Skip to content
dachdev

A Practical GDPR Checklist for Your Business Website

Six concrete steps every business website should take to meet GDPR requirements: consent, embeds, legal notices, hosting, and data minimisation.

By dachdev Redaktion3 min read

The General Data Protection Regulation (GDPR) has been in force since 2018 and applies to every website that processes personal data of people in the EU. It does not matter where the business itself is based: if you serve visitors in the EU, the GDPR applies to you. Yet many websites still fall short of the basics. This checklist covers what actually matters.

1. Consent Banner Before Any Tracking Script Runs

No analytics script, advertising pixel, or social media plugin should load before a visitor has given explicit consent. The technical approach is called a consent management platform: scripts are activated only after consent is recorded, not on page load.

A banner that merely informs but does not block anything is not enough. Simply visiting a page does not count as consent under the GDPR.

2. Two-Click Solution for Embedded Third-Party Content

Maps, YouTube videos, and similar external content present a specific problem: loading an embedded object transmits data to the third-party provider (such as the visitor's IP address) before the visitor has agreed to anything.

The clean solution is a placeholder that loads the actual content only after an active click. The visitor first sees an image or a brief notice explaining that clicking will send data to a third party. The external content is embedded only after that click.

3. Complete Imprint and a Readable Privacy Policy

Your legal notice (Impressum) must be complete and easy to find: name, address, contact details, and any required registration numbers. An imprint buried behind multiple clicks, or one that contains outdated information, is an unnecessary liability.

The privacy policy should explain in plain language what data you collect, for what purpose, and on what legal basis. Template generators can be a starting point but must be adapted to your actual setup. Generic templates that list services you do not use are a problem, not a solution.

4. EU Hosting Where Possible

When data is stored or processed on servers outside the European Economic Area, special transfer rules apply. US providers often operate under the EU-US Data Privacy Framework, which permits certain transfers, but the stability of that framework should not be taken for granted.

The simpler approach: choose a hosting provider with data centres in Germany or the EU. That significantly reduces the legal overhead.

5. Data Minimisation on Forms

Contact forms are a common weak point. Someone sending a quick enquiry does not need to provide a date of birth, a phone number, or a company address if those details are not necessary for handling the request.

The GDPR's data minimisation principle (Article 5) requires that you collect only what you genuinely need. Mandatory fields should be kept to a minimum. Any optional fields must be clearly marked as such.

6. Be Transparent About What Happens to the Data

When someone fills in a contact form, a short notice should appear right there explaining what happens next. Is the data stored in a CRM? How long is it kept? Are there processors with access to it?

This does not need to be a lengthy paragraph. A brief note with a link to the full privacy policy is sufficient, and far better than nothing.

A Realistic View

No business will be fully GDPR-compliant overnight, and no supervisory authority expects that. What matters is a clearly genuine approach to the subject: no obvious violations, up-to-date legal texts, and the technical basics in order.

A solid foundation can be built into a new website from the start. For existing websites, a structured review is worthwhile at least once a year.


This article is general information and not legal advice. Whether your website meets GDPR requirements, and what steps are needed in your specific situation, is something to discuss with a lawyer specialising in data protection and, where relevant, a data protection officer.

Ready?

Want us to deliver this for you?

Turn knowledge into results: tell us what you have in mind, we get back to you with an honest assessment.