Skip to contentStatus: The next project slots are almost full.
GDPR-Compliant Website – The Ultimate Checklist for Business Owners
Cookie banners, tracking, privacy policy & hosting: Everything your website needs for GDPR compliance – as a practical checklist.Why GDPR Compliance Is Not Optional
The General Data Protection Regulation (GDPR) has applied since May 2018 to every website that processes personal data of EU citizens. Violations can be costly: Up to 20 million euros or 4% of annual turnover – whichever is higher.
But don't panic. This checklist will help you get your website in order.
The Checklist: 12 Points for GDPR Compliance
1. SSL Encryption (HTTPS)
Your website must be accessible via HTTPS. Without an SSL certificate, form data is transmitted unencrypted – a clear GDPR violation.
Every website needs a complete privacy policy describing what data you collect, why, how long you store it, which third parties have access, and users' rights.
Cookies must not be set without prior consent (except technically necessary ones). Your banner must offer a genuine choice with "Reject" as easily accessible as "Accept."
4. Host Google Fonts Locally
Loading Google Fonts via Google CDN transmits visitor IP addresses to US servers. Solution: Host fonts locally on your server.
Inform users about data processing directly at the form, link to your privacy policy, and store only necessary data.
6. Use Analytics in a Privacy-Compliant Way
Privacy-friendly alternatives to Google Analytics include Umami (self-hosted), Plausible (EU), and Matomo (self-hosted). Even these should only load after consent.
7. Legal Notice (Impressum)
Required by German law (§ 5 TMG) for every commercial website. Must be reachable within two clicks from any page.
8. Data Processing Agreements (DPA)
You need a DPA for every third-party provider processing personal data: hosting, email marketing, analytics, cloud storage, CRM systems.
9. Check External Resources
Every external resource transfers the visitor's IP address. Load Google Maps only on click, use YouTube's enhanced privacy mode, and use static social media links.
Ideal: Servers in Germany or the EU. If data is transferred to the US, you need additional safeguards and must disclose this in your privacy policy.
You must be able to delete data when requested. Have a process for contact form data cleanup, easy newsletter unsubscription, and regular backup purging.
12. Record of Processing Activities
Document all data processing activities, especially if you regularly process personal data.
The 5 Most Common GDPR Mistakes
- Loading Google Fonts externally – Led to a wave of legal notices in 2022
- Cookie banners without real choice – "Accept only" is not consent
- Outdated privacy policy – Must match actually deployed tools
- Contact form without notice – Missing data processing information
- Analytics without consent – Tracking before cookie consent is illegal
Premium Advantage: GDPR-Compliant by Design
With a premium solution (Next.js on dedicated infrastructure), many GDPR issues don't exist in the first place: locally hosted fonts, no third-party plugins, servers in Germany, and privacy-first analytics.
Want to set up your website GDPR-compliant – or have an existing site audited? Get in touch – the initial consultation is free.Ready for the Starting Gun?
DevelopWebsites that inspire your visitors
Request Project
Your Website. Your System.
© 2026 Formatgeber // All rights reserved