Data protection declaration: Does it have to be approved?

29. August 2026 Laura Datenschutz DSGVO Datenschutzerklärung Recht

The question of whether a data protection declaration must be approved is often the subject of discussion, especially in the context of the GDPR. According to the applicable regulations, the creation of a data protection declaration is an information obligation of the controller, but not an obligation to consent of the data subjects. The data protection declaration serves to make the rights and obligations of users as well as the processing of their personal data transparent. It explains what data is used for and what rights the data subjects have. Consent is only required if special processing takes place, such as the sale of data to third parties. In such cases, the consent of the persons concerned must be given explicitly and voluntarily. However, it is important to note that the consent must not be understood as consent to the entire data processing, but only for the specific purpose for which it is granted. In everyday life, this means that companies must formulate their data protection declaration clearly and comprehensibly in order to minimize legal risks and gain trust among users. At the same time, they should check whether consent is actually necessary or whether the processing can be based on other legal bases, such as a contract or a legal obligation. The legal situation is complex, which is why it is advisable to contact a data protection officer or lawyer in case of uncertainty to ensure that all requirements are met. Overall, the data protection declaration is a central component of data processing, which plays a central role not only legally but also ethically. It is a sign of transparency and trustworthiness, which is crucial for the relationship between companies and users. ## What does this mean for your company? The obligation to create a data protection declaration is a fundamental part of the GDPR. It must be formulated clearly, comprehensibly and fully in order to protect the rights of users and avoid legal consequences. Consent is only required in exceptional cases, and even then it must be given voluntarily and specifically. It is important to make the processing of your data transparent in order to gain trust with your customers and employees. ## How ISN/xynap supports the modules of the infrastructure are GDPR compliant and help you to make your data processing transparent and legally compliant.

Sources (3)

  1. www.dr-datenschutz.de
  2. the-decoder.de
  3. www.golem.de