Website/business privacy notice under Article 13 of the Datenschutz-Grundverordnung (DSGVO, the German-facing text for the EU GDPR) plus the Bundesdatenschutzgesetz (BDSG) — a Data Protection Officer (Datenschutzbeauftragter "DSB") is mandatory once at least 20 people are continuously involved in automated processing of personal data (§ 38 BDSG), and cookie/tracking consent must comply with § 25 TDDDG.
⚠️ Это шаблон-болванка, а не юридическая консультация: перед использованием проверьте текст у юриста и адаптируйте под своё законодательство и конкретную ситуацию.
У этого шаблона опциональных разделов нет: текст одинаковый для всех. Поля показаны подписями: на сайте шаблон только для чтения, значения подставляются в системе.
PRIVACY NOTICE (DATENSCHUTZERKLÄRUNG)
Business name (responsible party), Business address Effective date: Effective date
This notice explains how Business name (responsible party) (the "Company", the responsible party / controller) collects, uses and protects personal data, in accordance with Article 13 of the EU General Data Protection Regulation (Datenschutz-Grundverordnung "DSGVO") and the Bundesdatenschutzgesetz "BDSG".
1. RESPONSIBLE PARTY 1.1. Business name (responsible party) is responsible for the processing described in this notice (Art. 4 Nr. 7 DSGVO). 1.2. Data Protection Officer (Datenschutzbeauftragter), if appointed: Data Protection Officer (Datenschutzbeauftragter), if any 1.3. ⚠️ Under § 38 BDSG, appointing a DSB is mandatory once at least 20 people are continuously engaged in the automated processing of personal data — this is easy to reach for a small restaurant/hotel/shop once part-time staff, POS terminals and marketing tools are counted.
2. WHAT DATA WE COLLECT AND WHY 2.1. What data is collected and why
3. PURPOSES AND LEGAL BASIS 3.1. Purposes and legal basis of processing
4. RECIPIENTS AND TRANSFERS ABROAD 4.1. Recipients & transfers abroad 4.2. Transfers of personal data outside the EU/EEA require either an adequacy decision covering the destination country or appropriate safeguards (e.g. EU standard contractual clauses).
5. RETENTION 5.1. Retention period
6. YOUR RIGHTS 6.1. Data subject rights 6.2. You may also lodge a complaint with the competent state data protection authority (Landesdatenschutzbehörde) if you believe your data has been mishandled.
7. COOKIES AND TRACKING 7.1. Cookies/tracking consent 7.2. Under § 25 Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG), storing or reading information on a visitor's device (cookies, tracking pixels, etc.) beyond what is strictly necessary for the service requested requires the visitor's prior, informed consent — a clear cookie-consent banner with a genuine "reject" option is required, not just an "accept" button.
8. CONTACT US 8.1. Questions about this notice, or requests to exercise your rights, may be sent to Privacy contact email.
⚠️ If CCTV, guest Wi-Fi logging, or staff monitoring is used, describe it explicitly in section 2 above and register it in the internal record of processing activities (Verzeichnis von Verarbeitungstätigkeiten, Art. 30 DSGVO) — this is typically the first document a supervisory authority asks for.
— — — ⚠️ This is a boilerplate template, not legal advice. German employment, consumer-protection, data-protection and workplace-safety law (BGB, Nachweisgesetz "NachwG", ArbSchG, MiLoG, SGB IV, DSGVO/BDSG, DDG, EGBGB Art. 246a) changes frequently and includes sector-specific exceptions — notably § 2a Gesetz gegen Schwarzarbeit "SchwarzArbG", which keeps the Gaststätten- und Beherbergungsgewerbe (restaurants and hotels) on paper-only Schriftform even after the BEG IV digitalisation reform. Statutory figures (Mindestlohn, Minijob-Grenze) are re-indexed periodically — have this document reviewed and adapted by a German employment/legal advisor (Rechtsanwalt/Steuerberater) and verified against the current rates before use. Where a German-language version of this document is also used, that version prevails in case of conflict.
Поля выключенных разделов приглушены — их не спрашивают.
Mandatory once ≥20 persons are continuously involved in automated data processing, § 38 BDSG
e.g. bookings, orders, CCTV, guest Wi-Fi, loyalty/marketing data
Processors, and any transfer outside the EU/EEA
Access, rectification, erasure, objection, and the right to complain to the state data protection authority
Consent required per § 25 TDDDG before non-essential cookies/tracking are set
2 из 11 полей берутся из карточки компании, сотрудника или контрагента, опросник можно надиктовать ИИ, а готовый документ выдаётся с номером, PDF и подтверждением ознакомления.