Data protection policy: This creates a legally binding framework in accordance with the GDPR and BDSG
A data protection policy is the operational translation of the GDPR into the company. This guide shows which chapters are mandatory, how to maintain the policy and when an external data protection officer can noticeably reduce the burden.
According to Article 24 Para. 2 GDPR, a data protection directive is actually mandatory as soon as the processing activities involve a risk to the rights and freedoms of natural persons. It translates the abstract obligations of the regulation into concrete instructions that management, departments and processors must adhere to. Without this internal framework, there is no evidence of accountability in accordance with Article 5 (2) GDPR, and it is precisely this gap that is immediately noticeable in every supervisory authority audit. The Federal Commissioner for Data Protection also considers the internal guidelines to be a central element of GDPR implementation in medium and large-sized companies.
This guide describes the structure, mandatory chapters and maintenance cycle of a data protection policy that will convince supervisory authorities, customers and auditors. It shows how you can interlink the guideline with the list of procedures, the TOM catalogue and the training plan, what role the data protection officer plays and when handing it over to an external officer is more economical than setting it up internally. In the end, you will know which 14 building blocks belong in a consistent data protection policy, how auditors recognise maturity and how a compliance platform and officer-as-a-service like CIVAC makes the maintenance effort calculable. The article is aimed at management, data protection officers and compliance officers in companies with around 50 employees.
Key Takeaways
- A data protection policy is the central link between GDPR requirements and lived practice and thus fulfils the accountability requirement according to Art. 5 Para. 2 GDPR.
- Mandatory components are scope, roles, legal basis, rights of those affected, TOM reference, reporting path according to Art. 33 GDPR, order processing and training cycle.
- The guideline is not a one-off document, but requires an annual review, version status and approval by management, otherwise it will no longer be audit-ready.
Legal basis: Why a data protection policy is not a free document
Art. 24 Para. 1 GDPR obliges the person responsible to implement appropriate technical and organisational measures and to check and update them if necessary. Paragraph 2 adds that this also includes the application of appropriate data protection safeguards, provided this is appropriate in relation to the processing activities. Supervisory authorities unanimously read this standard as meaning that internal guidelines are mandatory as soon as regular or extensive processing takes place. The German Data Protection Conference (DSK) confirms this in its brief paper No. 1 and points out that the accountability requirement according to Art. 5 Para. 2 GDPR can hardly be fulfilled without a documented guideline.
In addition, there is the BDSG: Section 38 requires a data protection officer as soon as at least 20 people constantly handle personal data automatically. The data protection policy is the document with which this representative exerts his control effect. It connects the abstract GDPR obligations with the concrete processes in sales, HR, IT and marketing and makes responsibilities assignable. Without them, the data protection officer consultant remains without leverage and the management loses the opportunity to manage data protection as a line function.
The operational consequence: An external data protection officer can take effect immediately on the basis of a tested guideline instead of first creating the foundations. CIVAC, as a compliance platform and officer-as-a-service, delivers the policy in a workspace where versions, approvals and training credentials are in one place. This turns the static Word document into a living control instrument that verifiably works. Anyone who wants to audit an existing guideline or set up a new one can receive a complete gap report in less than two weeks and start implementing it with specific deadlines. The appointment certificate, signed, filed, verifiable.
The 14 mandatory chapters of an audit-proof data protection policy
A robust data protection policy has a modular structure. From the testing practice of the state data protection authorities, 14 chapters can be derived that should not be missing from any guideline. This structure fully covers the GDPR and allows targeted updates without rewriting the entire document. Anyone who structures the document modularly gains audit readiness and reduces the maintenance effort by an estimated 40 percent compared to monolithic versions.
- Purpose and scope with definition of the recorded locations, subsidiaries and data categories.
- Roles and responsibilities: Management, DPO, department heads, IT, HR, contract processors.
- Legal basis according to Art. 6 and Art. 9 GDPR including consent management.
- List of procedures according to Art. 30 GDPR with maintenance cycle.
- Rights of those affected according to Art. 12 to 22 GDPR including response times.
- Technical and organisational measures according to Art. 32 GDPR.
- Reporting path for data breaches according to Art. 33 and 34 GDPR with 72-hour deadline.
- Data protection impact assessment according to Art. 35 GDPR with threshold analysis.
- Order processing according to Art. 28 GDPR including vendor list.
- Third country transfer according to Art. 44 ff. GDPR with Standard contractual clauses.
- Deletion concept in accordance with Art. 17 GDPR with deadlines for each data category.
- Training and awareness-raising with a minimum cycle of 12 months.
- Audit and review cycle with annual management review.
- Sanctions for violations, coordinated with HR and Works council.
Each chapter should name those responsible, frequency, location of evidence and escalation path. This creates a document that not only describes obligations, but also enables control. Anyone who maintains the chapters as a Word file will lose track after two years. Anyone who maintains them in a workspace has a versioned status for each line and can prove each statement in the exam with just one click. It is precisely this difference that supervisory authorities honor in their evaluation.
Interlocking with procedure directory, TOM and DPIA
A privacy policy never stands alone. It refers to the list of processing activities according to Article 30 GDPR, the catalogue of technical and organisational measures according to Article 32 GDPR and the data protection impact assessments according to Article 35 GDPR. These three documents are the operational backbone. If one is missing, the directive becomes a paper tiger and the accountability requirement according to Article 5 Para. 2 GDPR is not fulfilled.
In practical terms, this means: Every processing activity in the directory needs a legal basis from the directive, a TOM reference and, if necessary, a DPIA status. Supervisory authorities examine precisely these cross-references. If the directory lists 47 procedures, but the directive only recognises 3 legal bases, the finding is inevitable. The DSK expressly calls for this interlocking in its short paper No. 1. In its guidelines on accountability, the European Data Protection Board (EDPB) also requires a documented cross-link between the directive, list of procedures and risk analysis.
In a CIVAC workspace, the four documents are technically connected: a change in the list of procedures triggers a review task for the directive, a change of vendor triggers a TOM update, a new high-risk processing automatically creates a DPIA template. Licence the workspace for your internal representatives, or have our representatives order it. In both cases the toothing is retained. The auditor calls, the evidence is ready. If you have not yet named a DPO, you will find the right place to start in the profile of the external data protection officer. A quarterly routine that compares guidelines and directories can also be automated as a recurring task in the workspace and significantly reduces the burden of the annual review. This makes care plannable instead of project-like.
Role of the data protection officer: lever instead of letterhead
§ 38 BDSG requires a data protection officer for 20 or more people with automated data processing. Art. 39 GDPR lists its tasks: information, monitoring, advice, cooperation with the supervisory authority. The privacy policy is the tool he uses to scale these tasks. It defines his reporting line to management, his escalation rights and his participation in projects. Without this document, its function remains limited to on-call advice, which neither meets the requirements of the regulation nor the expectations of supervisory authorities.
In practical terms, this means: It is mandatory for the DPO to be involved in the DPIA process (Art. 35 Para. 2 GDPR). He is the contact person for those affected (Art. 38 Para. 4 GDPR). He must have access to all processing activities. A policy that requires it only at the end of a project violates the regulation. Regulatory authorities regularly punish this gap. The Bavarian State Office for Data Protection Supervision expressly pointed out the importance of documented reporting lines in its 2023 activity report.
Many medium-sized companies fail because of the personnel issue. An internal DPO with sufficient qualifications costs 90,000 to 120,000 euros per year. An external data protection officer brings templates, procedural models and audit experience with him from day one. CIVAC provides the platform in which the appointment certificate, reporting line and training certificates are all in one place. The SLA is 2 business days instead of the classic 2 to 6 weeks that many law firms set for responses. If you think about the function strategically, you combine an external DPO with an internal data protection coordinator who acts as an interface in the departments. This model has proven itself in companies with 200 to 2,000 employees and reduces both personnel costs and response times. Audit-proof, documented, § 38-firm.
Training and awareness: The underestimated compulsory part
Art. 39 Para. 1 lit. b GDPR requires the awareness and training of employees involved in processing operations. Supervisory authorities check the training cycle, topic coverage and verifiability. A privacy policy without training chapters will not pass the test. Experience shows: A 12-month cycle is the minimum; new employees need an onboarding module within the first 30 days. Anyone who extends the cycle to 24 months risks a finding in the exam.
The content is not arbitrary. They include data categories, legal bases, rights of those affected, reporting path in the event of incidents, order processing and behaviour in response to inquiries from authorities. Role-specific modules for HR, sales and IT increase effectiveness. According to testing practice, generic e-learning without reference to your own guidelines is inadequate. This applies all the more when special categories of personal data are processed in accordance with Art. 9 GDPR, such as health data or social data.
CIVAC provides 490 ready-to-use audit templates, twelve of which are training formats for the most common roles. Every completion creates proof in the workspace, every participation is time stamped. Anyone who maintains this in Excel will lose the overview and thus the evidence after two years. This shows the difference between a filing cabinet and a system: Others run compliance like a filing cabinet. We run it like software. More about the integration with the NIS 2 training requirement can be found in the article NIS 2 implementation Germany 2026. Anyone who combines data protection and information security training saves around 30 percent of training time per employee and noticeably relieves the burden on the HR function when it comes to maintaining training plans. The consideration of the works council in accordance with Section 87 BetrVG should also be bindingly regulated in the training chapter.
Reporting path: 72 hours after knowledge, not after confirmation
Art. 33 Paragraph 1 GDPR requires you to report a data breach within 72 hours of the person responsible becoming aware of it. Deadline begins as soon as we become aware of it. This clarification is critical because many companies only calculate the deadline after internal confirmation and therefore report it too late. The regulators read the wording strictly: knowledge means that a responsible person has evidence of an incident. Delays beyond 72 hours will be treated as a separate violation and may trigger fines under Article 83 (4) GDPR.
The data protection policy must clearly describe the reporting path. Who reports to whom, in what time frame, with what mandatory information? Art. 33 Paragraph 3 GDPR lists the minimum content: type of violation, categories and number of those affected, categories and number of data sets, consequences, measures taken. This information needs to be compiled in 72 hours, so prepared templates are crucial. Anyone who only designs the path in the incident will fail due to time and completeness.
In a CIVAC workspace, the reporting path is stored as a workflow: incident reporting in the system, automatic escalation to the DPO and management, pre-filled reporting template for the supervisory authority, deadline countdown. In addition, the NIS 2-24/72 reporting path is available in parallel, so that IT security incidents involving personal data do not have to be recorded twice. The clock starts on awareness. Anyone who has not yet documented a clear reporting path should do so before the next quarter, as the authorities are checking exactly this interface. A quarterly tabletop exercise in which a simulated incident is sent through the escalation chain is also helpful. This way the path stays alive in the minds of those responsible.
Maintenance cycle: Why a policy without a version level is worthless
A privacy policy is not a one-time document. Art. 24 Para. 1 GDPR expressly requires checking and updating. In testing practice, this means at least an annual review by the DSB and documented approval by management. Anyone who presents a document from 2022 without a version in the audit has a problem. Experience from official audits shows that an update cycle of 12 months is standard; in the case of major legal changes (such as the EU Data Protection Adaptation Act or new EDPB guidelines), an ad hoc update is mandatory. A significant change of vendor or a new high-risk processing are also triggers.
The maintenance cycle includes four steps: review of the changes since the last review (case law, new processing, change of vendor), adjustment of the affected chapters, formal release with version stamp, communication to employees and processors. Every step requires proof. Supervisory authorities usually require proof that the release took place within the last 12 months and was confirmed by an authorised signatory.
In practice, this cycle often fails due to three points: lack of resources in the DSB team, lack of reminder mechanism, lack of technical versioning. This is exactly where CIVAC’s compliance platform and Officer-as-a-Service comes into play. The workspace sends automatic review tasks, stores the previous versions in an audit-proof manner in the EU data residence and makes every change traceable. If you would like to delegate the review, have one of our officers appointed. If you want to run it internally, licence the workspace. Licence the workspace for your internal representatives, or have our representatives order it. Both models share the same audit trail and provide identical quality of evidence in the audit.
Typical gaps in supervisory authority reviews
From the activity reports of the state data protection authorities, patterns can be derived that regularly cause data protection guidelines to fail. Anyone who knows about these weak points can eliminate them before the next audit. Six gaps appear particularly frequently. They are the most common reasons for complaints and can be avoided in practice. In major proceedings in recent years, exactly these points have regularly triggered fines in the six and seven-figure range.
Firstly: missing or outdated order processing contracts. Art. 28 GDPR requires written or electronic contracts with all processors; the directive must bind the vendor list. Second: Insufficient third country transfers without current standard contractual clauses (SCC 2021/914). Third: deletion concepts that do not specify retention periods for each data category. Fourth: No documented training with evidence per employee. Fifth: reporting paths without clear escalation and without 72-hour mechanics. Sixth: DSFA threshold analyses that are missing or only carried out across the board. Experience has shown that these six points account for 80 percent of the findings.
Each of these gaps can be specifically addressed. CIVAC provides 490 audit templates, ten of which are related to data protection: list of procedures, TOM catalogue, DPIA threshold analysis, AVV standard, deletion concept, proof of training, reporting path, information process, data protection impact assessment, third country transfer check. The templates are provided with § and article references so that every statement can be verified. You can find out more about the integration with ISO 27001:2022 at ISO 27001:2022 transition October 2026. A preliminary self-check along these six fields takes around 4 hours with the platform and provides a clear prioritization for the next 90 days. This means that preparation for the next supervisory procedure can be planned rather than reactive. Audit-proof, documented, § 38-firm.
From document to system: How CIVAC makes the policy operational
A data protection policy is only as effective as its anchoring in everyday life. CIVAC sees itself as a compliance platform and officer-as-a-service: The workspace bundles guidelines, procedures directory, TOM, DPIA, AVV register and training certificates in an EU data residence, operated under an ISO/IEC 27001:2022 ISMS. Versions, approvals and reporting lines are technically depicted, not just documented. This sets the approach apart from classic consulting models that deliver Word documents and charge monthly hours for maintenance.
Two reference models are available. Licence the workspace for your internal representatives and manage the data protection function yourself, or have our representatives appointed and hand over the function completely. Either way, you get 490 audit templates, 25 assignee role profiles, and a reporting line that stands up to regulatory scrutiny. SLA: 2 business days instead of 2 to 6 weeks. Anyone who bundles several representative functions (DSB, ISB, ESG, IMB) also benefits from a shared governance layer.
If you want to audit an existing guideline or set up a new one, the next step is a structural discussion. We review your current document situation, identify the gaps according to the 14 chapters and provide an implementation plan with specific deadlines. Turn reading into an assignment. Write to info@civac.de or use the contact form at civac.de/faq. The auditor calls, the evidence is ready. A typical structural discussion lasts 45 minutes, the subsequent gap analysis is available after 5 working days and contains a recommendation on the form of purchase (internal licence or officer-as-a-service). You then decide whether you want to manage the function internally or hand it over completely.
FAQ
Is a data protection policy mandatory under the GDPR?
Art. 24 Para. 2 GDPR requires appropriate data protection precautions as soon as the processing involves a risk for those affected. Supervisory authorities and the DSK read this as a de facto obligation for internal guidelines as soon as regular or extensive processing takes place. Without a guideline, there is no proof of accountability in accordance with Article 5 (2) GDPR. In practice, it is the standard for every company with 20 or more employees.
How often does a privacy policy need to be updated?
The market standard is an annual review by the data protection officer with documented approval by management. In the event of significant legal changes or new high-risk processing, an ad hoc update is mandatory. The versioning must be audit-proof so that the status at the respective time can be verified during the audit. Supervisory authorities regularly recognise a review cycle beyond 18 months as a finding.
Who is responsible for the privacy policy?
The management bears responsibility as the person responsible within the meaning of Art. 4 No. 7 GDPR. The data protection officer advises and monitors, formulates and suggests, but does not issue regulations. The departments provide the process descriptions. The approval is given by the management, the reporting line must be clearly depicted in the document. This distribution of roles is a central examination question in supervisory procedures.
What differentiates a privacy policy from a privacy policy?
The data protection declaration in accordance with Articles 13 and 14 GDPR is aimed at those affected and is available externally. The privacy policy is an internal document that governs the organisation. Both documents complement each other. The policy is the basis from which the declaration can be consistently derived. Anyone who maintains both without a cross-connection risks contradictions that will immediately become apparent in the exam.
Do small businesses need their own privacy policy?
Even below the 20-person threshold of Section 38 BDSG, the obligation to account according to Art. 5 Para. 2 GDPR remains. A lean guideline with core content is therefore recommended. It can grow modularly and is the most important proof of appropriate measures in accordance with Art. 24 GDPR in the event of damage. Insurers are also increasingly asking about the status of cyber policies.
How do I integrate the data protection policy into an ISO 27001 ISMS?
Annex A.5.34 of ISO/IEC 27001:2022 requires a data protection policy. It is typically managed as part of the ISMS document set and interlinked with the controls of Appendix A domain A.5. This ensures that technical measures and organisational obligations produce a consistent picture. In CIVAC, both spheres are connected in one workspace, eliminating the need for double maintenance.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.