Privacy Policy and Information Obligations (Articles 12 to 14 GDPR)
When a privacy policy is required, which mandatory items of information it must contain and how it is structured: an overview of the information obligations under Articles 12, 13 and 14 GDPR.
The privacy policy is the central instrument through which the controller fulfills its information obligations. What it must contain follows from Article 13 GDPR (collection from the data subject) and Article 14 GDPR (collection from other sources); how the information is to be prepared and provided is governed by Article 12 GDPR. The term privacy notice is more apt than "privacy policy", because what is involved is pure information, not a declaration or an approval on the part of the data subject.
Key takeaways
- The trigger is the collection of data: where data are collected from the data subject, Article 13 GDPR applies; where they are obtained from other sources, Article 14 GDPR applies.
- The information must in principle be provided at the time of collection (Article 13) or, respectively, within a short period after the data have been obtained (Article 14).
- Its content consists of fixed mandatory items of information (controller, purposes, legal basis, recipients, storage period, rights and others), set out separately for direct collection and for collection from third parties.
- What is involved is pure information, not consent: no checkbox, no tying it to the conclusion of a contract.
- An infringement is subject to administrative fines (Article 83(5)(b) GDPR); the information must be provided free of charge.
1. When a privacy policy is required
1.1 Trigger: direct collection or collection from third parties
The information obligation attaches to the collection of personal data. What matters is where the data come from:
- Collection from the data subject (Article 13 GDPR): the data subject is the source, for example when completing a form, on registration or through observation of their behavior (video surveillance, sensors, tracking). The information must be provided at the time of collection.
- Collection from other sources (Article 14 GDPR): the data originate from third parties, from publicly accessible sources or from data brokers. The information must be provided within a reasonable period, at the latest within one month, and in certain circumstances earlier.
A privacy policy is therefore not owed "for the website" or "for the company", but for every processing operation that collects personal data. In practice, the information relating to many processing operations of the same kind is bundled into a single document.
1.2 Typical areas of application
It makes sense to organize the notices by target group and to keep separate notices available for particular processing situations.
| Level | Examples |
|---|---|
| General notices by target group | Customers and business partners, employees, applicants, website visitors |
| Specific services and offerings | Apps, web applications (SaaS, cloud), online shop, newsletter, user account |
| Particular processing situations | Video surveillance, guest Wi-Fi, time recording, photographs at events |
A general privacy policy covers the standard cases; for situations that the data subject does not readily expect, separate notices provided close to the context are required (on this, see design and practice).
1.3 Pure information, not an approval
The privacy policy informs; it does not require any approval. For practice, it follows that:
- No checkbox for the privacy policy on registration. Anyone who requires a confirmation box suggests a consent that is neither necessary nor intended here (on this, see consent as a legal basis).
- Not part of the contract. General terms and conditions should at most contain a reference to the privacy notice, not its content.
- Free of charge. The information may not be made conditional on a payment or on the purchase of a service (Article 12(5), first sentence, GDPR).
2. What purposes it serves
The privacy policy fulfills several functions at once, which should be kept in mind when drafting it:
- In relation to data subjects: information and external presentation; it is the precondition for data subjects being able to exercise their rights at all.
- In relation to supervisory authorities: safeguarding the organization and avoiding fines; missing or incomplete information is subject to an administrative fine in its own right (Article 83(5)(b) GDPR).
- In relation to competitors and lawyers: reducing the risk of cease-and-desist warnings and claims for damages.
- For the company itself: anyone who prepares the privacy policy carefully has to think through their own processing operations, their purposes and their legal bases. The document is therefore also an internal tool for review and structuring.
3. Which items of information it must contain
The following overview assigns each mandatory item of information to its legal basis and shows whether it is owed in the case of direct collection or of collection from third parties. The last column indicates when the item may exceptionally be omitted. The details, examples and the do's and don'ts are set out on the linked sub-pages.
| Mandatory item of information | Direct collection (Article 13) | Collection from third parties (Article 14) | May be omitted where |
|---|---|---|---|
| Controller (name, contact details, representative where applicable) | (1)(a) | (1)(a) | already known |
| Data protection officer (contact details) | (1)(b) | (1)(b) | no DPO / already known |
| Purposes and legal basis | (1)(c) | (1)(c) | already known |
| Legitimate interests (where Article 6(1)(f) applies) | (1)(d) | (2)(b) | processing not based on point (f) |
| Recipients or categories of recipients | (1)(e) | (1)(e) | no disclosure / already known |
| Transfer to a third country and safeguards | (1)(f) | (1)(f) | no third-country element |
| Storage period or criteria | (2)(a) | (2)(a) | (narrowly) dispensable |
| Data subject rights and right to lodge a complaint | (2)(b), (d) | (2)(c), (e) | already known |
| Withdrawal of consent | (2)(c) | (2)(d) | no consent relied on |
| Obligation to provide the data and consequences | (2)(e) | not applicable | direct collection only |
| Automated decision-making and logic involved | (2)(f) | (2)(g) | no such processing |
| Categories of personal data processed | not applicable | (1)(d) | third-party collection only |
| Source of the data | not applicable | (2)(f) | third-party collection only |
For each mandatory item of information it is worth carrying out an assessment against four states: information provided (the item appears in the notice), already known (the person already has it, Article 13(4) or Article 14(5)(a)), dispensable (conceivable only for individual items under paragraph 2) or exception (only in the case of collection from third parties, Article 14(5)). This makes it possible to document cleanly, for each processing operation, why an item was included or why it may be absent.
4. Structure of this chapter
General requirements (Article 12)
How the information is prepared and provided: concise, transparent, intelligible, easily accessible; form, icons, timing, legal consequences.
Content in the case of direct collection (Article 13)
Mandatory items of information where data are collected from the data subject, information on a change of purpose and the exception for information already available.
Content in the case of collection from third parties (Article 14)
Additional items of information (categories of data, source), timing of the information and the four exceptions under paragraph 5.
Design and practice
Structure, layered approach, level of detail, means of provision, typical mistakes, updating and checklist.
5. Primary sources
Article 12 GDPR
Transparent information, communication and modalities.
Article 13 GDPR
Information to be provided where personal data are collected from the data subject.
Article 14 GDPR
Information to be provided where personal data have not been obtained from the data subject.
WP 260 rev.01
Article 29 Working Party guidelines on transparency (endorsed by the European Data Protection Board).
Über den Autor
Über den Autor
Dieser Beitrag wurde von Dr. Thomas Helbing, Fachanwalt für IT-Recht in München, verfasst.
Dr. Helbing wird seit 2020 durchgehend bis heute (2026) vom Handelsblatt als einer der „Deutschlands besten Anwälte" im Bereich IT-Recht und Datenschutzrecht ausgezeichnet.
Laut Kanzleimonitor.de (Ausgaben 2024–2026) zählt er zu den führenden Anwälten für Datenschutz und IT-Recht und ist unter den Top-100 Anwälten in Deutschland (2024/25) gelistet. Kanzleimonitor gilt als besonders aussagekräftige Marktstudie, da sie ausschließlich auf persönlichen Empfehlungen von Unternehmensjuristen basiert.
Dr. Helbing verfügt über langjährige Beratungserfahrung im Datenschutz- und IT-Recht und berät Mandanten unterschiedlichster Größen, vom Startup über wachstumsstarke SaaS-Unternehmen und Unicorns bis hin zu internationalen Konzernen.
Sein beruflicher Hintergrund umfasst das gesamte Spektrum der Praxis im IT- und Technologierecht. Er begann seine Laufbahn in einer internationalen Großkanzlei, sammelte anschließend Inhouse-Erfahrung in einem DAX-Unternehmen und ist selbst Unternehmer und Gründer mehrerer digitaler Projekte. Darüber hinaus verfügt er über praktische Programmiererfahrung, wodurch er technische Systeme, Softwarearchitekturen und digitale Geschäftsmodelle nicht nur juristisch, sondern auch aus technischer Perspektive versteht.
Zu seinen Mandanten zählen seit vielen Jahren unter anderem Technologieunternehmen und SaaS-Anbieter, führende deutsche Forschungseinrichtungen sowie eine systemrelevante deutsche Großbank. Seine Beratungsschwerpunkte liegen insbesondere in den Bereichen DSGVO-Compliance, Datenökonomie, SaaS, KI-Regulierung und IT-Vertragsrecht.
Accountability (Article 5(2) GDPR)
Accountability as a principle of the GDPR: compliance with the principles and the ability to demonstrate it, documentation obligations, retention period, burden of proof borne by the controller.
General Requirements for the Information (Article 12 GDPR)
How the privacy policy must be prepared and made available: concise, transparent, intelligible and easily accessible form, clear and plain language, the form in which the information is provided, icons, timing and the legal consequences of a breach under Article 12 GDPR.