Free Data Governance Templates

Data Governance: 86 free templates to browse without an account, then edit with an AI agent and e-sign in GitLaw.

This category provides frameworks for handling sensitive information across jurisdictions like the European Union, United States, and Canada. It includes specialized templates such as the HIPAA Business Associate Agreement for healthcare data and the California Resident Notice at Collection for CPRA compliance. Employment and account management records fall here, but generic commercial contracts reside in the main Business category.

  • 86 templates
  • Free to edit with AI
  • No account needed to browse

Community library

Everything else in this category, uploaded by the GitLaw community. Read any of it free - check it fits your situation before you rely on it.

US
Recruitment Privacy Policy (Basecamp)
This recruitment privacy policy informs job applicants about how their data is collected, stored, and managed during the hiring process. It covers data collection through applicant tracking systems, retention periods for candidates who reach interview stages, and procedures for data access or deletion.
Updated 13 Aug 2026
California (US)
California Resident Notice at Collection (CCPA) (Basecamp)
This privacy notice informs California residents about the personal information a business collects at or before the point of collection. It specifically outlines categories of data, purposes of use, and sharing practices to comply with the California Consumer Privacy Act (CCPA).
Updated 13 Aug 2026
US
Subscription Services and Privacy Notice by Mozilla
This privacy notice details how user data is collected and processed across specific Subscription Services such as VPN, account monitoring, and email/phone masking. It outlines data sharing practices with third-party partners like Mullvad, Stripe, and Twilio while providing opt-out mechanisms for telemetry and analytics.
Updated 13 Aug 2026
US
Ad-Targeting Guidelines by Mozilla
These guidelines establish privacy-focused rules for digital marketing campaigns, specifically prohibiting intrusive retargeting and cross-device tracking. It lists approved contextual and technical targeting methods for agencies working on behalf of a company.
Updated 13 Aug 2026
England & Wales
Data Breach Notification Policy
This internal policy outlines how an organisation identifies, investigates, and reports personal data breaches to the Information Commissioner's Office (ICO). It establishes a 72-hour reporting window for high-risk incidents and mandates the maintenance of a comprehensive Data Breach Register for all security events.
Updated 13 Aug 2026
Thunderbird Privacy Notice by Mozilla
This privacy notice explains how a software application collects, handles, and shares user data to improve performance and manage communications. It details what technical and interaction data is gathered and specifies that sensitive content like email messages and contacts are stored locally and never sent to the company.
Updated 13 Aug 2026
Data Protection Addendum (DPA)
This data protection addendum establishes the legal framework for processing personal data in connection with a cloud services agreement. It defines the roles of Controller and Processor while setting out specific obligations for subprocessor management, security incident response, and cross-border data transfers.
Updated 13 Aug 2026
US
Websites, Communications & Cookies Privacy Notice by Mozilla
This privacy notice outlines how a company handles information collected through its websites, mobile apps, and digital communications. It covers data collection for job applications, contributor profiles, and payment processing while explaining the use of cookies and tracking tools.
Updated 13 Aug 2026
Privacy Policies Github Subprocessors (GitHub)
This document lists authorized subprocessors permitted to handle personal and customer data on behalf of an enterprise service provider. It includes a structured table for detailing the processor name, location, and the specific nature of data processing activities.
Updated 13 Aug 2026
Denmark
Privacy Policy (Denmark) by Seedsummit
This internal data protection policy establishes how a company manages personal information in compliance with the EU General Data Protection Regulation. It defines processing principles such as data minimization and storage limitation, and outlines the responsibilities of a designated IT systems administrator in Denmark.
Updated 13 Aug 2026

Browse other categories

Cybersecurity
314 documents
Data Breaches & Incident Management
66 documents

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by 5,000+ businesses

Nexus logoMlabs logoTechstars logo

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work,
with practicing lawyers

Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Ready to get started?

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.