A web agency in Strasbourg maintains sixteen websites: twelve for French clients, four for German ones. Each site was delivered by a different project manager, on a different date, with a different legal-page template. One German client has just forwarded a letter from a law firm pointing out a gap in the site's Impressum. The question in the Monday meeting is simple: "Do our other sites have the same problem, and why did the French template not catch it?" This article answers in three parts: what is identical on both sides of the Rhine, what differs, and how to run a single review for both countries.
Disclaimer: this article is provided for information only and does not constitute legal advice. The texts cited are those in force at the time of writing; for a specific situation, consult a qualified legal professional.
The GDPR and the DSGVO are the same text. "DSGVO" (Datenschutz-Grundverordnung) is simply the German name of Regulation (EU) 2016/679 of 27 April 2016, applicable since 25 May 2018 in every Member State. It was not transposed into national law: it applies as written. The articles that weigh most on a brochure site or an online shop are therefore the same in Lyon and in Munich:
The cookie rule is also shared in principle. It comes from Directive 2002/58/EC, the "ePrivacy" directive, which each State transposed into its own law: in France as article 82 of the Loi Informatique et Libertés, in Germany as § 25 TDDDG. Both say the same thing: no storing or reading of information on the user's device without consent, except to transmit a communication or to provide a service the user has expressly requested.
What the agency gains: the privacy policy, the record of processing, the processor contracts and the logic of the cookie banner can share a single skeleton. Only the national details change.
The legal notice (mentions légales). The list of publisher identification details (company name, registered office, telephone, registration number, share capital, publication director, hosting provider) now sits in article 1-1 of the Loi pour la confiance dans l'économie numérique (LCEN, law no. 2004-575). That article was created by law no. 2024-449 of 21 May 2024; until then the same list lived in article 6, part III, which is the reference most page templates still quote. The full list is in our article on the French legal notice.
Cookies. Article 82 of the Loi Informatique et Libertés sets the prior-consent principle. The CNIL spelled it out in its guidelines and recommendation of 17 September 2020: continuing to browse is not consent, refusing has to be as easy as accepting, and certain audience-measurement tools can be exempt from consent under conditions. The details are in our article on the "Reject all" button.
Email marketing. For individuals, the CNIL points to article L.34-5 of the Code des postes et des communications électroniques: consent before any commercial email.
The authority. One: the CNIL, for the whole country.
The Impressum. The German counterpart of the legal notice is § 5 of the Digitale-Dienste-Gesetz (DDG, the German Digital Services Act), a law of 6 May 2024 that entered into force on 14 May 2024. Older templates still cite "§ 5 TMG": that reference needs updating. The statute asks for the information to be "leicht erkennbar, unmittelbar erreichbar und ständig verfügbar" (easily recognisable, directly reachable and permanently available). The list covers name and address, legal form and authorised representatives, a means of fast electronic contact, the register and registration number, the VAT identification number where applicable, and the supervisory body for activities that require a licence. The law does not prescribe a language; in practice, the Impressum of a site aimed at a German audience is written in German.
Cookies. § 25 TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, the telecoms and digital-services privacy act of 23 June 2021 that transposes Directive 2002/58/EC) requires consent given on the basis of "clear and comprehensive information". Its only exceptions are transmitting a communication and what is "unbedingt erforderlich" (strictly necessary) for a service the user expressly requested. The text contains no specific exemption for audience measurement. One detail worth knowing: gesetze-im-internet.de still serves the TDDDG under the old "ttdsg" path — a trace of the former name TTDSG that many cookie banners still display.
National law. The Bundesdatenschutzgesetz (BDSG, the federal data protection act) supplements the regulation. Its § 38 requires a data protection officer as soon as a company regularly employs at least 20 people permanently on automated processing of personal data, a threshold the regulation itself does not contain and that Article 37(4) GDPR allows Member States to add.
The authority. Not one but sixteen. Article 51 GDPR lets each State provide "one or more" authorities, and Germany chose a federal structure: § 40 BDSG entrusts supervision of companies to the authorities of the Länder. The federal commissioner, the BfDI, publishes the list of the sixteen Landesbehörden. For a given client, the competent authority is the one of the federal state where the client is established, and that is the one named in its privacy policy.
| Item | French website | German website |
|---|---|---|
| Publisher identification page | Mentions légales, LCEN, article 1-1 | Impressum, § 5 DDG |
| Privacy policy | GDPR, Article 13; names the CNIL | GDPR, Article 13; names the Landesbehörde of the state |
| Cookie banner | Article 82 Loi Informatique et Libertés; refusing as easy as accepting (CNIL) | § 25 TDDDG; consent based on "clear and comprehensive information" |
| Analytics | Exemption possible under conditions (CNIL, 17 September 2020) | No specific exemption in § 25 TDDDG; consent by default |
| Contact form | GDPR, Articles 6, 13 and 32 | GDPR, Articles 6, 13 and 32: identical |
| Newsletter | Prior consent of individuals, article L.34-5 CPCE (CNIL) | Prior express consent, § 7 UWG; double opt-in is the usual way to prove it (GDPR, Article 7(1)) |
| Processors (hosting, email service) | GDPR, Article 28 | GDPR, Article 28: identical |
| Data protection officer | GDPR, Article 37 only | GDPR, Article 37 plus the 20-person threshold of § 38 BDSG |
| Supervisory authority | CNIL | Landesbehörde of the client's state (BfDI list) |
| Language of the legal pages | French in practice | German in practice |
Back to the Strasbourg agency. The problem was never German law: it was sixteen different templates. Here is a method that fits in a spreadsheet.
The payoff: the day a German client forwards a letter, the answer to "do our other sites have the same problem?" is one row in the spreadsheet, not a week of re-reading.
The free Sitetals check reviews your home page and reports, among other things, whether a legal notice page or a privacy policy page is missing or unreachable, and which third-party services your site loads. It is a starting point for the review described above, not a replacement for it.
Also worth reading:
Sources: Regulation (EU) 2016/679, Articles 5, 6, 7, 13, 21, 28, 30, 32, 37, 51 and 99 · Law no. 2004-575 of 21 June 2004 (LCEN), article 1-1 · Law no. 78-17 of 6 January 1978, article 82 · CNIL, guidelines and recommendation on cookies and other trackers of 17 September 2020 · CNIL, "Cookies et traceurs : que dit la loi ?" · CNIL, "La prospection commerciale par courrier électronique" · Digitale-Dienste-Gesetz, § 5 · Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, § 25 · Bundesdatenschutzgesetz, §§ 38 and 40 · Gesetz gegen den unlauteren Wettbewerb, §§ 7, 8 and 13 · BfDI, state authorities · Sitetals methodology.
Sitetals editorial team