The General Data Protection Regulation (GDPR) sets strict standards for protecting personal data online. What does that mean for your website? This article walks you through the key steps to address GDPR requirements and reduce legal risks.
1. Make your privacy policy easy to find
If your website processes personal data, it needs a privacy policy. Make it easy to find — for example, with a link in the footer — and include the required information. Key questions to answer include:
- What data is collected?
- Why do you process the data?
- What legal basis do you rely on?
- How long will the data be stored?
- What rights do visitors have over their data?
- Who is the data controller?
A privacy policy generator can give you a starting point. Check that the result accurately covers how your website actually handles data. Using a generator does not, on its own, ensure legal compliance.
2. Get cookie consent right
In Germany, Section 25 of the TDDDG generally requires consent to store information on a user’s device or access information already stored there. Exceptions include operations that are strictly necessary to provide a service the user has explicitly requested. The rule is not limited to cookies. If personal data is subsequently processed, you also need an appropriate legal basis under the GDPR. For cookies and similar technologies that require consent:
- Active opt-in: Only set cookies that require consent after the user has actively opted in.
- A genuine choice: Give users a genuine, voluntary choice, including the option to reject cookies that require consent.
- Clear information: Which cookies do you use, and what are they for?
- Easy withdrawal: Users must be able to withdraw consent at any time, as easily as they gave it.
Cookie consent tools such as Borlabs Cookie or Cookiebot can help. For more detail, read our guide to designing GDPR-compliant consent banners.
Web analytics without cookies
Even if you do not set cookies , other tracking technologies may still require consent . The GDPR protects personal data, regardless of the technology used to collect it.
Web analytics with Trackboxx: Our tracking tool helps you understand how visitors use your website. Whether consent is required depends on your specific setup and the features you use. Assess your website’s privacy requirements rather than assuming that not using cookies removes the need for consent.
3. HTTPS and TLS: protect data in transit
Use HTTPS with up-to-date TLS encryption to protect data as it travels between the browser and your web server. This is particularly important for personal data (for example, through contact forms). Encryption protects data in transit, but it does not make your website GDPR-compliant on its own.
4. Handle contact form data properly
If your website has contact forms, keep the following in mind:
- data minimisation: Only ask for the information you actually need.
- Purpose limitation: Tell visitors why you collect the information in the form.
- Choose the right legal basis: Depending on the enquiry, processing may be necessary to fulfil a contract, take steps before entering into one, or pursue a legitimate interest. A consent checkbox is not automatically required. Explain how you handle the data alongside the form and link to your privacy policy.
- Retention periods: Do not keep the data indefinitely.
5. Check your third-party integrations
Many websites use third-party services such as Google Analytics, the Facebook Pixel or embedded YouTube videos. For each service, check where data goes, the legal basis for processing it and any transfers to third countries. No short checklist or single tool can guarantee GDPR compliance:
- Google Analytics: Review your configuration, the necessary agreements and any data transfers. Tracking that requires consent must not start until the user has validly opted in; shortening an IP address is not enough.
- YouTube, Google Fonts, social media plugins: Check how each service is integrated. Services that require consent must not load before the user agrees. Locally hosted fonts, for example, do not trigger a request to an external font provider.
- Consider alternatives: Consider locally hosted fonts or analytics tools configured differently. With alternatives such as Matomo, compliance still depends on how you use them.
6. Put a data processing agreement in place
If an external service provider processes personal data on your behalf, you will generally need a data processing agreement (DPA). This sets out how the provider must handle the personal data. Many providers, including Mailchimp and Google, make these agreements available online. So do we.
7. Keep a record of processing activities
Businesses and self-employed website operators generally need to keep a record of processing activities . The exemption for organisations with fewer than 250 employees is narrow and does not, for example, cover the regular processing of customer or employee data. The record sets out information such as processing purposes, data categories, recipients, retention periods and safeguards.
The bottom line: privacy compliance takes ongoing work
The GDPR sets clear responsibilities for website operators. Transparent privacy information, appropriate legal bases, secure data transmission and carefully chosen third-party services are all important. You need a consent banner where consent is actually required. These measures help reduce privacy risks, but they are no substitute for reviewing your website’s specific setup.
Review your website regularly for changes to services, data flows and privacy requirements. This article provides general guidance, not a legal assessment of your individual circumstances.



