDF is not stored. Before the analysis starts, email addresses and phone numbers are replaced with pseudonyms, so they never reach the AI model in readable form. Only the graded report is kept, which is why quotes in your report may show pseudonyms instead of the original contact details.
When a checker is not enough
A checker tells you what is wrong with the document you have. It cannot write the document you need. If your policy fails, or you do not have one yet, GDPRWise generates a complete staff privacy policy from your actual HR situation: your systems, your CCTV and tracking choices, your retention periods. It is generated together with your privacy policy, processing register and the rest of your GDPR file, so the documents never contradict each other.
Upload your PDF and get the full graded report with all 12 checks within two minutes. Free, no account needed.