1. Building Foundational Knowledge of Data Protection and Laying the Groundwork for Compliance
To be data protection-compliant from the start, it's worth building foundational knowledge of the General Data Protection Regulation (GDPR), since it needs to be considered from day one. This prevents having to invest significant effort in retroactive adjustments later on — or even facing steep fines.
We're happy to help you build this foundational knowledge through expert articles on our website. Their main purpose is to give you a general overview and help you understand the principles of the GDPR.
To build a solid foundation for proper data protection, it helps to understand your business processes as early as the planning and development stage, documenting the collection, storage, use, and deletion of personal data across different areas and departments. This makes it much easier later on to create documents such as the record of processing activities, since the way data is processed is already known.
It's also important to note that high technical security standards in IT alone aren't enough to achieve data protection compliance.
2. Appointing a Data Protection Officer
Many companies also wonder, especially as they start to grow, at what point they need a data protection officer. In general, appointing a data protection officer only becomes mandatory once your start-up has 20 or more employees who regularly work with personal data. However, if your start-up processes sensitive data or special categories of personal data, a data protection officer must be appointed from the very beginning. This is the case, for example, when processing health or financial data. Overall, it's highly advisable to appoint a data protection officer as early as possible, ensuring optimal implementation of GDPR requirements right from the start.
This also raises the question of whether an internal or external data protection officer is the better choice — with an external option usually being the more cost-effective one.
3. Using Cold Outreach, Newsletters & More for Growth, Compliantly
During growth, start-ups need to keep in mind that once they reach 20 employees who are regularly in contact with personal data, appointing a data protection officer becomes mandatory.
Cold outreach and similar tactics are especially important and popular in the early stages of growth. For promotional emails sent as a newsletter, you must be able to document the customer's consent to receive the newsletter, and every newsletter must include a notice that recipients can opt out at any time.
If there's no existing email address or similar prior contact — meaning it's genuine cold outreach — emails must never be sent automatically. However, you may contact individual addresses if a "legitimate interest" exists. In that case, it's best practice to include a link to your privacy policy. For first contact via social media, phone, or networking, you must first obtain consent for use (e.g., sending a newsletter) before entering the contact details into your systems and using them. Individual outreach, however, remains permitted.
4. Processing and Sharing Personal Data Securely and Correctly
Processing data covers any use of it — whether collecting, storing, disclosing through transmission, or deleting — unless the data is anonymous.
Data may be processed if one of the following conditions applies (Art. 6 GDPR):
- Consent of the data subject
- Performance of a contract
- Legal obligations (e.g., archiving tax-relevant documents)
- Protection of vital interests
- Legitimate interests
Processing based on legitimate interests and consent are the most important legal bases, and technical and organizational measures can make processing easier, since they reduce data subjects' need for protection by safeguarding the data in other ways.
A growing start-up brings not just more customer data, but also more employee and applicant data. Employees must be given special protection under Section 23 BDSG, which reflects the fact that processing employee data always involves an imbalance of power to the employee's disadvantage. Employees must be adequately protected — including those who leave the company, whose data must be deleted accordingly after departure.
Special categories of personal data are also subject to additional protection, which is why explicit consent from the data subject is required.
When sharing data with third parties, the following points must be considered:
- Have the data subjects consented to the disclosure
- Is the disclosure necessary for the performance of a contract
- Is a Data Processing Agreement in place
- Is the data processed in a third country
5. Building a Data Protection-Compliant Online Presence
Beyond the mandatory privacy policy on the website, a company needs to pay attention to several other aspects of a data protection-compliant online presence. The privacy policy must first disclose the processors used on the website, and more generally across the business. These can be marketing and analytics tools like Google Analytics, but also payment providers like PayPal and many others. It's important to sign a Data Processing Agreement with each of them and create an overview of the various processors (processor directory).
A cookie banner must also be implemented, requiring visitors to actively consent to the use of cookies that aren't technically necessary — meaning consent must never be pre-selected by default.
Furthermore, under Section 5 of the German Telemedia Act, an imprint is also mandatory and must include the full name and address, as well as contact details.







