Data protection essentials: The Key Documents You Need

For startups in particular, it is often a challenge to have all data protection documents available in the right format and up to date. Numerous providers offer data protection templates, both free and paid. Companies must first determine which documents they actually need, whether they are suitable for their business, and how to manage them effectively within their data protection management system.

Those who use a software-based data protection management system can often store and manage the created templates in one place. With caralegal’s data protection management software, we provide a document center so that companies can quickly access the required documents at any time in their latest versions.

Overview of the essential data protection documents companies need under the GDPR

Which data protection documents do I really need?

Of course, it’s impossible to make a blanket statement about which standard documents a company needs. The requirements simply vary too much depending on the company’s size and business sector. 

However, most startups will eventually need the following data protection documents:  

  • Privacy Policy: The requirement for a privacy policy stems from the information obligations under Art. 13 et seq. GDPR. According to these provisions, the company (as the controller under the GDPR) must provide data subjects (often customers) with a range of information when collecting personal data. Privacy policies are particularly common for the operation of websites and apps, or in direct customer contact within a store.
  • Data Processing Agreement: If a startup transfers personal data to third parties for processing, it requires a data processing agreement (Art. 28 GDPR) for this relationship. In today’s division-of-labor economy, this is the rule rather than the exception. A very common use case in the field of online marketing is, for example, the use of Google Analytics as a data processor for the collection and analysis of user data. 
  • Consent declaration: If personal data is collected on the legal basis of consent (Art. 6(1)(a) GDPR, Art. 7 GDPR), companies must obtain such consent from the data subject in compliance with the GDPR and be able to demonstrate this to the supervisory authority. Consent can only ever be given for a specific purpose; a common use case is consent for advertising and market research. 
  • Employee confidentiality agreement: Companies must ensure that employees or external service providers who have access to personal data maintain confidentiality when handling such data. This requirement stems from the accountability obligation under Article 5(2) of the GDPR. Therefore, these individuals should be trained, and this should also be documented via a confidentiality agreement. Employees can complete data protection training through caralegal, receive a recognized training certificate, and thereby increase awareness of data protection within the company.

Companies should create these documents, and potentially others, to meet their own needs and keep them up to date at all times to avoid data protection violations and the resulting fines.

How can I verify that standard documents are up-to-date and GDPR-compliant?

To ensure that the documents used are up to date, it is advisable to use data protection documents that include a version date or version history. For non-experts, GDPR compliance is usually not immediately apparent. The market, particularly in the area of templates, is very diverse, and GDPR compliance is often promised for marketing purposes. 

Therefore, companies should take the time to seek out reliable providers and, above all, be aware that high-quality standard documents come at a price. To make data protection management easier for users, caralegal provides legally reviewed content with version dates. GDPR compliance is supported by the experts and attorneys at our partner firms ISiCO Datenschutz GmbH and Schürmann Rosenthal Dreyer Rechtsanwälte.

Who should prepare the documents?

Depending on the complexity, the initial version of the relevant documents can be prepared by a law firm specializing in IT law. Afterwards, the documents should only be modified by individuals with data protection expertise. Typically, this task is handled by the data protection officer. The next step is to collaborate with the relevant departments to adapt the templates to the company’s specific requirements.

Newsletter sign up

  • Only relevant news
  • Monthly
  • Over 2,000 subscribers are already reading it

Article written by

Dennis Kurpierz Co-Founder & COO

Dennis Kurpierz is co-founder and Chief Operating Officer of caralegal. Thanks to his many years of experience as a senior consultant and lead project manager at ISiCO Datenschutz GmbH, he is familiar with customer needs, pain points, and challenges in data protection management. As product owner, he applies this expertise to product development at caralegal.

All i need is
more time
caralegal

Set up in just 2 days
64 % time reduction
20 years of privacy expertise