Skip to content
Logo von nextlevels
Request a project
Back to the wiki

Privacy Policy

A privacy policy is the document through which the operator of a website or online shop fulfils their legal obligation to provide information under the General Data Protection Regulation (GDPR). It informs data subjects about which personal data is processed, for what purpose, on what legal basis and by whom; to which recipients it may be disclosed; and what rights data subjects are entitled to. It is crucial to clarify the terminology, which is constantly confused in practice: The privacy policy is an duty to provide information, not an consent form. It informs – it does not seek consent. Nobody “accepts” a privacy policy; that is the role of the cookie banner.

A privacy policy is mandatory for almost every website, as personal data is generated from the very first time a page is accessed: at the very least, the IP address and the server log entry constitute personal data. Anyone operating a website without providing a comprehensive and comprehensible privacy policy is in breach of the GDPR’s duty to provide information – and risks fines and formal warnings. The legal basis is provided by Article 13 of the GDPR (data collected directly from the data subject) and Article 14 of the GDPR (data from another source).

The privacy policy is based on two closely related provisions, which differ only in terms of the data source. Article 13 of the GDPR applies when data is collected directly from the data subject – which is usually the case on the web: someone visits a page, fills in a contact form or places an order. Article 14 of the GDPR applies when a company receives data about a person from another source, such as from a credit reference agency as part of a credit check. For purely informational websites, Article 13 is the key provision; online shops also regularly fall under Article 14.

Both provisions require that the information be available at the time of collection – i.e. usually when the website is visited – and is easily accessible. These are supplemented by the transparency requirement of Article 12 of the GDPR, which calls for a “precise, transparent, comprehensible and easily accessible form in clear and plain language”. A privacy policy that is buried in a wall of legal jargon or can only be accessed via roundabout routes does not meet this requirement.

What mandatory information must it contain?

Article 13 of the GDPR provides an exhaustive list of the minimum content required. If any of these points are missing, the privacy policy is incomplete and therefore flawed. The following overview summarises the mandatory components.

Mandatory information in a privacy policy under Article 13 of the GDPR
Mandatory informationWhat specifically must be included
Data controllerName and full contact details of the body responsible for deciding on the processing
Data Protection OfficerContact details, where a DPO must be appointed or has been appointed voluntarily
Purposes & Legal basisEach processing operation, including its purpose and the associated legal basis in accordance with Article 6 of the GDPR
Legitimate interestWhere Article 6(1)(f) applies, specify the specific interest
RecipientsRecipients or categories of recipients to whom data is disclosed
Transfers to third countriesTransfers outside the EU/EEA, including the legal basis
Retention periodDuration or, where this is not possible, the criteria for determining it
Data subjects’ rightsRight of access, rectification, erasure, restriction, data portability, objection
WithdrawalRight to withdraw consent at any time
Right to lodge a complaintRight to lodge a complaint with a supervisory authority
Obligation to provide dataWhether the provision of data is mandatory or contractually required, and the consequences of failure to provide it
Automated decision-makingNotice regarding automated decision-making, including profiling, where applicable

The most common mistake here is not an omission from this list, but a statement that describes something other than what the website actually does. A template generated by a tool lists tools that are not actually used, whilst making no mention of those that are actually in operation. An effective privacy policy is therefore not a standard text block, but an accurate reflection of the actual data processing taking place.

Three mandatory elements of a website are regularly conflated, even though they are based on different legal foundations and serve different purposes.

  • The legal notice governs the identification of the provider in accordance with the Digital Services Act (DDG). It states who is behind the website.
  • The privacy policy governs exclusively the handling of personal data. It provides information, but does not seek consent.
  • The cookie banner obtains active data protection consent for non-essential cookies and tracking – this is a consent tool, not an information tool.

Three documents, three legal bases, three purposes: they must not be combined. The Privacy Policy must be accessible from every subpage with one or two clicks, usually via a link in the footer clearly labelled ‘Privacy’. A hidden or creatively named link carries a risk of a warning letter.

Privacy policy in an online shop: a practical example

An online shop processes significantly more personal data than a purely informational website, and this is reflected in the privacy policy. The order processing itself is based on Article 6(1)(b) of the GDPR (performance of a contract) and includes data relating to the completion of the purchase, delivery and invoicing. If the shop integrates a payment service provider such as PayPal, Klarna or Stripe, that provider receives order and payment data – each provider used must be named, along with the purpose and a reference to their own privacy policy. The same applies to the delivery service provider (such as DHL), which receives address details and, in some cases, contact details for delivery. If the shop carries out a credit check via a credit reference agency for purchases on account, this falls under Article 14 of the GDPR and must be disclosed transparently, including the name of the credit reference agency and the legal basis. If a permanent customer account is offered, it must be possible to place an order as a guest – requiring customers to create an account conflicts with the principle of data minimisation. In addition, depending on the setup, there may be newsletters (double opt-in), product reviews and retargeting, which, like any marketing tracking, requires consent and must be covered by a data processing agreement where a service provider processes data on behalf of the shop.

Transfers to third countries and the US connection

As soon as an integrated service transfers data to a country outside the EU – which is the norm for US tools – the privacy policy must specify the legal basis for the transfer. In practice, this is either certification of the provider under the EU-US Data Privacy Framework (DPF) or, if this is not available, the conclusion of Standard Contractual Clauses (SCCs) together with a risk assessment. As the legal situation regarding transfers to the US is evolving, the basis for the transfer should be worded in such a way that it withstands any changes: specify the specific legal basis and update it should it change, rather than writing a blanket statement such as “legally compliant on the basis of the DPF”.

Common mistakes in practice

Four mistakes occur particularly frequently and are, at the same time, easily avoidable:

  • Remotely embedded fonts: If Google Fonts are loaded dynamically from an external server, the IP address is transmitted to the USA every time the page is accessed – without consent. The clean solution is local hosting.
  • Copied template: A template that does not fit the page lists third-party tools whilst omitting the actual ones.
  • Hidden link: A privacy policy that is not clearly labelled or is difficult to access breaches the requirement for transparency.
  • Unmentioned US data transfer: An integrated US tool without any indication of the legal basis for the transfer is a clear shortcoming.

The fact that such shortcomings are becoming increasingly apparent is also due to supervisory practice: In 2026, as part of the fifth Coordinated Enforcement Framework (CEF), the European data protection authorities will carry out a coordinated review of the information requirements under Articles 12 to 14 of the GDPR – in other words, precisely the document at issue here.

Accessibility and availability

Part of the requirement for comprehensibility is that the privacy policy must be accessible and usable in the first place. Two requirements are key here. Firstly, accessibility: The policy must be accessible from every subpage with one or two clicks, usually via a clearly labelled footer link. A link hidden in submenus or with a cryptic name is not sufficient. Secondly, accessibility: Since 28 June 2025, the Accessibility Enhancement Act (BFSG) has applied to many online services, particularly B2C online shops. A privacy policy that cannot be read by a screen reader – for example, because it is an unstructured PDF or appears in an inaccessible overlay – does not meet the transparency requirement. Comprehensible language, a clear heading structure and semantically correct HTML are therefore not merely a matter of convenience, but part of a legal obligation.

Maintaining the privacy policy: a living document

A privacy policy is never “finished”. It reflects the actual state of data processing – and that changes. Every newly integrated tool, every additional service provider, every new tracking or marketing function, and every change to retention periods or transfers to third countries must be reflected in the policy. The area of transfers to third countries is particularly volatile: As the legal basis for transfers to the US is in flux, this section should be reviewed regularly. It has proved effective to link the privacy policy to the website’s change management process: whenever a new tool is integrated, the team checks at the same time whether the policy needs to be updated. This ensures the document remains consistent with reality – and it is precisely this consistency that most policies fail to achieve in practice.

Frequently Asked Questions (FAQ)

Is a privacy policy mandatory?

Yes. As soon as a website processes personal data – even if it is only the IP address in the server log – Article 13 of the GDPR requires that data subjects be informed. This applies to virtually every website and online shop.

The privacy policy provides information about data processing (duty to inform). The cookie banner obtains consent for non-essential cookies and tracking (consent tool). Both are necessary, but fulfil different legal functions.

Can I use a generator or a template?

As a starting point, yes, but never without modification. A template must be adapted precisely to the services, tools and data flows actually in use. The most common shortcoming is a policy that does not match the actual data processing carried out on the site.

How often does the privacy policy need to be updated?

Whenever data processing changes – for example, when integrating a new tool, service provider or tracking mechanism – and also when the legal situation changes, such as in the case of transfers to third countries. The privacy policy is a living document, not a one-off task.

What is the potential fine for an incorrect privacy policy?

Breaches of the duty to provide information fall under Article 83(5)(b) of the GDPR and are subject to the upper fine threshold of up to 20 million euros or 4 per cent of global annual turnover. In practice, the lower-threshold risk arising from warning letters and claims for damages is more relevant for most companies.

Further reading