A privacy policy is legally required for every website in Germany as soon as personal data is processed – and that applies to virtually every web presence. The GDPR (Articles 13 and 14) requires information about the data controller, processing purposes, legal bases, storage duration, and data subject rights. Missing or outdated information can result in cease-and-desist notices and fines. A GDPR-compliant privacy policy must be complete, understandable, and accessible from every page.
Who Needs a Privacy Policy?
Every website needs a privacy policy as soon as personal data are processed. This begins with embedding Google Fonts, using a contact form, or storing server logs with IP addresses. In practice, hardly any exception exists – even a pure digital business card typically loads external resources or sets technically necessary cookies.
For businesses and self-employed individuals in NRW – from the trades company in Remscheid to the agency in Cologne – a legally compliant privacy policy is not an optional addition but a legal requirement under Articles 13 and 14 GDPR as well as Section 5 TMG or Section 5 DDG (since 2024).
What Content Is Mandatory?
The GDPR specifically prescribes what information users must receive. If mandatory details are missing, the privacy policy is not legally compliant – even if it formally exists.
- Name and full contact address of the data controller (imprint obligation applies in parallel)
- Contact details of the data protection officer, if one must be appointed
- What data is processed for what purpose (e.g., contact requests, analytics, newsletter)
- Legal basis under Art. 6 GDPR: consent (para. 1a), contract performance (para. 1b), legitimate interest (para. 1f), etc.
- Storage duration or criteria for determining it
- Recipients or categories of recipients (including third-country transfers)
- Data subject rights: access, rectification, erasure, restriction, objection, data portability
- Right to lodge a complaint with the competent supervisory authority (in NRW: LDI NRW)
- Information on automated decision-making / profiling, if applicable
An appropriate legal basis must be specified for each processing activity. Anyone using analytics tools like Google Analytics requires active consent from the user – a legitimate interest is generally considered insufficient.
Integrating Third-Party Services Correctly
Many websites embed external services without being aware of the data protection implications. Every third-party service must be individually listed in the privacy policy – with the provider name, purpose, legal basis, and a link to their own privacy policy.
- Google Analytics / Google Tag Manager: Consent via Consent Management Platform (CMP) required, document IP anonymization
- Google Maps / OpenStreetMap: Load maps only after consent or as a static preview image
- Google Fonts: Self-host instead of external embedding – otherwise IP data is transferred to the US without consent
- YouTube embeds: Use privacy-enhanced mode and list in privacy policy
- CDN services (Cloudflare, jsDelivr, etc.): Conclude a data processing agreement (DPA) and document it
- Booking systems / chat widgets: Make data sharing transparent, DPA with provider
For services that transfer data to third countries (e.g., the USA), additional information on the transfer mechanisms is required since the Schrems II ruling – typically EU Standard Contractual Clauses or an Adequacy Decision (for the USA: EU-US Data Privacy Framework since 2023).
Keeping the Privacy Policy Up to Date
A privacy policy created once is rarely permanently correct. Laws change, new services are integrated, providers update their own policies – all of this requires updates. In practice, a review at least once a year is recommended, as well as whenever the technical infrastructure of the website changes.
- Maintain a changelog: Document every content change with a date
- Check new tools: Before integrating a new plugin, script, or widget, clarify data protection implications
- Keep CMP in sync: Cookie banner and privacy policy must list the same services and categories
- Track provider updates: When a third-party provider changes their privacy policy, action may be needed
- Monitor legal changes: TTDSG, DDG, and EU regulations continue to evolve
Summary
- Required for all: Every website with data processing (forms, cookies, analytics) needs a privacy policy
- Mandatory content: Data controller, purposes, legal bases per Art. 6 GDPR, storage duration, data subject rights, right to complain
- List third-party services individually: Each external service with purpose, legal basis, and link to the provider's privacy policy
- Consent for tracking: Google Analytics, GTM, and similar services require active consent via CMP
- Self-host Google Fonts: External embedding transfers IP addresses without consent – legally risky
- Update regularly: Review at least annually and with every infrastructure change
- Footer link on every page: Privacy policy must always be directly accessible
