Data Protection HubIndividual TopicsTransparency Obligations

Privacy Policy and Information Obligations (Articles 12 to 14 GDPR)

When a privacy policy is required, which mandatory items of information it must contain and how it is structured: an overview of the information obligations under Articles 12, 13 and 14 GDPR.

The privacy policy is the central instrument through which the controller fulfills its information obligations. What it must contain follows from Article 13 GDPR (collection from the data subject) and Article 14 GDPR (collection from other sources); how the information is to be prepared and provided is governed by Article 12 GDPR. The term privacy notice is more apt than "privacy policy", because what is involved is pure information, not a declaration or an approval on the part of the data subject.

Key takeaways

  • The trigger is the collection of data: where data are collected from the data subject, Article 13 GDPR applies; where they are obtained from other sources, Article 14 GDPR applies.
  • The information must in principle be provided at the time of collection (Article 13) or, respectively, within a short period after the data have been obtained (Article 14).
  • Its content consists of fixed mandatory items of information (controller, purposes, legal basis, recipients, storage period, rights and others), set out separately for direct collection and for collection from third parties.
  • What is involved is pure information, not consent: no checkbox, no tying it to the conclusion of a contract.
  • An infringement is subject to administrative fines (Article 83(5)(b) GDPR); the information must be provided free of charge.

1. When a privacy policy is required

1.1 Trigger: direct collection or collection from third parties

The information obligation attaches to the collection of personal data. What matters is where the data come from:

  • Collection from the data subject (Article 13 GDPR): the data subject is the source, for example when completing a form, on registration or through observation of their behavior (video surveillance, sensors, tracking). The information must be provided at the time of collection.
  • Collection from other sources (Article 14 GDPR): the data originate from third parties, from publicly accessible sources or from data brokers. The information must be provided within a reasonable period, at the latest within one month, and in certain circumstances earlier.

A privacy policy is therefore not owed "for the website" or "for the company", but for every processing operation that collects personal data. In practice, the information relating to many processing operations of the same kind is bundled into a single document.

1.2 Typical areas of application

It makes sense to organize the notices by target group and to keep separate notices available for particular processing situations.

LevelExamples
General notices by target groupCustomers and business partners, employees, applicants, website visitors
Specific services and offeringsApps, web applications (SaaS, cloud), online shop, newsletter, user account
Particular processing situationsVideo surveillance, guest Wi-Fi, time recording, photographs at events

A general privacy policy covers the standard cases; for situations that the data subject does not readily expect, separate notices provided close to the context are required (on this, see design and practice).

1.3 Pure information, not an approval

The privacy policy informs; it does not require any approval. For practice, it follows that:

  • No checkbox for the privacy policy on registration. Anyone who requires a confirmation box suggests a consent that is neither necessary nor intended here (on this, see consent as a legal basis).
  • Not part of the contract. General terms and conditions should at most contain a reference to the privacy notice, not its content.
  • Free of charge. The information may not be made conditional on a payment or on the purchase of a service (Article 12(5), first sentence, GDPR).

2. What purposes it serves

The privacy policy fulfills several functions at once, which should be kept in mind when drafting it:

  • In relation to data subjects: information and external presentation; it is the precondition for data subjects being able to exercise their rights at all.
  • In relation to supervisory authorities: safeguarding the organization and avoiding fines; missing or incomplete information is subject to an administrative fine in its own right (Article 83(5)(b) GDPR).
  • In relation to competitors and lawyers: reducing the risk of cease-and-desist warnings and claims for damages.
  • For the company itself: anyone who prepares the privacy policy carefully has to think through their own processing operations, their purposes and their legal bases. The document is therefore also an internal tool for review and structuring.

3. Which items of information it must contain

The following overview assigns each mandatory item of information to its legal basis and shows whether it is owed in the case of direct collection or of collection from third parties. The last column indicates when the item may exceptionally be omitted. The details, examples and the do's and don'ts are set out on the linked sub-pages.

Mandatory item of informationDirect collection (Article 13)Collection from third parties (Article 14)May be omitted where
Controller (name, contact details, representative where applicable)(1)(a)(1)(a)already known
Data protection officer (contact details)(1)(b)(1)(b)no DPO / already known
Purposes and legal basis(1)(c)(1)(c)already known
Legitimate interests (where Article 6(1)(f) applies)(1)(d)(2)(b)processing not based on point (f)
Recipients or categories of recipients(1)(e)(1)(e)no disclosure / already known
Transfer to a third country and safeguards(1)(f)(1)(f)no third-country element
Storage period or criteria(2)(a)(2)(a)(narrowly) dispensable
Data subject rights and right to lodge a complaint(2)(b), (d)(2)(c), (e)already known
Withdrawal of consent(2)(c)(2)(d)no consent relied on
Obligation to provide the data and consequences(2)(e)not applicabledirect collection only
Automated decision-making and logic involved(2)(f)(2)(g)no such processing
Categories of personal data processednot applicable(1)(d)third-party collection only
Source of the datanot applicable(2)(f)third-party collection only

For each mandatory item of information it is worth carrying out an assessment against four states: information provided (the item appears in the notice), already known (the person already has it, Article 13(4) or Article 14(5)(a)), dispensable (conceivable only for individual items under paragraph 2) or exception (only in the case of collection from third parties, Article 14(5)). This makes it possible to document cleanly, for each processing operation, why an item was included or why it may be absent.

4. Structure of this chapter

5. Primary sources

Über den Autor

Über den Autor

Dieser Beitrag wurde von Dr. Thomas Helbing, Fachanwalt für IT-Recht in München, verfasst.

Dr. Helbing wird seit 2020 durchgehend bis heute (2026) vom Handelsblatt als einer der „Deutschlands besten Anwälte" im Bereich IT-Recht und Datenschutzrecht ausgezeichnet.

Laut Kanzleimonitor.de (Ausgaben 2024–2026) zählt er zu den führenden Anwälten für Datenschutz und IT-Recht und ist unter den Top-100 Anwälten in Deutschland (2024/25) gelistet. Kanzleimonitor gilt als besonders aussagekräftige Marktstudie, da sie ausschließlich auf persönlichen Empfehlungen von Unternehmensjuristen basiert.

Dr. Helbing verfügt über langjährige Beratungserfahrung im Datenschutz- und IT-Recht und berät Mandanten unterschiedlichster Größen, vom Startup über wachstumsstarke SaaS-Unternehmen und Unicorns bis hin zu internationalen Konzernen.

Sein beruflicher Hintergrund umfasst das gesamte Spektrum der Praxis im IT- und Technologierecht. Er begann seine Laufbahn in einer internationalen Großkanzlei, sammelte anschließend Inhouse-Erfahrung in einem DAX-Unternehmen und ist selbst Unternehmer und Gründer mehrerer digitaler Projekte. Darüber hinaus verfügt er über praktische Programmiererfahrung, wodurch er technische Systeme, Softwarearchitekturen und digitale Geschäftsmodelle nicht nur juristisch, sondern auch aus technischer Perspektive versteht.

Zu seinen Mandanten zählen seit vielen Jahren unter anderem Technologieunternehmen und SaaS-Anbieter, führende deutsche Forschungseinrichtungen sowie eine systemrelevante deutsche Großbank. Seine Beratungsschwerpunkte liegen insbesondere in den Bereichen DSGVO-Compliance, Datenökonomie, SaaS, KI-Regulierung und IT-Vertragsrecht.