Privacy Policy Generator Germany
GDPR plus BDSG, the TDDDG cookie rules, the Impressum duty and a live Abmahnung industry.
A German Datenschutzerklärung carries more than GDPR. It sits next to a statutory Impressum, it has to name the state supervisory authority for your Land, and it is read by an audience that includes competitors looking for a reason to send an Abmahnung.
Germany is the strictest practical market in the EU, not because GDPR reads differently there but because three extra layers sit on top. The Bundesdatenschutzgesetz fills the GDPR opening clauses, the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG, formerly TTDSG) governs cookies in § 25, and the Digitale-Dienste-Gesetz carries the Impressum duty in § 5.
Enforcement is also decentralised. Sixteen state authorities plus the federal commissioner supervise different sectors, and they coordinate through the Datenschutzkonferenz rather than acting as one body. Guidance that is settled in one Land is sometimes still contested in another.
The distinctive German risk is private enforcement. Competitors and Abmahnvereine send cease-and-desist letters with cost demands over a missing Impressum, an unlawfully embedded Google Font or a cookie banner without a same-level reject button. That happens on a timescale of weeks, long before any regulator would act.
What a privacy policy in Germany has to cover
Controller identity matching the Impressum exactly, including legal form and register number
The competent state supervisory authority for your Land, named as the complaint route
Your Datenschutzbeauftragter, or an explanation of why the § 38 BDSG threshold is not met
Every remote asset that transmits an IP address before consent - fonts, maps, embeds, CDNs
Creditworthiness checks for invoice and instalment payment, including the agency used and the Article 22 position
German employee data under § 26 BDSG belongs in a separate staff notice. Mixing it into the public policy tends to produce a document that is wrong for both audiences.
How Germany actually moves personal data
Google Fonts and other remote assets
A Munich court held that loading Google Fonts from Google’s servers transmits the visitor’s IP address without a basis. Self-hosting fonts, maps and scripts is now the German default, and the policy should say which assets are self-hosted.
Employee data under § 26 BDSG
German employment processing has its own basis and its own limits, and works council co-determination applies to any tool capable of monitoring performance - which includes most analytics and ticketing systems.
Payment by Rechnungskauf and SEPA direct debit
Buy-now-pay-later and invoice purchase are dominant in German e-commerce and involve creditworthiness checks by SCHUFA or Creditreform, which is a disclosure and an Article 22 question at the same time.
Consent records under § 25 TDDDG
The burden of proving consent sits with you, and German courts have been willing to look at the actual banner implementation rather than the policy’s description of it.
Newsletter double opt-in
German case law effectively requires confirmed opt-in with a logged confirmation email. Single opt-in lists are the ones that generate Abmahnungen.
Third parties the draft will ask you about
Stripe · Klarna · PayPal · SCHUFA · DHL · Hetzner · IONOS · Matomo · CleverReach · Datev
The rules that apply
GDPR + BDSG
The BDSG carries German rules on employee data (§ 26), video surveillance, and the threshold at which a Datenschutzbeauftragter becomes mandatory.
§ 25 TDDDG
Consent before storing or accessing information on a device, with a narrow strictly-necessary exemption. This is the German cookie rule, and it is not GDPR.
§ 5 DDG - Impressum
A complete legal notice with company form, register number, VAT ID, managing directors and a contact route. Missing it is the most-abmahnt defect on the German web.
Mandatory data protection officer
Required where twenty or more people are constantly engaged in automated processing, or where processing needs a DPIA - a far lower bar than the GDPR default.
Widerrufsbelehrung
Distance-selling cancellation instructions in the statutory form. Getting the wording wrong extends the cancellation window from fourteen days to twelve months.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
The German checklist
Publish a complete Impressum
Company name and legal form, address, contact, register court and number, VAT ID, and the person responsible for editorial content where you publish one.
Self-host every third-party asset you can
Fonts, icon sets, maps and analytics. Anything that phones home before consent is a live risk.
Check the DPO headcount threshold
Count everyone who regularly handles personal data automatically - including part-timers and contractors.
Use the statutory cancellation wording
Copy the model Widerrufsbelehrung and model withdrawal form rather than rewriting them.
Log double opt-in confirmations
Keep the confirmation email, timestamp and IP for every subscriber; it is the evidence that ends a marketing complaint.
Where this usually goes wrong
No Impressum, or an incomplete one
It must be reachable in two clicks from every page and carry the register court, register number, VAT ID and representative. This is the single most common cause of a German cease-and-desist letter.
Loading fonts, maps or scripts from US servers before consent
Each remote asset transmits an IP address. German courts have awarded damages for exactly this, and the fix - self-hosting - is cheaper than the letter.
A cookie banner where reject is a text link
Under § 25 TDDDG the German authorities expect reject at the same level as accept. The DSK guidance is explicit.
Not appointing a Datenschutzbeauftragter when the headcount rule bites
Twenty people regularly processing personal data by automated means triggers the duty regardless of company size, and the appointment must be notified to the state authority.
Wrong Widerrufsbelehrung wording
The cancellation instruction is prescribed almost word for word. A paraphrase extends the withdrawal period to a year and is independently actionable.
Frequently asked questions
Do I need a German-language privacy policy?
If you address the German market, yes in practice. Transparency under Article 12 requires plain, intelligible language for the audience, and German courts have treated English-only notices aimed at German consumers as failing that test.
What is an Abmahnung?
A formal cease-and-desist letter, usually from a competitor or an association, demanding you stop a practice and pay their legal costs. It is a private enforcement mechanism with no regulator involved, and it moves in weeks.
Is Google Analytics legal in Germany?
It can be, with consent obtained before the tag fires, IP anonymisation configured, a processor agreement in place and a documented transfer assessment. What is not defensible is loading it on page one before any consent.
When do I need a Datenschutzbeauftragter?
When twenty or more people are constantly engaged in automated processing of personal data, or when your processing requires a DPIA, or when you process for commercial transfer or market research. The threshold is German, not GDPR.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator Germany
Answer a short questionnaire and get a draft written for Germany. Free to start, no card required.
Generate your privacy policyOther documents for Germany
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.