General Requirements for the Information (Article 12 GDPR)
How the privacy policy must be prepared and made available: concise, transparent, intelligible and easily accessible form, clear and plain language, the form in which the information is provided, icons, timing and the legal consequences of a breach under Article 12 GDPR.
Articles 13 and 14 GDPR determine what must be communicated to the data subject. Article 12 GDPR governs how this is done: the form, language, accessibility and timing of the information. These requirements apply to the privacy policy irrespective of whether the data are collected from the data subject or from other sources.
Key takeaways
- The information must be concise, transparent, intelligible and easily accessible and must use clear and plain language (Article 12(1), first sentence, GDPR).
- The benchmark for intelligibility is the average member of the relevant target audience; where the offering is directed at children, a stricter benchmark applies.
- Permissible forms are writing and electronic form; purely oral information is not sufficient.
- The controller must actively inform: merely keeping the information available for retrieval is not enough, the individual must actually be able to take note of it before collection.
- A breach is subject to administrative fines (Article 83(5)(b) GDPR) and, where collection depends on the will of the data subject, may render the processing unlawful.
1. Overview
Article 12(1), first sentence, GDPR requires the controller to provide all information under Articles 13 and 14 GDPR in a "concise, transparent, intelligible and easily accessible form, using clear and plain language". This requirement can be broken down into two obligations: a requirement of precision (the information must be substantively correct and complete) and a requirement of intelligibility (it must be capable of being understood without excessive effort). The two stand in tension with one another: the more complete and granular the details, the more difficult the text. Resolving that tension is the real drafting task (on this, see design and practice).
The requirements of Article 12 give concrete expression to the principle of transparency (Article 5(1)(a) GDPR). They leave the controller considerable latitude in how to comply; a breach can be established only where the information is grossly imprecise or unintelligible.
2. Presentation
2.1 Intelligibility and target audience
Information is intelligible where a typical member of the audience addressed can grasp it without excessive cognitive or temporal effort. The controller may draw on its knowledge of that audience: a controller collecting personal data from professionals may assume a higher level of understanding than one addressing the general public or children.
Where offerings are directed at children, high requirements as to intelligibility apply; wording, tone and medium must be appropriate for children (Recital 58 GDPR). The same applies mutatis mutandis to other vulnerable addressees. Where there is uncertainty as to intelligibility, testing with members of the target audience is advisable (Article 29 Working Party, WP 260 rev.01, Guidelines on transparency, adopted on 11 April 2018, para. 9).
2.2 Clear and plain language
The information should be formulated simply, avoid complex sentence and language structures and dispense with abstract or ambiguous terms. The purposes and the legal basis in particular must be stated clearly. Vague formulations that mean everything and nothing fail the transparency requirement.
| Don't (too vague) | Do (specific) |
|---|---|
| "We may use your data to develop new services." | "We store your purchase history and use it as the basis for suggesting further products to you." |
| "We may use your data for research purposes." | "We evaluate how visitors use our website in order to make it clearer and easier to navigate." |
| "We use your data in order to offer personalized services." | "We store which articles you have clicked on and show you advertising matching those articles." |
The examples are taken from the transparency guidelines (WP 260 rev.01, para. 12). They show the pattern: state the type of data, the specific use and the consequence for the data subject.
Two views on doing without modal verbs. The supervisory authorities recommend avoiding modal words such as "may", "might", "some", "often" or "possible" altogether (WP 260 rev.01, para. 13). As a blanket prohibition, that goes beyond the legal position: Article 12(1) GDPR requires precision, not the abandonment of every modal verb. Where processing in fact takes place only under certain conditions, "may" is even more accurate than an assertion in the indicative. The authorities' line targets the real problem: a "may" must not serve to obscure processing that is in truth already settled. In practice, the recommendation is therefore: avoid modal verbs where they create ambiguity; retain them where they reflect a genuine condition.
Intelligibility is also served by defining recurring terms once and then using them consistently, instead of describing the same type of data or the same purpose afresh in every section. A controller who defines the data automatically generated on each page view (IP address, time, page accessed, information about browser and device) once as "access data" can then refer to that term briefly in the individual sections. This avoids repetition, keeps the text short and thereby also serves the precision required by Article 12(1) GDPR. The technique reaches its limit where a collective term is drawn so broadly that the specific processing is no longer discernible; in that case, the section concerned must break down which data are actually meant.
2.3 Easy accessibility
Information is easily accessible where the data subject does not first have to search for it but immediately recognizes where and how to access it. Established ways of implementing this:
- On every page of a website, a clearly recognizable link under a familiar term ("Privacy", "Privacy notice"). A placement or coloring that draws no attention to the link is not sufficient (WP 260 rev.01, para. 11).
- For apps, the information should already be available before download in the store and reachable at any time in a few steps after installation; the notice must relate specifically to the app and not merely reproduce the company's general terms.
- Where data are collected online, a link at the point of collection, or the information on the same page, is a suitable solution.
Privacy notices and cookie banners are often displayed together but must be kept legally distinct: the obligation to inform follows from Articles 13 and 14 GDPR, whereas consent to the storing of, or access to, information on terminal equipment follows from § 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG). For accessibility, it follows that the cookie banner must contain a clearly labeled link to the privacy notice, separate from the link to the cookie information. The mandatory items must not be relegated to the banner and hidden there behind several clicks.
3. Form of the information
3.1 In writing, electronically or orally
The information is provided in writing or by other means, including, where appropriate, by electronic means (Article 12(1), second sentence, GDPR). Purely oral information is not sufficient; this follows a contrario from Article 12(1), third sentence, GDPR, which provides for oral information only at the request of the data subject. By contrast, an oral reference to information available in another form is permissible and often practicable, for example, where data are collected by telephone, a reference to the notice available online.
The duty laid down in Article 12(1), third sentence, GDPR to verify identity before providing information orally concerns the individual exercise of data subject rights, not the general privacy notice under Articles 13 and 14 GDPR. The latter must also be accessible to future users whose identity the controller cannot verify at all (WP 260 rev.01, para. 20).
3.2 Active provision of information rather than mere availability
Articles 13 and 14 GDPR require that the information be "communicated" to, or "made available" to, the data subject. The controller must therefore take action: make the information available or clearly direct the individual to where it can be found (link, QR code). Merely keeping it available for retrieval is sufficient only where the controller actively points to it and the individual actually has the opportunity to take note of it before collection (Recital 58 GDPR; WP 260 rev.01, para. 33).
A change of medium is permissible depending on the collection situation, as long as it does not make taking note of the information appreciably more difficult. Where data are collected via an electronic form, the information must as a rule also be reachable electronically; at the very least, a reference on the form itself is required.
4. Icons
The controller may supplement the information with standardized icons in order to give a meaningful overview at a glance; where they are presented electronically, they must be machine-readable (Article 12(7) GDPR). Icons supplement the information but do not replace it: all mandatory items must still be provided in text form. A delegated act of the Commission could make particular icons binding (Article 12(8) GDPR); to date, no set of icons has become established. In practice, icons are an additional source of error where icon and text diverge.
5. Timing of the information
The timing is part of proper information and has a bearing on its content: what must be communicated are the current details known at the time of collection.
- Where data are collected from the data subject, the information must be provided at the time of collection, in practice before processing begins, so that the individual can still decide or object (details under information to be provided where data are collected from the data subject).
- Where data are obtained from third parties, a reasonable period applies, at the latest one month, and in certain circumstances earlier (details under information to be provided where personal data have not been obtained from the data subject).
6. Provision free of charge
The information under Articles 13 and 14 GDPR is made available free of charge (Article 12(5), first sentence, GDPR). It must not be made conditional on a payment or on the purchase of a service. Where the controller collects data in connection with a purchase, the information must be provided before the transaction is concluded and at the point of collection, not only afterwards.
7. Legal consequences of a breach
Missing, incomplete or incorrect information is subject to administrative fines under Article 83(5)(b) GDPR. In addition, a claim for compensation under Article 82 GDPR may arise. Whether the processing itself becomes unlawful depends on whether the collection depends on the will of the data subject: where collection is based on consent or is in fact avoidable (for example, video surveillance in public spaces), the information deficiency may render the processing unlawful; where the individual has to tolerate the collection in any event, the processing remains lawful, but the information must be provided subsequently.
8. Distinction from data subject rights
In addition to the requirements as to presentation and form, Article 12 GDPR also contains procedural rules for handling requests from individual data subjects: the one-month time limit for responding, the verification of identity, the handling of requests free of charge and the treatment of manifestly unfounded or excessive requests (Article 12(2) to (6) GDPR). Thematically, these rules belong to the data subject rights (access, rectification, erasure and others) and are dealt with there. For the privacy policy, only the requirements of Article 12(1), (5) and (7) GDPR set out here are relevant.
9. Primary sources
Über den Autor
Über den Autor
Dieser Beitrag wurde von Dr. Thomas Helbing, Fachanwalt für IT-Recht in München, verfasst.
Dr. Helbing wird seit 2020 durchgehend bis heute (2026) vom Handelsblatt als einer der „Deutschlands besten Anwälte" im Bereich IT-Recht und Datenschutzrecht ausgezeichnet.
Laut Kanzleimonitor.de (Ausgaben 2024–2026) zählt er zu den führenden Anwälten für Datenschutz und IT-Recht und ist unter den Top-100 Anwälten in Deutschland (2024/25) gelistet. Kanzleimonitor gilt als besonders aussagekräftige Marktstudie, da sie ausschließlich auf persönlichen Empfehlungen von Unternehmensjuristen basiert.
Dr. Helbing verfügt über langjährige Beratungserfahrung im Datenschutz- und IT-Recht und berät Mandanten unterschiedlichster Größen, vom Startup über wachstumsstarke SaaS-Unternehmen und Unicorns bis hin zu internationalen Konzernen.
Sein beruflicher Hintergrund umfasst das gesamte Spektrum der Praxis im IT- und Technologierecht. Er begann seine Laufbahn in einer internationalen Großkanzlei, sammelte anschließend Inhouse-Erfahrung in einem DAX-Unternehmen und ist selbst Unternehmer und Gründer mehrerer digitaler Projekte. Darüber hinaus verfügt er über praktische Programmiererfahrung, wodurch er technische Systeme, Softwarearchitekturen und digitale Geschäftsmodelle nicht nur juristisch, sondern auch aus technischer Perspektive versteht.
Zu seinen Mandanten zählen seit vielen Jahren unter anderem Technologieunternehmen und SaaS-Anbieter, führende deutsche Forschungseinrichtungen sowie eine systemrelevante deutsche Großbank. Seine Beratungsschwerpunkte liegen insbesondere in den Bereichen DSGVO-Compliance, Datenökonomie, SaaS, KI-Regulierung und IT-Vertragsrecht.
Privacy Policy and Information Obligations (Articles 12 to 14 GDPR)
When a privacy policy is required, which mandatory items of information it must contain and how it is structured: an overview of the information obligations under Articles 12, 13 and 14 GDPR.
Information to Be Provided Where Data Are Collected from the Data Subject (Article 13 GDPR)
Which mandatory items a privacy notice must contain where personal data are collected from the data subject: the catalogs of Article 13(1) and (2) GDPR with examples, purposes and legal basis, legitimate interests (Mousse), information on a change of purpose and the exception for information the data subject already has.