Dieter
← All articlesData protection explained

How to create a privacy policy: mandatory information, examples and common mistakes

Every website needs a privacy policy, because even loading a page processes personal data. This guide shows which information Art. 13 GDPR requires, how to describe services such as analytics, newsletters or Google Fonts correctly, what the TDDDG means for cookies and which mistakes most often lead to cease-and-desist letters.

Sebastian SchenkLegally reviewed by Franziska Breidenbach
Last reviewed: Thursday, 17 September 2026
How to create a privacy policy: mandatory information, examples and common mistakes

Table of contents

  1. In brief
  2. What a privacy policy is and where the obligation comes from
  3. Who needs a privacy policy?
  4. The mandatory information under Art. 13 GDPR
  5. Typical services and what you need to write about them
  6. Cookies, consent and the TDDDG
  7. Data transfers to the USA and other third countries
  8. Step by step: how to create your privacy policy
  9. Example of a text block
  10. The most common mistakes
  11. Generator, template or lawyer?
  12. What happens without a privacy policy, or with a faulty one?
  13. How often does the privacy policy need updating?
  14. Conclusion

In brief

  • Every website needs a privacy policy. As soon as a page is loaded, the server processes the IP address, and that is personal data. The obligation follows from Art. 12 to 14 GDPR.
  • The content depends on the services you use. Hosting, contact form, newsletter, analytics, fonts, videos, shop: each service needs its own section covering purpose, legal basis, recipients, retention period and, where applicable, third-country transfers.
  • Cookies and tracking additionally require consent under § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG), unless they are strictly necessary for technical reasons. The cookie banner does not replace the privacy policy; the two have to match.
  • The policy is a living document. Every new service, every change of provider and every change in the law has to be worked in. An outdated policy is the most common reason for cease-and-desist letters.

What a privacy policy is and where the obligation comes from

The privacy policy is the text you use as the controller to inform visitors to your website which personal data you process, for what purpose, on which legal basis, who receives the data, how long it is stored and which rights data subjects have. The name is not prescribed. “Privacy notice”, “data protection information” or “privacy statement” all refer to the same document. Its legal anchor is Art. 13 GDPR (data collected directly from the person) and Art. 14 GDPR (data obtained from other sources). Art. 12 GDPR sets the form: concise, transparent, intelligible, easily accessible and in clear and plain language.

One point matters for putting it in context: the privacy policy is purely an information obligation. It does not create a legal basis. Whether you may use a tracking tool is decided not by the text of the policy but by Art. 6 GDPR and § 25 TDDDG. The policy merely documents what you are already doing lawfully. The legal notice (Impressum) is a separate document with its own legal basis (§ 5 of the German Digital Services Act, DDG) and is created separately with the legal notice generator.

Who needs a privacy policy?

Practically anyone who operates a website. Back in 2016, the Court of Justice of the European Union ruled that dynamic IP addresses are personal data too (CJEU, judgment of 19 October 2016, C-582/14, “Breyer”). Because every web server processes the visitor’s IP address just to be able to deliver the page at all, the information obligation applies from the very first page view. The size of the business is irrelevant: freelancers, associations, tradespeople and sole traders are affected just as much as large corporations.

The obligation does not stop at the website. Art. 13 GDPR applies to every collection of data, so it also applies towards customers, job applicants, employees and suppliers. That is why, alongside the website policy, you usually need separate privacy information for the application process, for employees and for customers in a contractual relationship. Company profiles on LinkedIn, Instagram or Facebook also need a privacy notice, which is easiest to provide as a link to your website.

The mandatory information under Art. 13 GDPR

Art. 13 GDPR is a checklist. If one of the following points is missing, the policy is incomplete, however detailed the rest may be:

  1. 1Name and contact details of the controller (Art. 13(1)(a)); for companies, the company name with address, email and telephone number, and the representative where applicable.
  2. 2Contact details of the data protection officer (point (b)), if one has been designated. A name is not mandatory; a reachable functional address is enough.
  3. 3Purposes and legal basis of each processing operation (point (c)). Where you rely on legitimate interests under Art. 6(1)(f), also what that interest consists of (point (d)).
  4. 4Recipients or categories of recipients (point (e)), such as the hosting provider, newsletter provider, payment service providers, public authorities.
  5. 5Transfers to a third country (point (f)), including the safeguard you rely on, such as an adequacy decision or standard contractual clauses.
  6. 6Retention period or the criteria used to determine it (Art. 13(2)(a)). “As long as necessary” is not enough if a specific period is known.
  7. 7Data subject rights (point (b)): access, rectification, erasure, restriction, objection, data portability.
  8. 8Right to withdraw consent (point (c)), with the note that withdrawal does not affect the lawfulness of processing carried out before it.
  9. 9Right to lodge a complaint with a supervisory authority (point (d)).
  10. 10Whether providing the data is required by law or by contract and what happens if it is not provided (point (e)).
  11. 11Automated decision-making including profiling (point (f)), if used, with the logic involved and its significance.

For data from other sources, Art. 14 GDPR adds the source of the data and the categories of data. On a website this concerns, for example, credit checks in a shop or enriched CRM data.

Typical services and what you need to write about them

Most of the work lies in taking stock: which services are embedded on the site, and which of them process personal data? The table shows the most common cases with the usual legal basis. It does not replace an assessment of the individual case, but it points you in the right direction.

ServiceUsual legal basisWhat matters
Hosting, server log filesArt. 6(1)(f) GDPR (legitimate interest in operation and security)Name the hosting provider as a processor, state the retention period for the logs (typically 7 to 14 days) and the location of the data centre.
Contact form, email enquiriesArt. 6(1)(b) (pre-contractual steps) or point (f)Which fields are mandatory, how long enquiries are stored, whether a ticket system (processor) sits behind it.
NewsletterArt. 6(1)(a) GDPR (consent), proof via double opt-inName the mailing service provider and where it is based, mention open and click tracking separately, withdrawal via the unsubscribe link.
Web analytics (Google Analytics, Matomo with cookies)Consent under § 25(1) TDDDG and Art. 6(1)(a) GDPRNo tracking without consent. Matomo without cookies and with truncated IP addresses can be based on point (f) as long as no cross-device profiles are created.
Google Fonts, external scripts, CDNsArt. 6(1)(f), unproblematic only when hosted locallyWhen fonts are loaded from Google’s server, the IP address goes to the USA. In 2022 the Regional Court of Munich I awarded damages for exactly that. Host fonts locally and describe it that way in the policy.
YouTube, Google Maps, social media pluginsConsent (§ 25 TDDDG, Art. 6(1)(a))Two-click solution or a consent tool that loads the content only after consent has been given. YouTube’s privacy-enhanced mode on its own is not enough.
Online shop, payment service providersArt. 6(1)(b) (contract), point (c) (retention for tax purposes)Payment providers are usually independent controllers, not processors. State the retention periods of 8 or 10 years.
Job application formArt. 6(1)(b), § 26 of the German Federal Data Protection Act (BDSG)Link to separate privacy information for applicants, state the deletion period after a rejection (in practice up to six months).

For every service that processes data on your behalf, you additionally need a data processing agreement. The privacy policy informs your visitors; the DPA governs the relationship with the service provider. The two belong together, but they are not the same thing.

Data transfers to the USA and other third countries

As soon as a service processes data outside the EU and the EEA, the rules of Chapter V of the GDPR (Art. 44 to 49) apply. For the USA, the European Commission’s adequacy decision on the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795) has been in force since 10 July 2023. Transfers to US companies certified under the Framework are therefore permitted without you needing any further safeguards. The decision has been challenged in court; the General Court of the EU dismissed the first action in 2025, and the proceedings continue on appeal. As long as the decision stands, you can rely on it, but you should keep an eye on whether that remains the case.

If the provider is not certified or is based in another third country, you need the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914) and an assessment of whether the level of data protection in the destination country actually supports the clauses. In the privacy policy, you always name the third country and the safeguard you rely on. “Data may be transferred to the USA” without naming the basis is incomplete.

Step by step: how to create your privacy policy

  1. 1Take stock. List all services, plugins, scripts and forms on your website. Check in your browser (developer tools, “Network” tab) or with a website scanner which third-party providers are actually loaded. Do not forget backend services: hosting, CDN, email, ticket system.
  2. 2Define the controller and the DPO. Company name, address, email and, where applicable, the contact details of the data protection officer. If you are unsure whether you need a DPO, the external data protection officer page helps you with its obligation check.
  3. 3Write a section for each service. Always following the same pattern: what the service does, which data it processes, why, on which legal basis, who the provider is and where it is based, how long the data is stored, whether there is a third-country transfer and under which safeguard.
  4. 4Add the general sections. Data subject rights, right to withdraw consent, right to lodge a complaint naming the competent supervisory authority, retention periods in general, a note on which information is mandatory.
  5. 5Reconcile with the consent tool. Every service in the banner must appear in the policy and vice versa. The categories in the banner (necessary, statistics, marketing) should be reflected in the policy.
  6. 6Publish it. As a separate page, for example under /privacy, reachable from every page of the website with one click (footer), and additionally linked at every form. Not as a PDF, not behind a login, not only in the cookie banner.
  7. 7Set the date and a review schedule. “Last updated: month year” at the end, and a fixed date, at least every six months, on which you review your services and the legal situation.

Example of a text block

This is what a complete section for a single service looks like, using a newsletter provider as an example. The structure is the same for every service:

Six pieces of information in one paragraph: provider, data, purpose, legal basis, withdrawal, retention period, plus the DPA and the location. It is exactly this completeness that separates a robust policy from a copied template.

The most common mistakes

  • Copied template. The policy describes services you do not use and says nothing about the ones you do. For supervisory authorities, a sure sign that nobody has looked at it.
  • Outdated legal references. “TTDSG” instead of “TDDDG”, “TMG” instead of “DDG”, references to the Privacy Shield, which has been invalid since 2020. Mistakes like these reveal that the policy has not been touched in years.
  • Missing services. Usually the inconspicuous ones: fonts loaded from Google’s server, a chat widget, the map in the contact section, the job application form.
  • No retention period. “As long as necessary” without a specific period or comprehensible criteria.
  • Third country without a safeguard. The US provider is named, but not whether it is certified under the Data Privacy Framework or whether standard contractual clauses apply.
  • Policy hard to reach. Linked only in the cookie banner, available only as a PDF, or found only after several clicks.
  • Banner without a genuine choice. The decline option is hidden, “Accept” is highlighted, services load before the decision is made. Then there is no consent, whatever the policy says.
  • DPO contact details missing. Anyone who has designated a data protection officer must publish their contact details (Art. 37(7) GDPR). If the DPO changes, the policy has to follow.

Generator, template or lawyer?

There are no formal requirements as to who writes it. You may write the policy yourself. The question is which route suits your workload and your risk:

RouteAdvantageDisadvantage
Free templateFast, freeNever fits exactly, includes services you do not use and lacks the ones you do. No updates. Highest risk of cease-and-desist letters.
Generator with a service libraryIndividual, kept up to date, inexpensive, ready in minutesOnly as good as your stocktake. With unusual processing (scoring, AI, health data) it reaches its limits.
Bespoke drafting by a lawyerTailor-made, the right choice for complex processingExpensive, and every update costs again. Oversized for a typical company website.

Dieter takes the middle route: you enter your website URL, detected services are suggested, the text blocks are legally reviewed and are updated centrally whenever the law changes. How that works in detail is shown on the create a privacy policy product page.

What happens without a privacy policy, or with a faulty one?

Three risks, in practice in this order. First, cease-and-desist letters. Since the judgment of the Court of Justice of the European Union of 4 October 2024 (C-21/23), it has been settled that competitors can issue cease-and-desist letters for breaches of the GDPR information obligations as a violation of competition law. Second, complaints to the supervisory authority, which any data subject can file free of charge and which regularly end with a review of the entire website. Third, fines: breaches of Art. 12 to 14 GDPR fall into the upper tier of fines of up to 20 million euros or 4 percent of worldwide annual turnover (Art. 83(5)(b) GDPR). For small businesses, the actual fines remain well below that, but they do happen, and they never come alone.

How often does the privacy policy need updating?

There is no fixed deadline, but there is a clear trigger: any change to the processing. A new newsletter tool, a change of hosting provider, an additional form, an AI chatbot on the site, a new payment provider in the shop. Art. 13(3) GDPR also requires you to inform people before further processing for a new purpose. Add to that changes in the law, such as the renaming of the TTDSG to TDDDG, the end of the Privacy Shield or new court rulings on individual services. As a rule of thumb: review with every technical change and at least once every six months.

Conclusion

A privacy policy is not a piece of legal busywork but a structured description of what your website actually does. If you take the stocktake seriously, work through the same pattern for every service and reconcile the policy with your consent tool, you are on the safe side. The rest is maintenance: a fixed review schedule and a tool that keeps track of legal changes for you.

Author

Sebastian Schenk

Co-Founder & CEO

Lawyer and data protection officer. Drives product vision at simply Legal and ensures Dieter is sound legally and in practice.

Sources and further reading

Frequently asked questions

Do I need a privacy policy if my website does not set any cookies?

Yes. The obligation does not arise from cookies but from the processing of personal data. Merely loading the page transmits the IP address to the server, and according to CJEU case law that counts as personal data. A website without cookies therefore needs a shorter privacy policy, but not no privacy policy at all.

Is the cookie banner enough as a privacy policy?

No. The banner obtains consent under § 25 TDDDG; the privacy policy fulfils the information obligations under Art. 13 GDPR. Both are mandatory, and both must describe the same services. A banner that refers to a policy in which the services are missing renders the consent invalid.

Do I have to name my data protection officer in the privacy policy?

If you have designated a data protection officer, their contact details must be published (Art. 37(7) GDPR), and the privacy policy is the usual place for that. A name is not mandatory; a reachable functional address such as [email protected] is enough. If you are not required to designate a DPO, you simply leave the section out.

Can I keep using Google Fonts?

Yes, if you host the font files on your own server. Then no IP address flows to Google. If the fonts are loaded directly from Google’s server, the Regional Court of Munich I found a GDPR breach and awarded damages in 2022. Embed them locally, describe them as a separate service in the policy, done.

Where does the privacy policy have to be placed on the website?

Reachable from every page with one click, in practice as a link in the footer labelled “Privacy” or “Privacy policy”. It should additionally be linked at every form where data is entered. Not sufficient: only as a PDF, only in the cookie banner or behind a login.

Is an English privacy policy necessary?

Art. 12 GDPR requires language that the target audience can understand. If your website is in English or you address international customers, the privacy policy must also be available in that language. A purely German-language site for the German market does not need a translation.

This article reflects the position at the date of publication. We update our content when the law changes.

Related articles

Technical and organisational measures (TOM): What Art. 32 GDPR requires and how small businesses implement it

Thursday, 11 September 2025

Technical and organisational measures (TOM): What Art. 32 GDPR requires and how small businesses implement it

Technical and organisational measures (TOM) are the part of the GDPR that decides over fines and data breaches. This guide explains the requirements of Art. 32 GDPR, the classic TOM catalogue with examples, how to rate your protection needs, which measures are realistic for a company of ten people and how to build the TOM document that authorities and clients want to see.

Data processing agreement (DPA): when you need one, what it must contain and when you don’t

Thursday, 23 October 2025

Data processing agreement (DPA): when you need one, what it must contain and when you don’t

A data processing agreement is mandatory as soon as a service provider processes personal data on your behalf: hosting, cloud, newsletters, CRM. With tax advisers, lawyers or banks, on the other hand, you don’t need one. This guide explains how to tell the difference, the mandatory contents under Art. 28 GDPR, how to deal with sub-processors and US providers, and how to check a provider’s DPA in ten minutes.

Record of processing activities and deletion concept: mandatory content under Art. 30 GDPR, deletion periods and structure

Monday, 10 November 2025

Record of processing activities and deletion concept: mandatory content under Art. 30 GDPR, deletion periods and structure

The record of processing activities is the first document a supervisory authority wants to see, the deletion concept the second. This guide explains who has to keep a record (almost everyone, despite the 250-employee exemption), which details Art. 30 GDPR requires, which retention periods determine the deletion periods and how to link the two so that they work in everyday business.

Dieter helps you avoid fines

Ready to go

Dieter takes care of your data protection.

Get started without a demo call and set up your data protection in a few steps.

Get started