Privacy policy for websites: a GDPR guide
What must your website's privacy policy contain? A complete GDPR guide to privacy policies for businesses and webshops in Denmark, with examples and a checklist.
Thor, Dokumentkonsulent
Do you have a website, webshop or digital platform that collects personal data from users? Then you are required by the GDPR to have a clear and accessible privacy policy. If you lack one, or your existing policy is incomplete, you risk orders and fines from the Danish Data Protection Agency and the loss of your users' trust.
This guide explains what a privacy policy must contain, what the GDPR requires, and what you as a Danish business must do to comply.
What is a privacy policy?
A privacy policy (in Danish "persondatapolitik" or "privatlivspolitik") is a document that informs users about:
- Which personal data you collect about them
- Why you collect it (the purpose of the processing)
- What you use it for
- Who has access to the data
- How long you keep it
- Which rights the users have
A privacy policy is not a formal consent document. It fulfils the duty to inform. You must provide this information to the people whose data you process, whether or not you ask for consent.
Who is required to have a privacy policy?
All businesses and organisations that process personal data about EU citizens are subject to the GDPR. This applies regardless of the size of the business.
You are required to have a privacy policy if your website:
- Collects email addresses (newsletter, contact form)
- Uses analytics tools (Google Analytics, HubSpot etc.)
- Sells products and stores customer data
- Uses cookies for tracking or personalisation
- Has log-in features
- Uses chat features or live support
- Embeds social media or third-party content
Important: Even passive use of Google Analytics constitutes processing of personal data and requires a privacy policy.
What must the privacy policy contain?
The GDPR (Regulation 2016/679) Articles 13 and 14 list the mandatory information you must give to the data subjects (the users).
1. Identification of the data controller
Who is responsible for the processing of data?
- The company's name
- CVR number
- Physical address
- Contact details (email, telephone)
- The DPO (data protection officer), which is only relevant for businesses that are required to appoint a DPO under Article 37
2. Categories of personal data and purposes of collection
Describe clearly what data you collect and why:
Example table:
| Category of data | Purpose | Legal basis |
|---|---|---|
| Name and email | Sending a newsletter | Consent (GDPR Art. 6(1)(a)) |
| IP address | Analysis of website traffic | Legitimate interest (GDPR Art. 6(1)(f)) |
| Order data | Order processing and accounting | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Cookie data | Personalisation and marketing | Consent (Art. 6(1)(a)) |
3. Legal basis for the processing
The GDPR requires every processing of personal data to have a legal basis. The most used for websites are:
- Consent (Art. 6(1)(a)): The user has given free, informed and unambiguous consent, for example to cookies and a newsletter
- Contract (Art. 6(1)(b)): The processing is necessary to perform an agreement with the user, for example e-commerce
- Legal obligation (Art. 6(1)(c)): You are legally required to keep the data, for example accounting data
- Legitimate interest (Art. 6(1)(f)): Your business's legitimate interest outweighs the user's interest in privacy, for example fraud prevention and basic analysis
4. Recipients of personal data
Who do you share data with? State:
- Data processors (for example hosting providers, analytics tools, email platforms)
- Any third-party recipients (for example a payment gateway, social media)
- Transfers to third countries outside the EU/EEA
Third-country transfers: Do you use Google Analytics, the Facebook Pixel or other US services? This can constitute transfers to third countries. You must state the transfer basis used (for example the EU-US Data Privacy Framework) and inform users of the risks it involves.
5. Retention period
State how long you keep the different categories of data:
- Customer data: Accounting material must as a rule be kept for 5 years after the end of the financial year the material relates to (the Bookkeeping Act)
- Email subscribers: As long as the subscription is active plus a reasonable period (for example 1 year after unsubscribing)
- Contact form enquiries: Typically 1-2 years
- Log files and technical data: Typically 3-12 months
6. Users' rights
You must inform users that they have the following rights:
Right of access (Art. 15): The user can request to see what data you have recorded.
Right to rectification (Art. 16): The user can require incorrect data to be corrected.
Right to erasure ("the right to be forgotten") (Art. 17): Under certain conditions the user can require their data to be erased.
Right to restriction of processing (Art. 18): The user can require the processing to be restricted in certain situations.
Right to data portability (Art. 20): The user can receive their data in a machine-readable format and transfer it to another provider.
Right to object (Art. 21): The user can object to processing based on legitimate interest, and there is an unconditional right to object to direct marketing.
Right to withdraw consent (Art. 7(3)): If the processing is based on consent, the user can withdraw it at any time.
State how users exercise these rights (an email address etc.), and state that they can complain to the Danish Data Protection Agency.
7. Right to complain to the Data Protection Agency
You must inform users that they can complain to the Danish Data Protection Agency (datatilsynet.dk) if they believe you are processing their data in breach of the GDPR.
8. Automated decisions and profiling
Do you use automated systems to make decisions about users, for example credit scoring, ad targeting or product recommendations? Then you must inform users of this and give them the right to request human intervention.
Cookies and a cookie policy: separate requirements
In addition to the privacy policy, the Danish Cookie Order (implementing the ePrivacy Directive) requires:
- Prior consent to non-essential cookies (analytics and marketing cookies)
- A clear cookie banner that informs about cookie use and gives the user a choice
- The option to reject cookies or adjust the consent
Essential cookies (those necessary for the website to function) do not require consent.
Note: Your privacy policy should contain a section on cookies that refers to your cookie policy, or vice versa. The two documents are closely connected.
When should the privacy policy be updated?
You must update your privacy policy:
- When you start collecting new categories of data
- When you switch to new analytics tools, newsletter platforms etc.
- When you start sharing data with new third parties
- On changes in the law or new guidance from the Data Protection Agency
- At least once a year as a routine
Remember to state the update date on the document, so users can see when it was last changed.
Placement and accessibility on the website
The GDPR requires the privacy policy to be easily accessible to users.
Good practice:
- A link in the website footer (the most used placement)
- A link in consent banners (cookies, newsletter)
- A link in the checkout process (webshops)
- A link in contact forms
Bad practice (avoid):
- Only accessible via a search function
- Hidden behind a sub-item in the "About us" section
- Not linked from the cookie banner
The most common mistakes in privacy policies
- Copied and uncritically used standard text. Many policies are generic and do not match the business's actual data practices
- Outdated content. The policy is not updated after a switch to new third-party services
- Missing third-country transfers. In particular, the use of Google Analytics and other US services is not mentioned
- An unclear legal basis. People write "we process your data" without stating the legal basis
- Missing information on rights. Users do not know they can require access or erasure
- No update date. Users cannot see whether the policy is current
The GDPR and children
If your website collects data from children, particularly strict rules apply. When an information society service is offered directly to a child, processing based on consent is in Denmark only lawful if the child is at least 13 years old. If the child is under 13, consent is required from the holder of parental responsibility (GDPR Article 8 and section 6 of the Danish Data Protection Act). State your age limit in the privacy policy.
The privacy policy and B2B: what is different?
Most guides on privacy policies focus on consumers. But what about B2B?
If your business processes personal data about contact persons at customers and suppliers (for example "Lars Hansen, purchasing manager, lars.hansen@company.dk"), that data is personal data and regulated by the GDPR, even though the purpose is commercial.
What you must do:
- Your privacy policy (or a B2B version of it) should cover the processing of contact persons' data
- You can inform them by sending an email with a link to the policy
- These contact persons have the same rights as consumers: access, erasure and objection
Consequences of a missing or inadequate privacy policy
The Data Protection Agency has the power to:
- Issue orders to bring the processing into compliance with the GDPR
- Recommend fines. In Denmark, GDPR fines are as a rule imposed by the courts following a report from the Data Protection Agency, and the level of fines can reach up to EUR 20 million or 4% of global annual turnover, whichever is higher
- Publish decisions, which can harm the business's reputation
For most SMEs, an actual fine for an inadequate privacy policy is rare on a first breach if you show a willingness to put things right. But the Data Protection Agency carries out ongoing supervisory activities, and complaints from users can trigger an investigation.
A missing privacy policy can also lead to:
- The loss of user trust and negative publicity
- Lost business opportunities with companies that impose GDPR requirements on suppliers
- Breach of contract towards B2B customers who require compliance
External data processing: what must appear in the policy?
Most businesses use one or more cloud services that process personal data:
- Mailchimp or ActiveCampaign (email marketing)
- Zendesk or Freshdesk (customer service)
- Stripe or QuickPay (payment processing)
- HubSpot or Salesforce (CRM)
- Google Workspace (email, documents)
All of these providers are data processors, and your business is the data controller. You are responsible for these providers processing data correctly, and you must:
- Enter into a data processing agreement with them (most large providers offer standard agreements)
- Inform users that you use them, in your privacy policy
- State whether transfers to third countries take place
Conclusion
A privacy policy is not just a legal requirement but a signal of trust to your users. Make sure it reflects your actual data practices, states the legal basis and retention periods, informs users of their rights and complaint options, and is kept up to date. A generic template text that does not fit your business is often worse than nothing.
The content of this article is for guidance only and does not constitute legal advice. Consult an adviser with GDPR expertise for advice on your specific situation.
Related templates
This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.