# Privacy Policy and Information Obligations (Articles 12 to 14 GDPR)

When a privacy policy is required, which mandatory items of information it must contain and how it is structured: an overview of the information obligations under Articles 12, 13 and 14 GDPR.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/transparenzpflichten
> Sprache: en



The privacy policy is the central instrument through which the controller fulfills its information obligations. What it must contain follows from Article 13 GDPR (collection from the data subject) and Article 14 GDPR (collection from other sources); how the information is to be prepared and provided is governed by Article 12 GDPR. The term privacy notice is more apt than "privacy policy", because what is involved is pure information, not a declaration or an approval on the part of the data subject.

<Callout type="info">
  **Key takeaways**

  * The trigger is the **collection of data**: where data are collected from the data subject, Article 13 GDPR applies; where they are obtained from other sources, Article 14 GDPR applies.
  * The information must in principle be provided **at the time of collection** (Article 13) or, respectively, within a short period after the data have been obtained (Article 14).
  * Its content consists of fixed **mandatory items of information** (controller, purposes, legal basis, recipients, storage period, rights and others), set out separately for direct collection and for collection from third parties.
  * What is involved is **pure information, not consent**: no checkbox, no tying it to the conclusion of a contract.
  * An infringement is **subject to administrative fines** (Article 83(5)(b) GDPR); the information must be provided free of charge.
</Callout>

## 1. When a privacy policy is required [#1-when-a-privacy-policy-is-required]

### 1.1 Trigger: direct collection or collection from third parties [#11-trigger-direct-collection-or-collection-from-third-parties]

The information obligation attaches to the collection of personal data. What matters is where the data come from:

* **Collection from the data subject** (Article 13 GDPR): the data subject is the source, for example when completing a form, on registration or through observation of their behavior (video surveillance, sensors, tracking). The information must be provided at the time of collection.
* **Collection from other sources** (Article 14 GDPR): the data originate from third parties, from publicly accessible sources or from data brokers. The information must be provided within a reasonable period, at the latest within one month, and in certain circumstances earlier.

A privacy policy is therefore not owed "for the website" or "for the company", but for every processing operation that collects personal data. In practice, the information relating to many processing operations of the same kind is bundled into a single document.

### 1.2 Typical areas of application [#12-typical-areas-of-application]

It makes sense to organize the notices by target group and to keep separate notices available for particular processing situations.

| Level                            | Examples                                                                    |
| -------------------------------- | --------------------------------------------------------------------------- |
| General notices by target group  | Customers and business partners, employees, applicants, website visitors    |
| Specific services and offerings  | Apps, web applications (SaaS, cloud), online shop, newsletter, user account |
| Particular processing situations | Video surveillance, guest Wi-Fi, time recording, photographs at events      |

A general privacy policy covers the standard cases; for situations that the data subject does not readily expect, separate notices provided close to the context are required (on this, see [design and practice](/docs/dsgvo-hub/einzelthemen/transparenzpflichten/1.3.5.4-gestaltung-und-praxis)).

### 1.3 Pure information, not an approval [#13-pure-information-not-an-approval]

The privacy policy informs; it does not require any approval. For practice, it follows that:

* **No checkbox** for the privacy policy on registration. Anyone who requires a confirmation box suggests a consent that is neither necessary nor intended here (on this, see [consent as a legal basis](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.1-einwilligung)).
* **Not part of the contract.** General terms and conditions should at most contain a reference to the privacy notice, not its content.
* **Free of charge.** The information may not be made conditional on a payment or on the purchase of a service (Article 12(5), first sentence, GDPR).

## 2. What purposes it serves [#2-what-purposes-it-serves]

The privacy policy fulfills several functions at once, which should be kept in mind when drafting it:

* **In relation to data subjects:** information and external presentation; it is the precondition for data subjects being able to exercise their rights at all.
* **In relation to supervisory authorities:** safeguarding the organization and avoiding fines; missing or incomplete information is subject to an administrative fine in its own right (Article 83(5)(b) GDPR).
* **In relation to competitors and lawyers:** reducing the risk of cease-and-desist warnings and claims for damages.
* **For the company itself:** anyone who prepares the privacy policy carefully has to think through their own processing operations, their purposes and their legal bases. The document is therefore also an internal tool for review and structuring.

## 3. Which items of information it must contain [#3-which-items-of-information-it-must-contain]

The following overview assigns each mandatory item of information to its legal basis and shows whether it is owed in the case of direct collection or of collection from third parties. The last column indicates when the item may exceptionally be omitted. The details, examples and the do's and don'ts are set out on the linked sub-pages.

| Mandatory item of information                                       | Direct collection (Article 13) | Collection from third parties (Article 14) | May be omitted where              |
| ------------------------------------------------------------------- | ------------------------------ | ------------------------------------------ | --------------------------------- |
| Controller (name, contact details, representative where applicable) | (1)(a)                         | (1)(a)                                     | already known                     |
| Data protection officer (contact details)                           | (1)(b)                         | (1)(b)                                     | no DPO / already known            |
| Purposes and legal basis                                            | (1)(c)                         | (1)(c)                                     | already known                     |
| Legitimate interests (where Article 6(1)(f) applies)                | (1)(d)                         | (2)(b)                                     | processing not based on point (f) |
| Recipients or categories of recipients                              | (1)(e)                         | (1)(e)                                     | no disclosure / already known     |
| Transfer to a third country and safeguards                          | (1)(f)                         | (1)(f)                                     | no third-country element          |
| Storage period or criteria                                          | (2)(a)                         | (2)(a)                                     | (narrowly) dispensable            |
| Data subject rights and right to lodge a complaint                  | (2)(b), (d)                    | (2)(c), (e)                                | already known                     |
| Withdrawal of consent                                               | (2)(c)                         | (2)(d)                                     | no consent relied on              |
| Obligation to provide the data and consequences                     | (2)(e)                         | not applicable                             | direct collection only            |
| Automated decision-making and logic involved                        | (2)(f)                         | (2)(g)                                     | no such processing                |
| Categories of personal data processed                               | not applicable                 | (1)(d)                                     | third-party collection only       |
| Source of the data                                                  | not applicable                 | (2)(f)                                     | third-party collection only       |

<Callout type="info">
  For each mandatory item of information it is worth carrying out an assessment against four states: **information provided** (the item appears in the notice), **already known** (the person already has it, Article 13(4) or Article 14(5)(a)), **dispensable** (conceivable only for individual items under paragraph 2) or **exception** (only in the case of collection from third parties, Article 14(5)). This makes it possible to document cleanly, for each processing operation, why an item was included or why it may be absent.
</Callout>

## 4. Structure of this chapter [#4-structure-of-this-chapter]

<Cards>
  <Card title="General requirements (Article 12)" href="/docs/dsgvo-hub/einzelthemen/transparenzpflichten/1.3.5.1-allgemeine-anforderungen" description="How the information is prepared and provided: concise, transparent, intelligible, easily accessible; form, icons, timing, legal consequences." />

  <Card title="Content in the case of direct collection (Article 13)" href="/docs/dsgvo-hub/einzelthemen/transparenzpflichten/1.3.5.2-inhalt-bei-direkterhebung" description="Mandatory items of information where data are collected from the data subject, information on a change of purpose and the exception for information already available." />

  <Card title="Content in the case of collection from third parties (Article 14)" href="/docs/dsgvo-hub/einzelthemen/transparenzpflichten/1.3.5.3-inhalt-bei-dritterhebung" description="Additional items of information (categories of data, source), timing of the information and the four exceptions under paragraph 5." />

  <Card title="Design and practice" href="/docs/dsgvo-hub/einzelthemen/transparenzpflichten/1.3.5.4-gestaltung-und-praxis" description="Structure, layered approach, level of detail, means of provision, typical mistakes, updating and checklist." />
</Cards>

## 5. Primary sources [#5-primary-sources]

<Cards>
  <Card title="Article 12 GDPR" href="https://dsgvo-gesetz.de/art-12-dsgvo/" description="Transparent information, communication and modalities." />

  <Card title="Article 13 GDPR" href="https://dsgvo-gesetz.de/art-13-dsgvo/" description="Information to be provided where personal data are collected from the data subject." />

  <Card title="Article 14 GDPR" href="https://dsgvo-gesetz.de/art-14-dsgvo/" description="Information to be provided where personal data have not been obtained from the data subject." />

  <Card title="WP 260 rev.01" href="https://www.edpb.europa.eu/our-work-tools/our-documents/article-29-working-party-guidelines-transparency-under-regulation_en" description="Article 29 Working Party guidelines on transparency (endorsed by the European Data Protection Board)." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.