Data protection declaration Have a website created: GDPR-proof, documented, auditable
A data protection declaration is not a template text, but a legal document according to Art. 13 GDPR. Anyone who uses cookies, tracking, web analysis or application forms needs a checked, signed version. This article shows when a generator is sufficient and when the DSB has to sign.
According to Art. 13 GDPR, every person responsible must inform data subjects transparently at the time of data collection, in a precise, understandable and easily accessible form. For websites, this means a complete data protection declaration that names every processing: from the hosting log file to the contact form to the conversion pixel. Supervisory authorities such as the LfDI Baden-Württemberg and the LfD Bavaria have imposed five-figure fines several times in recent years because declarations were out of date, named unclear recipients or concealed third-country transfers. The Hamburg Commissioner for Data Protection and Freedom of Information also regularly points out inadequate cookie banners and gaps in information about web analysis services. Added to this is the growing pressure from warnings under competition law, which have become even more common since the BGH ruling VI ZR 1116/22.
If you want to have a data protection declaration drawn up, you have three options: generator, law firm or external data protection officer. This article describes which variant suits which risk situation, which eleven mandatory pieces of information must not be missing in accordance with Art. 13 and Art. 14 GDPR, how you can keep the processing list consistent in accordance with Art. 30 GDPR and how CIVAC's compliance platform and officer-as-a-service bundles the declaration including order processing contracts, TOM documentation and appointment certificate in one workspace. You will receive concrete decision criteria, a realistic cost calculation and a suggestion on how you can turn a legally mandatory exercise into a resilient part of your compliance stack. The appointment certificate, signed, filed, verifiable.
Key Takeaways
- A data protection declaration is only legally secure if it contains all eleven mandatory details of Article 13 GDPR and is adapted to the tools actually used (analytics, CDN, tracking).
- Generators provide a raw version; The responsibility for accuracy and completeness remains with the person responsible and should be countersigned by the data protection officer.
- For third country transfers (e.g. Google Ads, Meta), standard contractual clauses, TIA and additional measures must be mentioned, otherwise Art. 44 ff. GDPR applies.
What the GDPR specifically requires in terms of mandatory information
Art. 13 GDPR lists the information requirements for direct collection. This includes the name and contact details of the controller, if applicable representatives in the Union, contact details of the data protection officer, purposes and legal basis of the processing, legitimate interests in Article 6 Paragraph 1 lit. Anyone who does not collect data directly from the data subject, for example by enriching it from the commercial register or through lead lists, must also meet the requirements of Art. 14 GDPR.
A website usually processes more data categories than are visible at first glance: server log files, cookies and comparable technologies in accordance with Section 25 TTDSG, contact form, newsletter with double opt-in, application portal, web analysis, re-targeting, Maps, fonts, video embeds, chat widgets, A/B testing tools, conversion tracking and push notifications. Each individual processing needs its own description with legal basis, purpose, recipients, data categories and storage period. Anyone who generalizes here risks an order from the supervisory authority according to Art. 58 GDPR and, in the worst case, a fine according to Art. 83 Paragraph 5 GDPR. The external external data protection officer uses a tool matrix to check in the CIVAC Workspace what processing actually takes place on the website, compares the result with the processing directory in accordance with Art. 30 GDPR, checks the associated order processing contracts and adds missing clauses. This creates a coherent documentation from a collection of tools. Group structures with shared responsibility in accordance with Art. 26 GDPR are also mapped in the workspace, so that the distribution of tasks between the parent company and subsidiary is recorded in writing. Others run compliance like a filing cabinet. We run it like software.
Generator, law firm or DSB: which variant wears when
Generators create a standard text from a questionnaire. For a pure business card website without tracking, without forms and without third-party providers, this can be sufficient, as long as the provider is updated regularly and the source of the generation is cited. As soon as web analysis, conversion tracking, application forms, a shop or a customer portal come into play, the declaration becomes a legal assessment: legal bases, third country transfers, TIA, joint responsibility according to Art. 26 GDPR and cookie consent according to Section 25 TTDSG must be neatly brought together. The typical mistake is to place generator text on a complex website and simply ignore tools that are not in the template.
Law firms deliver high-quality texts, but often without ongoing maintenance. However, a data protection declaration is not a one-time document. It changes as soon as a new tool is integrated, a processor changes, a sub-processor is added or jurisdiction changes. The external data protection officer combines both levels: legal assessment plus operational maintenance. In the CIVAC Workspace, the declaration is versioned alongside the processing directory, AV contracts and TOM documentation. Every change creates an audit trail with author, date and reason. Licence the workspace for your internal representatives or have our representatives order it. Both provide the same proof: appointment certificate, signed, filed, verifiable. The auditor calls, the evidence is ready. For companies with multiple domains, international subsidiaries or frequently changing marketing stacks, this versioning is the decisive operational advantage over Word documents or Wiki pages. There is also the option of transferring tasks from the declaration directly into a ticket workflow, so that maintenance does not depend on a single person, but rather runs as a process with substitution regulations.
Cookies, tracking and Section 25 TTDSG: the most common mistake
§ 25 TTDSG requires consent for any access to end devices that is not absolutely necessary. This applies to practically all marketing and analysis cookies as well as local storage-based trackers, fingerprinting methods and pixels from third-party providers. Consent must be informed, voluntary, granular and as easy to revoke as it is to give. Cookie banners with preset checkmarks, dark patterns or no reject button are not permitted. The Data Protection Conference made it clear in its guidelines that shaky graphics, colour gradients, asymmetrical buttons and click traps also render consent ineffective. The ECJ confirmed the obligation to provide active consent in Planet49 (C-673/17) in 2019, the BGH followed this in BGH I ZR 7/16.
In this context, the data protection declaration must not only list every cookie, but also the provider, purpose, duration, data categories, recipient and third-country reference. Anyone who uses Google Analytics 4, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel or Microsoft Clarity transfers data to the USA. Here, the EU-US Data Privacy Framework must be checked, the certification numbers stated and additional measures documented, especially for sub-processors without DPF certification. There are 490 ready-to-use audit templates in CIVAC Workspace, including a complete tool matrix for web tracking. The data protection officer enters the tools for each domain, the system derives the necessary clauses from them and creates a versioned data protection declaration including a separate cookie declaration. If a tool is removed or added, the change is automatically propagated in the declaration and in the directory in accordance with Art. 30. In addition, the DPO checks whether the consent management tool used provides an audit-proof record of consent, since the burden of proof for consent lies with the person responsible (Art. 7 Para. 1 GDPR). Audit-proof, documented, § 25 TTDSG-proof.
Third country transfers: Schrems II, DPF and reality
Since the ECJ ruling in Schrems II (C-311/18), those responsible have had to check every time data is transferred to a third country whether the level of protection is essentially equivalent to that of the GDPR. For the USA, the EU-US Data Privacy Framework has been in effect as an adequacy decision in accordance with Article 45 of the GDPR since July 2023, but only for certified recipients. Anyone who uses a non-certified sub-processor still needs standard contractual clauses in accordance with Article 46 (2) (c) GDPR plus a transfer impact assessment. Additional special conditions apply to transfers to India, China, Great Britain or Switzerland. Great Britain benefits from its own adequacy decision, India and China require additional technical and organisational measures.
You must present this constellation transparently in the data protection declaration: which specific data goes where, on what legal basis, with what guarantees, and how can those affected receive a copy of the SCC. Phrases like “data can be transferred to third countries” are not enough. Supervisory authorities specifically check whether the guarantees mentioned match the actual tool landscape. CIVAC's compliance platform and officer-as-a-service maintains a list of certified DPF participants, maps them against your tool matrix and adds the missing TIA assessments. Each entry receives a reference to the source and an inspection note from the DSB. In this way, a marketing practice creates verifiable documentation that you can submit to the supervisory authority within the statutory deadline. When a provider exits the DPF, which has happened with several U.S. services in the past two years, the system highlights the gap and suggests action. For providers with an Asian group structure, such as TikTok or Alibaba Cloud, additional risk indicators such as court access rights and requests from authorities are checked and documented in the TIA. The appointment certificate, signed, filed, verifiable.
Processing directory and data protection declaration as twins
Art. 30 GDPR obliges those responsible and processors to keep a register of processing activities. The directory is internal, the data protection declaration is external, but both must be consistent in content. If the declaration names HubSpot, Hotjar and Vimeo, but the internal directory only knows HubSpot, the supervisory authority is right to impose fines in accordance with Article 83 (4) GDPR. Inconsistencies are the most common finding in audits and the most common reason for questions from the Group Audit Committee. As part of a due diligence check for M&A transactions, the data protection declaration and the directory are compared, often with points deducted if the structures do not match.
The CIVAC Workspace interlinks both documents: Each new processing is created centrally, the system automatically propagates the information into the directory according to Art. 30, the directory of processors, the data protection declaration and, if necessary, the DPIA according to Art. 35 GDPR. Versions are kept with a time stamp and person responsible. This creates the consistency that auditors expect. More background on the interaction of the documents can be found in the CIVAC FAQ. Anyone who has a data protection declaration drawn up should use the same source that maintains the processing directory. This means there are no breaks between internal documentation and external communication. Licence the workspace for your internal representatives or have our representatives order it. Reporting to management and the supervisory board also benefits: quarterly reports show which processing operations have been added, which AV contracts have been renewed, where action is required and what risk classifications the respective processing carries in accordance with Art. 35 GDPR. This visibility is particularly important for supervisory bodies, which must demonstrate appropriate risk management in accordance with Section 91 (2) AktG.
Applicant data, newsletters and customer forms
Three forms on a website generate three independent processing processes: the career form, the newsletter and the contact form. Section 26 of the Federal Data Protection Act (BDSG) applies to applicant data, Art. Each of these legal bases triggers its own obligations: for applicant data, a deletion period of usually six months after rejection in accordance with AGG evidence, for newsletters a double opt-in with logging of the IP address, the time stamp and the confirmation link, and for the contact form, retention within the framework of the HGB and AO deadlines if a business transaction follows.
A blanket data protection declaration does not cover these differentiations. For example, anyone who accepts applications via a third-party system such as Personio, Workday or SAP SuccessFactors must name the processor, document the AV contract, be transparent about the storage period and, if necessary, point out a talent pool function with separate consent. The CIVAC Workspace provides a ready-made clause library for each of these paths, which the external DSB releases. Risk management is also located in the processing directory: If a sub-processor changes, the system generates a notification to the DPO and the affected departments so that the declaration is updated and communicated internally before an applicant or newsletter subscriber requests information in accordance with Art. 15 GDPR. Turn reading into an assignment: If this is still organised in an Excel spreadsheet in your house, it's worth taking a look at the workspace. The integration with applicant management and the marketing automation system, which is particularly error-prone in practice, can also be managed because changes are visible across all processing.
Updates, versioning and the audit trail
A privacy policy gets old. Tools are introduced, abolished or changed, processors change their sub-processor list, new rulings and guidelines from the Data Protection Conference (DSK) shift obligations. Anyone who cannot prove at the time of an examination when which version of which declaration was valid will lose in the argument. Section 31 BDSG and Art. 24 GDPR require proof of compliance, not just the assertion. A clean versioned declaration is also an important means of defence in disputes with competitors who are considering taking action under competition law based on the UWG or the UGP Directive.
The CIVAC Workspace keeps each data protection declaration as a versioned document. Changes are logged with author, date, reason and approval. When published, the new version will be linked on the website; the old version will remain searchable for the duration of the retention period. This saves discussions with the supervisory authority if an incident from the previous year is brought up. You can find out more about the ordering and documentation methodology in the overview of CIVAC representative roles. The auditor calls, the evidence is ready. Deadline expires when we become aware of it: In the event of a data breach, clean versioning helps to quickly reconstruct which data was processed at what point in time according to which legal basis, which processor was involved and which TOMs were documented in the respective version. Without this database, the 72-hour deadline set out in Article 33 of the GDPR can hardly be met. A versioned inventory is also the basis for ensuring that external auditors receive the necessary evidence as part of a SOC2 or ISAE 3402 audit without having to build their own special report every quarter. In the case of an acquisition or an investor audit, this structured history is also a valuable asset because it demonstrates the care of the person responsible over several years.
Costs, effort and realistic delivery times
A well-prepared data protection declaration for a medium-sized website costs between 800 and 3,500 euros initially, depending on the tool landscape, number of processing operations, number of domains and third-country reference. Ongoing maintenance by an external data protection officer is often between 350 and 1,500 euros per month in the Officer-as-a-Service package, depending on the number of employees and risk profile. Compared to fines according to Art. 83 GDPR, which can amount to up to 20 million euros or 4% of global annual turnover for gross violations, this is a sensible investment in legal certainty. In addition, there is reputational damage, which is usually significantly more serious than the fine itself.
The delivery time is the second factor. Traditional law firms require two to six weeks, depending on workload and queries. The CIVAC SLA is two working days for the initial version, including tool matrix, processing directory entry and appointment certificate for the external DPO. This is made possible by the 490 ready-to-use audit templates, a standardised onboarding route in the workspace and a team of 25 representative roles who work in a coordinated manner across data protection, information security, compliance and occupational safety. For many medium-sized companies, this is the crucial difference: not the hourly rate, but the time until verifiable compliance. Licence the workspace for your internal representatives or have our representatives order it. In both models you receive the same documentation, the same audit trail, the same legal assessment and EU data residency for all filed documents. The main advantage from the management's point of view is that responsibility according to Section 130 OWiG is clearly documented and in an emergency, organisational negligence cannot be alleged.
How CIVAC embeds the privacy policy into the compliance stack
A data protection declaration is not an end product, but a node in a network of processing directory, AV contracts, TOM documentation, data breach reporting path according to Art. 33 GDPR (72 hours) and the NIS 2 reporting line (24h early warning, 72h follow-up report). CIVAC's compliance platform and officer-as-a-service bundles these elements in a workspace that is operated with EU data residency and hardened against an ISMS built according to ISO/IEC 27001:2022. The 93 controls and the 490 templates are linked in such a way that a change to the declaration automatically triggers the processing directory, the DPIA list and, if necessary, the supplier evaluation. This also applies to the preparation of external audits by auditors, ISO certifiers or the supervisory authority itself.
You have two paths: you licence the workspace and maintain the data protection declaration with your internal data protection officer, or you hand over the order to CIVAC and receive an external DPO including the appointment certificate within two working days. In both cases the data does not leave the European Economic Area and in both cases the proof is available before the auditor asks. Hybrid models are also possible: You keep your internal DPO and add individual special topics such as third-country transfers, international employment relationships or AI processing as an officer-as-a-service. Turn reading into a mandate.: Write to info@civac.de or use the contact form on civac.de. You will receive an initial assessment of your tool matrix, a proposal for the appointment certificate and a binding delivery date for the finished data protection declaration. The appointment certificate, signed, filed, verifiable. If your company now works with multiple Word documents, Sharepoint files and an Excel spreadsheet for AV contracts, the switch to a consolidated solution can be organised within a few weeks without disrupting ongoing operations.
FAQ
Do I even need a data protection declaration for a purely business card website?
Yes. The hosting itself creates server log files with IP addresses, which are personal data according to Art. 4 No. 1 GDPR. As soon as you use an imprint, a contact form, external fonts or embedded content, further processing is relevant. A slim but complete declaration in accordance with Art. 13 GDPR is therefore mandatory in any case and should be checked at least once a year.
Is a generator enough, or does a data protection officer have to sign?
A generator delivers a raw version. According to Art. 5 Para. 2 GDPR, responsibility for completeness and accuracy remains with the person responsible. As soon as tracking, applicant portals, third-country transfers or shared responsibilities are involved, an internal or external data protection officer should countersign the declaration and file it in a version. This reduces the risk of fines and the liability risk for management.
How often do I have to update the privacy policy?
Occasionally, in practice several times a year. The triggers are new tools, changes in processors, new sub-processors, case law from the ECJ or BGH as well as updated guidelines from the data protection conference. In the CIVAC Workspace, changes are recorded in a versioned manner so that each version remains traceable with the date and reason and exams can be passed retroactively. In addition, an annual full audit by the data protection officer is recommended.
How much does it cost to create a GDPR-compliant data protection declaration?
A cleanly created initial version for a medium-sized website costs 800 to 3,500 euros, depending on the tool landscape, third-country transfers and number of domains. Ongoing maintenance by an external data protection officer in the Officer-as-a-Service package is usually between 350 and 1,500 euros per month and includes the processing directory, AV management and the response to data subject rights. Compared to fines according to Art. 83 GDPR, this is a predictable investment.
Who is liable for an incorrect data protection declaration?
The responsible party within the meaning of Art. 4 No. 7 GDPR is the company, represented by the management. This can be held personally responsible according to Section 130 OWiG. An external data protection officer checks, documents and discharges, but does not assume the original responsibility according to Art. 24 GDPR, which is why the written order plays a central role.
What deadline applies in the event of a data breach, such as a data leak in the form?
According to Art. 33 GDPR, data breaches must be reported to the responsible supervisory authority within 72 hours of becoming aware of it, and in certain cases also to those affected in accordance with Art. 34 GDPR. Deadline begins as soon as we become aware of it. The CIVAC Workspace provides a reporting path that documents receipt, assessment, reporting and evidence, so that you can react in a legally compliant manner even under time pressure and meet the burden of proof.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.