Skip to main content
web60

Irish SME

Used ChatGPT to Write Your Website Privacy Policy and Terms? Read Them Again

Eamon Rheinisch··15 min read
Flat illustration of a paper document with wavy lines and a teal magnifying glass resting over it, set against soft teal leaf shapes

You did the sensible thing. The site was nearly ready, the footer had two empty links marked Privacy and Terms, and nobody wanted to pay a solicitor to fill them. So you opened ChatGPT, typed something like "write a privacy policy and terms and conditions for my small business website", and thirty seconds later you had two long, confident, properly formatted documents. You pasted them in. Job done.

I am not going to tell you that was foolish. It was a reasonable shortcut, and AI is a genuinely good drafting partner for a lot of business writing. But it comes up on my calls more often than you would think, and when a business owner and I actually read those two pages together, line by line, we nearly always find the same handful of problems. Some of them are harmless. A few are the kind that make you look careless, or worse, like you were trying to pull a fast one on your own customers.

So this is for you, the owner who has an AI-drafted policy sitting in the footer right now. You do not need to start again. You need an afternoon, a list, and the willingness to read your own small print.

The Document Reads Well. That Is the Trap.

The reason AI legal text is risky is not that it reads badly. It reads beautifully. It has numbered headings, defined terms, phrases like "to the fullest extent permitted by law". It looks like something a professional produced, so you skim it and move on.

But a language model does not know your business. It does not know which contact form plugin you installed, whether you take card payments, where your mailing list lives, or that you sell to customers in Ireland rather than Ohio. It fills those gaps with the most statistically likely text, and a large share of the privacy policies and terms on the internet were written for American businesses.

Even the Toolmaker Says Check It

Do not take my word for it. OpenAI's own terms of use say that using it can produce output that "does not accurately reflect real people, places, or facts", that you should not rely on it "as a substitute for professional advice", and that you "must evaluate Output for accuracy and appropriateness" before using it [3]. That is the company that built the tool telling you to read what it wrote.

None of this means you should stop using AI. I am a big believer in business owners doing more themselves, and our guide to what AI-powered WordPress means for business owners makes that case properly. The point is narrower. AI drafts. You verify. Legal pages are where skipping the second half costs the most.

Four Things AI Usually Gets Wrong for an Irish Business

You do not need to understand every clause to spot trouble. Most of the problems fall into four groups, and once you know what to look for you can find them in ten minutes.

What you might findWhy it is a problemWhat to do
References to California, US states or the FTCWrong legal system for your customersDelete and replace with GDPR wording
No mention of the Data Protection CommissionCustomers have a right to be told where to complainAdd the DPC complaint right
Tools and data you do not actually useYour policy must describe your real processingRewrite from an inventory of your site
Arbitration, foreign courts, "sole discretion"Some of these terms are always unfair under Irish lawRemove them from your terms

American Law Dressed Up as Your Policy

Search your privacy policy for "California", "CCPA", "Do Not Sell", "Federal Trade Commission", "COPPA" or "state law". If any of those appear, the model has borrowed from a US template. At best it confuses your customers. At worst it tells them about rights and complaint routes that have nothing to do with them, while leaving out the ones they actually have under GDPR.

It also tells anyone who reads it carefully that nobody at your business did. That matters more than people think. The customers most likely to read a privacy policy are exactly the ones who care how their data is handled.

The Missing Complaint Right

The Data Protection Commission publishes a plain list of what you must tell people when you collect their personal data [1]. It includes who you are and how to contact you, why you are collecting the data and your lawful basis for doing so, who else receives it, how long you keep it, the rights people have (access, correction, erasure and the rest), and the right to lodge a complaint with a supervisory authority.

That last item is the one AI drafts most often fumble. In Ireland the supervisory authority is the Data Protection Commission. Some drafts name the UK's regulator, some name a US state attorney general, and some leave it out entirely. Check yours. It is one sentence, and it is required.

A Policy for a Website You Do Not Have

This is the problem nobody spots, because the text sounds plausible. A generic AI policy will happily say you use Google Analytics, run a newsletter, use cookies for advertising and share data with "trusted partners". Maybe you do none of that. Meanwhile it says nothing about the booking plugin that stores names and phone numbers, the payment provider that processes cards, or the contact form that emails enquiries to your Gmail.

Your privacy policy is supposed to describe what your website actually does with people's information. The DPC is explicit that purposes, recipients and retention periods have to be stated. A policy describing an imaginary website does not meet that standard, however professional it sounds.

Take a piano teacher in Longford who takes term bookings and fees through their website. Their real data story is simple: parents' names, phone numbers, children's ages, and payments through one provider. An AI draft that talks about advertising cookies and marketing partners, while saying nothing about holding details of children, is not just padded. It is describing someone else's business, and leaving out the one category of data a careful parent would most want explained.

Terms That Irish Law Will Not Enforce

The terms and conditions page is where AI drafts get genuinely risky, because American consumer contracts routinely include clauses that Irish law treats as unfair. Look for any of these:

  • "Disputes will be resolved by binding arbitration"
  • "You waive the right to participate in a class action"
  • "These terms are governed by the laws of [a US state]" or "exclusive jurisdiction of the courts of [wherever you are]"
  • "We may interpret these terms at our sole discretion"

The CCPC's guidance on the Consumer Rights Act 2022 includes a "black list" of terms that are always unfair [2]. It covers terms that hinder a consumer's right to take legal action, including forcing them into arbitration not governed by law, terms giving the business the exclusive right to interpret the contract, and terms granting exclusive jurisdiction to courts where the business is based when the consumer does not live there. A consumer simply is not bound by an unfair term.

The choice-of-law clause has its own problem. Under Article 6 of the EU's Rome I Regulation, a business that directs its activities to consumers in a country cannot use a governing-law clause to strip those consumers of the protections they would have at home [4]. Putting "governed by the laws of Delaware" in your terms does nothing for you.

What This Actually Costs You

This is the part that should make you put the kettle on and open your footer links today.

Imagine a customer disputes a cancellation charge. They are annoyed but reasonable, and then they read your terms and find a clause saying all disputes go to binding arbitration under American rules. The clause is unenforceable, so it gives you no protection at all. What it does give them is the impression that you tried to sign them away from their rights. A small disagreement becomes a report to the CCPC, a review on Google, and a story told at the school gate.

The privacy side works the same way. A customer who asks what you hold about them is entitled to a straight answer. If your policy promised things you never set up, or described data sharing you do not do, you are now explaining your own document to them. That is a conversation no owner enjoys.

Flat illustration of two documents side by side, the left with teal highlighted lines and the right marked with a large teal tick
An AI draft is a starting point. The verification is your job.

None of this is likely to bring a regulator to your door tomorrow. It is a slow, quiet cost. Lost trust, avoidable disputes, and a website that tells careful readers nobody was paying attention.

How to Fix an AI-Drafted Privacy Policy in Five Steps

You can keep most of what you already have. The fix is to give the AI the facts it was missing, then verify what comes back.

  1. Inventory. Write down every tool on your website that touches customer information: contact forms, booking plugins, payment providers, mailing list services, analytics, chat widgets, embedded maps and videos.
  2. Brief. Ask the AI again, this time giving it that list, the fact that you are an Irish business selling to consumers in Ireland and the EU, and an instruction to follow GDPR and Irish consumer law, with no US references.
  3. Verify. Go through the result against the DPC's list of required information, item by item, and confirm the complaint right names the Data Protection Commission.
  4. Strip. Search your terms for arbitration, class action, foreign governing law, exclusive jurisdiction and "sole discretion", and remove anything that matches the CCPC's black list.
  5. Deploy and date. Put the updated pages on your site, add a "last updated" date at the top, and set a reminder to revisit them whenever you add a new plugin or service.

One thing to keep out of step two: customer data. You are describing your systems, not pasting in real names, emails or order details. If you are not sure why that matters, our piece on staff pasting customer data into ChatGPT explains the risk in plain terms.

What This Process Cannot Do

I want to be straight with you about the limits here. AI does not know what your plugins do with data behind the scenes, and neither will you unless you read their documentation. A booking tool might store data with a provider outside the EU, for example, and that has to be disclosed. Your inventory is only as good as your knowledge of each tool.

And there are businesses for whom an afternoon with a chatbot is not enough. If you handle health information, run subscriptions with auto-renewal, work in a regulated profession, or sell mostly to other businesses on negotiated contracts, pay a solicitor to review your terms. A solicitor's fee is cheap next to one serious dispute. The same goes for anyone who has had a complaint already. This article is a practical checklist, not legal advice.

Flat illustration of a small house shape with a teal shield on its front, surrounded by soft teal foliage on an off-white background
Fewer third-party tools on your site means fewer paragraphs to get right.

Where Your Website Platform Fits In

A lot of the length in a privacy policy comes from the tools bolted onto a site. Every extra tracker, every third-party script, every data transfer outside the EU is another paragraph you have to get right. So the ideal setup for a small business is a site where you know exactly where your data lives, the defaults do not quietly add trackers you never chose, and you can edit your own legal pages whenever you need to, without waiting on anyone or paying by the hour.

That is the standard. Web60 was built to meet it. Sites are hosted on SmartHost's sovereign Irish cloud, so data held by the website itself stays in Ireland and you are not writing a paragraph about your host shipping it overseas. Analytics are privacy-first and do not require cookie consent, which removes one of the most common cookie consent headaches, though you should still mention that analytics in your privacy policy for transparency. The DPC's cookie guidance ties consent to the technologies a site actually uses, with an exemption only for those strictly necessary to provide the service a visitor asked for [5]. Fewer tools genuinely means fewer obligations to get wrong.

And because it is full WordPress, the platform that runs roughly four in ten of all websites according to W3Techs [6], your privacy and terms pages are ordinary pages you edit yourself. Change a supplier on Tuesday, update your policy on Tuesday. If you are starting from scratch, Web60's AI builder turns a description of your business into a working WordPress site in about a minute, for €60 a year with hosting, SSL and backups included. Spend the time you save on the two pages in the footer.

The Practical Upshot

You do not need to bin your AI-drafted policy, and you do not need to feel bad about using one. You need to read it once with the right questions in mind. Does it describe your actual website? Does it name the Data Protection Commission? Does it mention any American law? Do your terms try to send disputes anywhere other than an Irish court?

Answer those four honestly and fix what you find, and your legal pages go from decoration to something that genuinely protects you. It is one afternoon. Your customers will never thank you for it, but the careful ones will notice, and they are often the ones worth keeping.

Frequently Asked Questions

Can I use ChatGPT to write my website privacy policy?

Yes, as a first draft. Give it an accurate list of the tools your site uses and tell it you are an Irish business selling to consumers in Ireland and the EU. Then verify the result against the Data Protection Commission's list of required information. OpenAI's own terms say output should not be relied on as a substitute for professional advice, so the checking is your responsibility.

Is an AI-generated privacy policy legally valid in Ireland?

The law does not care who drafted it. It cares whether it is accurate and complete. A privacy policy written by AI is fine if it correctly describes your processing, purposes, lawful basis, recipients, retention periods and people's rights, including the right to complain to the Data Protection Commission. A policy that describes tools you do not use, or omits ones you do, falls short however it was written.

What must a website privacy policy include under GDPR?

When you collect data directly from people, you must tell them who you are and how to contact you, why you are collecting the data and your lawful basis, who receives it, any transfers outside the EU, how long you keep it, their rights (access, correction, erasure, restriction, portability and objection), how to withdraw consent where relevant, and their right to lodge a complaint with the Data Protection Commission.

Can my website terms say disputes go to arbitration or a foreign court?

Not with Irish consumers. Under the Consumer Rights Act 2022, terms that hinder a consumer's right to take legal action, force them into arbitration not governed by law, or give exclusive jurisdiction to courts where the business is based when the consumer lives elsewhere are on the black list of terms that are always unfair. The consumer is not bound by them.

Do I need a cookie policy if my website uses no tracking cookies?

Consent is not required for cookies that are strictly necessary to provide the service a visitor asked for, but you still need to be open about any other cookies or similar technologies your site uses, and listing everything is good practice. Many small sites cover this in a short cookies section of the privacy policy rather than a separate page. If you are unsure whether a particular tool sets cookies, check its documentation before you write the section.

How often should I update my privacy policy?

Whenever something changes: a new plugin that collects data, a new payment provider, a new mailing list tool, or a change in how long you keep records. Add a "last updated" date to the top of the page. If nothing has changed, a quick read once a year is a sensible habit.

Sources

Eamon Rheinisch
Eamon RheinischSales Director, Web60

Eamon leads sales at Web60 and SmartHost, working directly with Irish business owners making the switch from cheap shared hosting to managed WordPress. With a background in enterprise technology sales — including Oracle and multiple Irish SaaS businesses — he understands the questions Irish SMEs ask before committing to a hosting platform. He writes about hosting comparisons, total cost of ownership, web design for Irish businesses, and how to evaluate what you’re actually buying.

More by Eamon Rheinisch →

Ready to get your business online?

Describe your business. AI builds your website in 60 seconds.

Build My Website Free →
Buy NowTry Free
ChatGPT Privacy Policy and Terms: What to Fix | Web60