Since March 2026, European data protection authorities have been coordinating their review of a single document: the Privacy Policy. The fifth Coordinated Enforcement Framework (CEF) focuses on the information requirements under Articles 12 to 14 of the GDPR, with 25 supervisory authorities taking part, including German state authorities. And the most common shortcoming they find is not a forgotten clause, but a privacy policy that does not reflect the reality of the website.
This makes the issue topical, but the obligation is long-standing. Anyone who operates a website or an online shop processes personal data from the moment the page is first accessed: At the very least, the IP address and the server log entry constitute personal data. This gives rise to a duty to provide information under Article 13 of the GDPR, and the privacy policy is the document through which you fulfil this duty.
This article clarifies a narrowly defined question: what content must be included in a privacy policy for a website and an online shop, and what has changed in the regulatory framework? This concerns the document itself, not the cookie banner. We deal with the mechanics of consent – that is, when you need an opt-in under Section 25 of the TDDDG and what a banner must look like – separately at legally compliant tracking and cookie consent. Both topics are interlinked, but legally they are two different matters. And first of all: this is a technical guide, not legal advice in individual cases.
What the privacy policy is, legally speaking, and what it isn’t
First, let’s clarify the distinction, as there’s a lot of confusion here. The privacy policy is an duty to provide information, not a means of obtaining consent. It informs the data subject about what data you process and for what purpose. It does not seek consent. Nobody ‘accepts’ a privacy policy. That is the difference between it and the cookie banner, which collects active consent.
It must also be distinguished from the legal notice and the terms and conditions. The legal notice governs the provider identification in accordance with the Digital Services Act, whilst the terms and conditions govern the contractual relationship. The privacy policy governs exclusively the handling of personal data. Three documents, three legal bases, three purposes. They should not be combined.
Legally, it is based on two provisions. Article 13 of the GDPR applies when you collect data directly from the individual, which is the norm on the web: someone visits the site, fills in a form, places an order. Article 14 of the GDPR applies when you obtain data about a person from another source, such as a credit reference. For most websites, Article 13 is the key provision; online shops also regularly fall under Article 14.
The mandatory information under Article 13 of the GDPR
Article 13 provides an exhaustive list of the minimum content required. If any of these points are missing, the privacy policy is incomplete. This is not a procedural error, but a breach of the duty to provide information, which, under Article 83(5)(b) of the GDPR, falls within the upper fine bracket: theoretically up to 20 million euros or 4 per cent of global annual turnover. In practice, a medium-sized business rarely reaches this maximum threshold. More relevant is the lower-threshold risk: formal warnings and claims for damages, which can apply even in the case of minor shortcomings.
The following information is mandatory:
| Mandatory information | What specifically needs to be included |
|---|---|
| Data controller | Name and full contact details of the body responsible for deciding on the processing |
| Data Protection Officer | Contact details, where a DPO must be appointed or has been appointed voluntarily |
| Purposes and legal basis | Each processing operation, together with its purpose and the relevant legal basis under Article 6 of the GDPR |
| Legitimate interest | If you rely on Article 6(1)(f), you must specify the specific interest |
| Recipients | Recipients or categories of recipients to whom data is disclosed |
| Transfers to third countries | Transfers to countries outside the EU/EEA, including the legal basis for the transfer |
| Retention period | The duration or, where this is not possible, the criteria for determining the duration |
| Data subjects’ rights | Right of access, rectification, erasure, restriction, data portability, and objection |
| Withdrawal | The right to withdraw consent at any time |
| Right to lodge a complaint | The right to lodge a complaint with a supervisory authority |
| Obligation to provide data | Whether the provision of data is mandatory or necessary for a contract, and what happens if data is not provided |
| Automated decision-making | Information on automated decision-making, including profiling, where applicable |
The most common mistake is not a missing item from this list, but a statement that describes something other than what the website actually does. A template generated by a tool lists tools that you do not actually use, whilst making no mention of the three that are actually in use. This is precisely what stands out as soon as someone examines the page with the intention of checking it, be it a regulatory authority in the ongoing CEF, a competitor or a warning letter organisation: a listed tool that isn’t integrated anywhere, or an integrated tool that’s missing from the statement. Both are visible from the outside.
Why the authorities will be looking closely at this in 2026
The reason why the privacy policy deserves attention right now is not because of a new law, but because of supervisory practice. The CEF mentioned at the outset is a coordinated audit exercise: the participating authorities use the same set of questions to review the privacy policies within their remit. The audit does not check whether a policy exists at all, but whether it is fit for purpose.
Three criteria take centre stage. Is it complete, i.e. does it contain all the mandatory information? Is it comprehensible, i.e. written in clear, simple language in accordance with the transparency requirement of Article 12, rather than in legal jargon? And is it transparent regarding data flows from third parties, particularly in complex models such as platforms, online marketing or data-driven AI applications? The latter is a clear indication: anyone using AI functions on their website – such as a chatbot that processes user input – must clearly set this out in the privacy policy, from the processing of the input right through to the provider. We describe separately how this can be achieved in practice without falling into the typical pitfalls, including how to use AI tools in compliance with data protection regulations.
Beyond the content, the privacy policy has to be easy to find. It must be accessible from every subpage with one or two clicks, usually via a link in the footer clearly labelled ‘Privacy’ or ‘Privacy Policy’ in the footer. A hidden or creatively named link carries a risk of a warning letter, in line with established case law on the accessibility of the legal notice. And it must be accessible: from 28 June 2025, the Accessibility Enhancement Act (BFSG) will apply to many online services, and a privacy policy that cannot be accessed by anyone using a screen reader does not meet the transparency requirement. We have outlined what this means in technical terms in our guide to accessibility under the BFSG.
The third-party services that affect almost every website
The bulk of a real privacy policy is not made up of abstract mandatory information, but of the specific services running on the site. Every integrated third-party service that processes data requires its own section detailing the purpose, legal basis, recipients and, where applicable, transfers to third countries. These building blocks apply to almost every website:
- Hosting and server log files. Simply visiting the site generates log data containing the IP address. The legal basis is usually the legitimate interest in secure operation.
- Web fonts. If you dynamically embed fonts from an external server, such as Google Fonts via the Google CDN, the IP address is transferred to the USA with every page view, without consent. In 2022, the Munich I Regional Court awarded a data subject 100 euros in damages for this (Case No. 3 O 17493/20), followed by a wave of warning letters. The clean solution is to host the fonts locally. This eliminates the need for data transfer, and the privacy policy becomes much shorter in this respect.
- Audience measurement and analytics. Google Analytics 4 and similar tools require consent and must be included in the policy, specifying the tool, provider, purpose and data transfer. Consent for this is obtained via the banner, not the policy.
- Newsletters. Specify the procedure, in particular the double opt-in, plus the mailing service provider and the retention period for registration data.
- Contact forms. Which fields are collected, for what purpose, and how long the enquiry is retained.
- Embedded content. Maps, videos, social media plugins, font libraries and reCAPTCHA load external resources and transfer data in the process. Each embedding constitutes a separate processing operation.
The key principle for all these elements is specificity. Effective information specifies the actual tool used and its provider, not a vague reference to ‘web analytics services’. What is in use must be included; what is not in use has no place in the statement.
Transfers to third countries in the USA: the tricky bit
As soon as a service transfers data to the USA – which is usually the case with US tools – the privacy policy must specify the legal basis for the transfer. It is important to note the current status here, as it is subject to change.
The EU-US Data Privacy Framework (DPF) has, since the adequacy decision of July 2023, formed the basis for data transfers to organisations that have obtained certification under the Framework. On 3 September 2025, the General Court of the European Union dismissed an action challenging this decision (Case T-553/23, Latombe). The decision therefore remains in force. However, an appeal was lodged with the Court of Justice of the European Union at the end of October 2025 (C-703/25 P), and the political basis of the Framework – a US executive order – is under scrutiny. A ‘Schrems III’ scenario – that is, the decision being overturned by the highest court – cannot be ruled out.
This has two implications for your privacy policy. Firstly, the check: determine whether the relevant US provider is in fact DPF-certified, and specify this basis. If it is not, you will need Standard Contractual Clauses (SCCs) plus a risk assessment as the basis for the transfer. Secondly, the wording: draft the legal basis for the transfer in such a way that it withstands any change in the legal situation. Anyone who writes “the transfer is carried out in a legally compliant manner on the basis of the DPF” and then the decision is overturned will, from one day to the next, have an incorrect document. Anyone who specifies the exact basis and updates it in the event of a change remains on the safe side. Transfers to third countries are the shakiest part of any privacy policy and should be reviewed regularly.
What an online shop needs in addition
An online shop processes significantly more data than a simple information page, and this is reflected in the privacy policy. The additional elements centre on the order and its processing.
The order processing itself is based on Article 6(1)(b) of the GDPR, namely the performance of a contract. This covers the data required for the completion of the purchase, delivery and invoicing. A clear distinction must be made regarding customer accounts: a permanent account requires its own legal basis and a statement on the retention period. And you must offer a guest checkout option. Forcing customers to create an account conflicts with the principle of data minimisation, and the supervisory authorities view this critically. This is the one area of the online shop where shortcomings are most likely to be found.
In addition, there are the service providers in the chain, and each one must be named specifically. Payment service providers such as PayPal, Klarna or Stripe receive order and payment data; each provider used must be named, along with the purpose and a reference to their own privacy policy. The same applies to delivery and logistics service providers, such as DHL for delivery and parcel tracking, which receive address details and, in some cases, contact details. Anyone carrying out a credit check – for example, when selling on account – is subject to Article 14 of the GDPR and must ensure transparency regarding the process, including the credit reference agency involved and the legal basis. In addition, depending on the setup, this includes fraud prevention, review services such as Trusted Shops, wishlists and personalisation, as well as retargeting via the Meta pixel or Google Ads, which – like all marketing tracking – requires consent. It is more cost-effective to incorporate such issues early on into e-commerce development with a security and compliance strategy than to document them retrospectively.
The quick check before going live
Before a website or online shop goes live, you can check its status with just a few points:
- Is all the mandatory information required under Article 13 in place, including data subjects’ rights and the right to lodge a complaint?
- Does the privacy notice accurately reflect the tools actually used, with no third-party tools or omissions?
- Are transfers to the US specified and supported by a specific, up-to-date legal basis (DPF certification or SCCs)?
- Are fonts hosted locally, rather than being loaded dynamically from external servers?
- In the online shop, are payment, delivery and any credit assessment service providers listed individually, and is guest checkout available?
- Is the privacy policy accessible from every subpage with one or two clicks, clearly labelled and accessible to all?
Conclusion
An effective privacy policy is not a template that you create once and then forget about, but a carefully maintained reflection of your own data processing practices. The mandatory information under Article 13 is the minimum requirement; the specific, honest description of the services used is the extra step where most fail. Two areas deserve particular attention in 2026 because they are in flux: data transfers to third countries, specifically the US, where the legal basis remains contentious, and the authorities’ expectation of genuine transparency, which is being subject to a coordinated review this year.
Ultimately, a legally sound assessment of your specific setup should be in the hands of data protection and legal experts, because whether processing is truly based on the correct legal grounds is determined on a case-by-case basis, not by a checklist. However, the greatest risk lies not in the finer details, but in the mundane. Four mistakes crop up time and again, and all four can be rectified in an hour: remotely embedded Google Fonts, a copied template that doesn’t fit the page, a hidden data protection link, and an unmentioned transfer to the US. Once you’ve sorted those out, you’ve got the bulk of it behind you.