Skip to content

Reviewing and Keeping Your Website's Privacy Policy Up to Date

Provimedia 5 min read 11 July 2026 2 views
Unternehmerpflichten
Reviewing and Keeping Your Website's Privacy Policy Up to Date
Illustrative image · AI-generated

Anyone who operates a website automatically processes visitors' personal data and is obligated to inform them transparently about it. This is exactly what the privacy policy regulates, and no German website can do without one.

In brief: the privacy policy is a legally required disclosure under Articles 13/14 GDPR that explains which personal data a website collects, for what purpose, and on what legal basis. Every website operator is affected, from sole proprietors to large corporations. If it is missing or outdated, fines and warning notices (Abmahnungen) may follow.

Who is subject to the obligation to provide a privacy policy?

Every person and company that operates a website and processes personal data in doing so must provide a privacy policy. This affects practically all websites, because even a page visit, a contact form, a newsletter signup form, or embedded tracking tools process personal data such as IP addresses or email addresses. Legal form and company size do not matter: the obligation applies to sole proprietors and freelancers just as much as to small businesses and large corporations. Purely informational pages without an online shop or login area are not exempt either. Even if a website has only a few visitors or seems purely private, that does not change the legal obligation; what matters is solely that personal data is processed, not the size of the audience.

What must be included in the privacy policy?

For every single data processing activity on the website, you must state the purpose, the legal basis, possible recipients of the data, and the retention period. This applies separately to each processing activity; a blanket statement that data is processed "within the scope of statutory provisions" is not sufficient. In addition, the policy must include data subject rights: the right to access, rectification, erasure, and objection to processing. This is supplemented by the contact details of the controller and, where applicable, the data protection officer, so that data subjects can actually exercise their rights. Completeness at the level of individual services is important here: a contact form, a newsletter tool, and a hosting provider are each independent processing activities with their own purpose and legal basis, and must be listed separately accordingly.

What exactly do you need to do?

To create a legally sound privacy policy and keep it up to date permanently, it is best to proceed in these steps:

  1. Record all data processing activities on the website (contact form, newsletter, tracking, hosting, payment services).
  2. Name the purpose, legal basis, recipients, and retention period for each processing activity.
  3. List data subject rights (access, erasure, objection) and the controller's contact details.
  4. Link the privacy policy so it is easy to find (usually in the footer).
  5. Update the policy promptly whenever new tools or services are introduced, such as a new newsletter provider.

By when and how often must it be updated?

There is no fixed deadline for the initial creation; the obligation to inform applies from the day your website goes live and processes personal data. More important than that first date is ongoing maintenance: as soon as a processing activity changes, for example through a new tracking tool, a new newsletter provider, or a new hosting or payment service provider, the policy must be adjusted promptly. A regular check, for example once a year, is also advisable to catch outdated information, even if nothing appears to have changed. Anyone who adds new processing activities only with a delay risks a policy that no longer reflects reality at the time it is used; that is exactly what supervisory authorities and competitors alike check for.

What are the consequences of a violation?

If the privacy policy is missing, outdated, or incomplete, fines of up to €20 million or 4% of global annual turnover may apply. In practice, however, it is rarely the supervisory authorities that react first: more often, warning notices (Abmahnungen) come from competitors or consumer protection associations that treat a missing or defective privacy policy as a competition law violation. Both risks exist independently of each other and can also occur at the same time, if a violation first becomes public and is then taken up by an authority. A tool like Company Audit shows which of these obligations specifically apply to your company by checking compliance requirements individually for your business.

Frequently asked questions

Is a generator enough to create a privacy policy?

Generators only provide a framework. You must enter the specific processing activities on your website correctly yourself, otherwise the policy stays incomplete or incorrect. A generated template therefore does not replace your own inventory of all the tools and services actually in use.

Do I need a privacy policy even if I do not use a contact form?

Yes. Even a simple page visit usually processes personal data such as the IP address via the hosting provider, so the obligation to inform applies regardless of whether there is a contact form. Purely text-based or portfolio pages without any interaction options are not exempt either.

Where must the privacy policy be linked?

The common and recommended approach is a clearly visible link in the footer that is reachable from every subpage of the website. This way, visitors find the policy regardless of which page they land on, without having to actively search for it.

What is better: listing everything conceivable or only the services actually used?

When in doubt, it is more sensible to phrase things concisely and truthfully rather than listing all conceivable processing activities that do not actually take place on the website. An overly broad, precautionary listing can be just as misleading as an incomplete one.

Who is responsible for keeping the privacy policy up to date?

The website operator itself is responsible. It must update the policy independently for every new processing activity, such as an additional tool or service provider; an obligation that cannot be delegated to agencies or hosting providers.

Source: Articles 13/14 GDPR. This article is general information and does not replace legal advice for individual cases. As of: July 2026.

Share this article

Stay up to date

Get the latest articles, insights and industry updates straight to your inbox.

Unsubscribe at any time. See our privacy policy.

Decide for yourself what Google shows you

Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.

Add provimedia.de to my preferred sources

Ihre Unternehmer­pflichten im Griff

Company Audit erstellt Ihnen in wenigen Minuten eine individuelle Pflichtenliste – mit Fristen-Kalender, Erinnerungen und KI-Assistent. Für Selbständige und KMU.