How to make your website GDPR-compliant

😎 Price promotion
10% discount on all Trackboxx annual subscriptions with the code: tb10action
Table of contents

The General Data Protection Regulation (GDPR) sets strict standards for protecting personal data online. What does that mean for your website? This article walks you through the key steps to address GDPR requirements and reduce legal risks.

Who does the GDPR apply to — and are there exceptions?

The GDPR applies when you process personal data* as part of the activities of an establishment in the EU. It can also cover providers outside the EU that offer goods or services to people in the EU or monitor their behaviour there. Citizenship is not the deciding factor. The exemption for purely personal or household activities is narrow: a publicly accessible website is not exempt simply because it makes no money.

*Personal data means any information relating to an identified or identifiable person. That includes obvious details such as a name, address or email address, but also information such as IP addresses, location data and website activity. What matters is whether the information can identify someone, directly or indirectly.

1. Make your privacy policy easy to find

If your website processes personal data, it needs a privacy policy. Make it easy to find — for example, with a link in the footer — and include the required information. Key questions to answer include:

  • What data is collected?
  • Why do you process the data?
  • What legal basis do you rely on?
  • How long will the data be stored?
  • What rights do visitors have over their data?
  • Who is the data controller?

A privacy policy generator can give you a starting point. Check that the result accurately covers how your website actually handles data. Using a generator does not, on its own, ensure legal compliance.

2. Get cookie consent right

In Germany, Section 25 of the TDDDG generally requires consent to store information on a user’s device or access information already stored there. Exceptions include operations that are strictly necessary to provide a service the user has explicitly requested. The rule is not limited to cookies. If personal data is subsequently processed, you also need an appropriate legal basis under the GDPR. For cookies and similar technologies that require consent:

  • Active opt-in: Only set cookies that require consent after the user has actively opted in.
  • A genuine choice: Give users a genuine, voluntary choice, including the option to reject cookies that require consent.
  • Clear information: Which cookies do you use, and what are they for?
  • Easy withdrawal: Users must be able to withdraw consent at any time, as easily as they gave it.

Cookie consent tools such as Borlabs Cookie or Cookiebot can help. For more detail, read our guide to designing GDPR-compliant consent banners.

Web analytics without cookies

Even if you do not set cookies , other tracking technologies may still require consent . The GDPR protects personal data, regardless of the technology used to collect it.

Web analytics with Trackboxx: Our tracking tool helps you understand how visitors use your website. Whether consent is required depends on your specific setup and the features you use. Assess your website’s privacy requirements rather than assuming that not using cookies removes the need for consent.

3. HTTPS and TLS: protect data in transit

Use HTTPS with up-to-date TLS encryption to protect data as it travels between the browser and your web server. This is particularly important for personal data (for example, through contact forms). Encryption protects data in transit, but it does not make your website GDPR-compliant on its own.

4. Handle contact form data properly

If your website has contact forms, keep the following in mind:

  • data minimisation: Only ask for the information you actually need.
  • Purpose limitation: Tell visitors why you collect the information in the form.
  • Choose the right legal basis: Depending on the enquiry, processing may be necessary to fulfil a contract, take steps before entering into one, or pursue a legitimate interest. A consent checkbox is not automatically required. Explain how you handle the data alongside the form and link to your privacy policy.
  • Retention periods: Do not keep the data indefinitely.

5. Check your third-party integrations

Many websites use third-party services such as Google Analytics, the Facebook Pixel or embedded YouTube videos. For each service, check where data goes, the legal basis for processing it and any transfers to third countries. No short checklist or single tool can guarantee GDPR compliance:

  • Google Analytics: Review your configuration, the necessary agreements and any data transfers. Tracking that requires consent must not start until the user has validly opted in; shortening an IP address is not enough.
  • YouTube, Google Fonts, social media plugins: Check how each service is integrated. Services that require consent must not load before the user agrees. Locally hosted fonts, for example, do not trigger a request to an external font provider.
  • Consider alternatives: Consider locally hosted fonts or analytics tools configured differently. With alternatives such as Matomo, compliance still depends on how you use them.

6. Put a data processing agreement in place

If an external service provider processes personal data on your behalf, you will generally need a data processing agreement (DPA). This sets out how the provider must handle the personal data. Many providers, including Mailchimp and Google, make these agreements available online. So do we.

7. Keep a record of processing activities

Businesses and self-employed website operators generally need to keep a record of processing activities . The exemption for organisations with fewer than 250 employees is narrow and does not, for example, cover the regular processing of customer or employee data. The record sets out information such as processing purposes, data categories, recipients, retention periods and safeguards.

The bottom line: privacy compliance takes ongoing work

The GDPR sets clear responsibilities for website operators. Transparent privacy information, appropriate legal bases, secure data transmission and carefully chosen third-party services are all important. You need a consent banner where consent is actually required. These measures help reduce privacy risks, but they are no substitute for reviewing your website’s specific setup.

Review your website regularly for changes to services, data flows and privacy requirements. This article provides general guidance, not a legal assessment of your individual circumstances.

The GDPR at a glance

The EU adopted the GDPR in 2016, and it has applied since 25 May 2018. It strengthens the protection of personal data and establishes a common framework across the EU. Its scope goes well beyond websites: it also covers businesses, public authorities, associations and healthcare organisations. For the legislation and up-to-date guidance, visit the European Commission website or a national data protection authority such as Germany’s Federal Commissioner for Data Protection and Freedom of Information (BfDI).

Expert in web development & online marketing with over 15 years of experience.
Developer & CEO of Trackboxx – the Google Analytics alternative.

This might also interest you.

😎 Price promotion

10% off all annual subscriptions of Trackboxx with the code: