Status: The next project slots are almost full.
Back to Blog
May 31, 2026

GDPR-Compliant Website – The Ultimate Checklist for Business Owners

Cookie banners, tracking, privacy policy & hosting: Everything your website needs for GDPR compliance – as a practical checklist.
GDPR-Compliant Website – The Ultimate Checklist for Business Owners
The General Data Protection Regulation (GDPR) has applied since May 2018 to every website that processes personal data of EU citizens. Violations can be costly: Up to 20 million euros or 4% of annual turnover – whichever is higher. But don't panic. This checklist will help you get your website in order. Your website must be accessible via HTTPS. Without an SSL certificate, form data is transmitted unencrypted – a clear GDPR violation. Every website needs a complete privacy policy describing what data you collect, why, how long you store it, which third parties have access, and users' rights. Cookies must not be set without prior consent (except technically necessary ones). Your banner must offer a genuine choice with "Reject" as easily accessible as "Accept." Loading Google Fonts via Google CDN transmits visitor IP addresses to US servers. Solution: Host fonts locally on your server. Inform users about data processing directly at the form, link to your privacy policy, and store only necessary data. Privacy-friendly alternatives to Google Analytics include Umami (self-hosted), Plausible (EU), and Matomo (self-hosted). Even these should only load after consent. Required by German law (§ 5 TMG) for every commercial website. Must be reachable within two clicks from any page. You need a DPA for every third-party provider processing personal data: hosting, email marketing, analytics, cloud storage, CRM systems. Every external resource transfers the visitor's IP address. Load Google Maps only on click, use YouTube's enhanced privacy mode, and use static social media links. Ideal: Servers in Germany or the EU. If data is transferred to the US, you need additional safeguards and must disclose this in your privacy policy. You must be able to delete data when requested. Have a process for contact form data cleanup, easy newsletter unsubscription, and regular backup purging. Document all data processing activities, especially if you regularly process personal data.
  • Loading Google Fonts externally – Led to a wave of legal notices in 2022
  • Cookie banners without real choice – "Accept only" is not consent
  • Outdated privacy policy – Must match actually deployed tools
  • Contact form without notice – Missing data processing information
  • Analytics without consent – Tracking before cookie consent is illegal
With a premium solution (Next.js on dedicated infrastructure), many GDPR issues don't exist in the first place: locally hosted fonts, no third-party plugins, servers in Germany, and privacy-first analytics.
Trademark
Trademark
Want to set up your website GDPR-compliant – or have an existing site audited? Get in touch – the initial consultation is free.

Ready for the Starting Gun?

DevelopWebsites that inspire your visitors
Request Project
© 2026 Formatgeber // All rights reserved