Blog
GDPR24 May 2026 8 min🇩🇰 Denmark

Privacy policy for websites: a complete guide 2026

A privacy policy guide: what must a privacy policy contain under the GDPR, how do you write one, and what are the typical mistakes? A complete guide for Danish websites.

Thor, Dokumentkonsulent

Written for Danish law and Danish contract practice.

Do you run a website that collects information from visitors via a contact form, a newsletter sign-up, cookies or a webshop? Then you are required to have a privacy policy. It is not a formality but a legal requirement under the GDPR, which applies to all businesses and websites that process personal data about EU citizens.

This guide explains what a privacy policy must contain, how to write one that complies with the GDPR, and which mistakes most often land businesses in trouble with the Danish Data Protection Agency.

What is a privacy policy?

A privacy policy (also called a data protection policy or privacy policy) is a document that informs your users, customers and visitors about how you collect, use, store and protect their personal data.

The document must be easily accessible, typically via a link in the footer of your website, and written in clear, understandable language. Legal jargon that makes the policy unreadable does not meet the transparency requirements under the GDPR.

When is a privacy policy mandatory?

You are required to have a privacy policy as soon as your website processes personal data. This applies if you:

  • Have a contact form (name, email, message)
  • Use analytics cookies (Google Analytics, Facebook Pixel etc.)
  • Run a webshop (customer register, order data, payment data)
  • Offer a newsletter sign-up
  • Have users who create accounts or log in
  • Collect IP addresses via server logs

These activities all constitute processing of personal data under GDPR Article 4, and the requirement for a privacy policy follows from the GDPR's duty to inform in Articles 13 and 14.

What must a privacy policy contain?

The GDPR sets specific requirements for the information your privacy policy must contain. Here are the mandatory elements:

1. The data controller's identity and contact details

State your business's full name, address, CVR number and contact details. The user must always know who is responsible for the processing of their data.

Example: "Data controller: Virksomhed ApS, Eksempelvej 1, 1165 Copenhagen K, CVR: 12345678, email: privatliv@virksomhed.dk"

2. The purposes of the processing and the legal basis

For each purpose of the data processing, you must state:

  • What are the data used for? (for example "answering your enquiry via the contact form")
  • Which legal basis gives you authority? (consent, contract, legal obligation or legitimate interest)

3. Categories of personal data

Describe what types of data you collect, for example name, email address, telephone number, IP address and payment details. If you process special categories (health data, data on ethnic origin etc.) or civil registration numbers, stricter requirements and additional documentation apply.

4. Recipients of personal data

If you disclose data to third parties, you must name them, either by name or as categories (for example "our email marketing platform" or "payment gateway"). If you use data processors, you must have entered into a data processing agreement with them.

5. Retention periods

State how long you keep the different categories of data. This can be specified per purpose, for example "Customer data in connection with a purchase is kept for 5 years in accordance with the Bookkeeping Act" and "Newsletter subscribers are deleted 6 months after unsubscribing."

6. The data subjects' rights

The privacy policy must inform users that they have the right to:

  • Access: to see what data you have about them
  • Rectification: to have incorrect data corrected
  • Erasure ("the right to be forgotten")
  • Restriction: to restrict the processing in certain situations
  • Data portability: to have their data provided in a machine-readable format
  • Objection: to object to processing based on legitimate interest, and an unconditional right to object to direct marketing

If the processing is based on consent, you must also state that consent can be withdrawn at any time.

7. The right to complain to the Data Protection Agency

You must inform users that they can lodge a complaint with the Data Protection Agency (datatilsynet.dk) or another relevant supervisory authority.

8. Whether data is transferred to third countries

If you use services from providers outside the EU/EEA (for example Google Analytics, Mailchimp or AWS), this must appear, along with the safeguards in place (typically the EU standard contractual clauses, SCC, possibly combined with a valid transfer basis such as the EU-US Data Privacy Framework).

9. On the use of automated decisions and profiling

If you use automated systems that make decisions with legal effect for the user (for example credit assessment or behaviour-based pricing), this must be mentioned explicitly, and the user has the right to request human intervention.

How to write a privacy policy step by step

Step 1: Map your data processing

Review all the places your website collects data: forms, cookies, analytics tools, payment systems, live chat, booking modules and more. Note what is collected and for what purpose.

Step 2: Identify your legal bases

For each purpose you must have a legal basis. The most used are:

Purpose Typical legal basis
Newsletter Consent
Order processing Performance of a contract
Accounting material Legal obligation (the Bookkeeping Act)
Analytics cookies Consent
Fraud prevention Legitimate interest

Step 3: Write the policy in clear language

The GDPR's transparency requirement (Article 5) means the text must be understandable for the target group. Avoid unexplained abbreviations, complex legal constructions and long sentences. Bullet points and tables make the policy more readable.

Step 4: Keep it updated

The privacy policy is a living document. If you introduce new services (for example a new CRM platform or a chatbot widget), the policy must be updated before the new processing starts.

The most common mistakes in privacy policies

1. Copy-paste from another business

A copied policy is rarely accurate for your website and may contain incorrect legal bases or missing purposes. The Data Protection Agency assesses the correctness of the content, not who wrote it.

2. An incorrect or missing legal basis

"Legitimate interest" is not a blank cheque for free data processing. Many businesses use it as a default justification without having carried out the necessary balancing of interests.

3. No update after new services

If you introduce a new analytics tool, CRM system or chatbot, the policy must be updated. It is not enough to have a generic wording like "we use cookies and analytics tools."

4. The policy is hard to find

A privacy policy must be easily accessible. Place a link in the footer and at all the points where you collect data (contact forms and sign-up flows).

5. Missing information about data processors

If you use third-party services (Google Analytics, Stripe, Mailchimp etc.), these are data processors. They must be named, and you must have a data processing agreement with them.

6. Vague retention periods

"We keep data for as long as necessary" is not precise enough. State specific periods per category or per purpose.

Privacy policy vs. cookie policy

Many people confuse the privacy policy with the cookie policy. The two documents are related but serve different purposes:

Privacy policy Cookie policy
Purpose Inform about all processing of personal data Inform specifically about cookies and tracking
Requirement GDPR Articles 13-14 The Cookie Order and the GDPR
Content All categories of data, purposes, rights Cookie types, purposes, lifetimes, third parties
Placement Website footer Footer and cookie banner

Many businesses choose to combine the two in one document with separate sections, and that is fully acceptable.

The Data Protection Agency's guidance

The Data Protection Agency has published guidance and examples of privacy policies at datatilsynet.dk. As a Danish business, you should use these as a reference, as they reflect the Danish supervisory authority's interpretation of the GDPR.

The Data Protection Agency supervises and can, among other things:

  • Issue orders to bring the processing into line with the rules
  • Express criticism
  • Recommend fines. In Denmark, GDPR fines are as a rule imposed by the courts following a report from the Data Protection Agency, and for serious breaches the fine can reach up to EUR 20 million or 4% of global annual turnover

The level of fines depends on the nature of the breach and the size of the business. For smaller businesses, actual fines have in practice often been considerably lower than the maximum, but they can become significant for serious or repeated breaches. A missing privacy policy is also a breach that is relatively easy for the authority to establish.

Frequently asked questions about privacy policies

Should the privacy policy be translated into English?

It depends on your target group. If your website also addresses users in other countries, the policy should be available in a language they understand. If you address only Danish-speaking users, a Danish policy is sufficient.

Can I use a free template from the internet?

Yes, but use it as a starting point, not as a finished product. Adapt the content to your specific website and data processing. A generic template rarely matches your actual processing practice.

Do I need to update the policy on changes in the law?

Yes. If the Data Protection Agency issues new guidance, or the interpretation of the GDPR changes, you should update your policy. The same applies if you change your data processing practice.

What happens if my website does not have a privacy policy?

The Data Protection Agency can establish the breach on inspection and issue an order or criticism, and in serious cases recommend a fine. It is a relatively easy matter for the authority to identify and document.

Does the requirement also apply to B2B websites?

Yes. Even though B2B contacts are business people, they are still natural persons with GDPR rights. If you collect their contact details, the duty to inform applies.

Conclusion

A privacy policy is not just a legal requirement but a foundation of trust. Users and customers are increasingly aware of what happens to their data, and a clear, honest privacy policy signals seriousness. Make sure it reflects your actual data processing, and keep it updated as you adopt new services.


The content of this article is for guidance only and does not constitute legal advice. The Data Protection Agency's guidance at datatilsynet.dk is the authoritative source for the current interpretation of the GDPR in Denmark.

Related templates

This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.