Which data protection documents do I really need?
Of course, it’s impossible to make a blanket statement about which standard documents a company needs. The requirements simply vary too much depending on the company’s size and business sector.
However, most startups will eventually need the following data protection documents:
- Privacy Policy: The requirement for a privacy policy stems from the information obligations under Art. 13 et seq. GDPR. According to these provisions, the company (as the controller under the GDPR) must provide data subjects (often customers) with a range of information when collecting personal data. Privacy policies are particularly common for the operation of websites and apps, or in direct customer contact within a store.
- Data Processing Agreement: If a startup transfers personal data to third parties for processing, it requires a data processing agreement (Art. 28 GDPR) for this relationship. In today’s division-of-labor economy, this is the rule rather than the exception. A very common use case in the field of online marketing is, for example, the use of Google Analytics as a data processor for the collection and analysis of user data.
- Consent declaration: If personal data is collected on the legal basis of consent (Art. 6(1)(a) GDPR, Art. 7 GDPR), companies must obtain such consent from the data subject in compliance with the GDPR and be able to demonstrate this to the supervisory authority. Consent can only ever be given for a specific purpose; a common use case is consent for advertising and market research.
- Employee confidentiality agreement: Companies must ensure that employees or external service providers who have access to personal data maintain confidentiality when handling such data. This requirement stems from the accountability obligation under Article 5(2) of the GDPR. Therefore, these individuals should be trained, and this should also be documented via a confidentiality agreement. Employees can complete data protection training through caralegal, receive a recognized training certificate, and thereby increase awareness of data protection within the company.
Companies should create these documents, and potentially others, to meet their own needs and keep them up to date at all times to avoid data protection violations and the resulting fines.
How can I verify that standard documents are up-to-date and GDPR-compliant?
To ensure that the documents used are up to date, it is advisable to use data protection documents that include a version date or version history. For non-experts, GDPR compliance is usually not immediately apparent. The market, particularly in the area of templates, is very diverse, and GDPR compliance is often promised for marketing purposes.
Therefore, companies should take the time to seek out reliable providers and, above all, be aware that high-quality standard documents come at a price. To make data protection management easier for users, caralegal provides legally reviewed content with version dates. GDPR compliance is supported by the experts and attorneys at our partner firms ISiCO Datenschutz GmbH and Schürmann Rosenthal Dreyer Rechtsanwälte.
Who should prepare the documents?
Depending on the complexity, the initial version of the relevant documents can be prepared by a law firm specializing in IT law. Afterwards, the documents should only be modified by individuals with data protection expertise. Typically, this task is handled by the data protection officer. The next step is to collaborate with the relevant departments to adapt the templates to the company’s specific requirements.






