Person reviewing a checklist on a laptop by a window

Checking your company website against the GDPR

The GDPR touches an ordinary company website at three points where data gets collected, the contact form, analytics and embedded services such as maps or videos, and all three can be checked yourself in about half an hour.

The privacy policy, a dedicated page describing how data is handled, is required on almost every website and has to match what the site actually does rather than a template downloaded a year ago. More often than the use of analytics or forms themselves, it is the gap between that text and the scripts actually loading that turns into a problem.

The contact form usually processes data under Article 6(1) of the GDPR, typically as necessary to answer the enquiry, and that legal basis needs no separate consent checkbox as long as the form only asks for what answering the enquiry actually requires.

An analytics tool such as Google Analytics needs the visitor's consent before the script counts anything at all, and that consent is separate from whatever the contact form relies on. Germany's data protection authorities set this out in a joint guidance for website operators from December 2021, and analytics running before consent remains one of the most common violations on ordinary sites since.

Maps, video players and fonts loaded directly from a third party server transmit the visitor's IP address the same way external fonts do, and need either consent or a move to local hosting before the element loads at all.

If hosting, analytics or newsletter tools sit outside the European Union, transferring data to them needs extra safeguards, usually EU standard contractual clauses, and without them using such a service for website data becomes legally questionable.

Every provider that technically processes the site's data, hosting, newsletter sending, a CRM, needs a data processing agreement, covered in its own article on the topic, and without that agreement the company is formally liable for the provider's actions as if they were its own.

The half hour self check runs like this. Submit the contact form and check where the message goes and what happens to the data afterward. Open the page with a script blocker on and see which domains try to load before anyone clicks consent. Compare that list with what the privacy policy actually says.

This text explains what to look for in a self check and does not replace legal advice. A full assessment of a website needs a look at the actual scripts, forms and provider contracts, and a specialist should make that call in unclear cases.

Share
Portrait of Illia Belichenko, technical specialist at Illia BizTech
Illia Belichenko

Illia is responsible for the technical side of Illia BizTech: website development, website updates, forms, integrations, automation and technical support. He works on connecting websites, content, advertising and internal workflows so they work together without creating unnecessary manual work.

A GDPR checklist for a website is easiest to work through during development rather than hunting for problems on a site that is already live. Illia BizTech goes through the contact form, the cookie banner, externally loaded fonts and the site's own providers before launch, which is exactly why the checklist in this article does not turn into a separate expensive project once the site is already running.

Illia BizTech builds and maintains websites for small and medium businesses in Russian, German and English, from the first version through ongoing maintenance and SEO work. A team carries the project from idea to launch without long internal approval chains, so the client speaks directly with the people writing the code and managing the content, not through a chain of account managers. That fits businesses moving to Germany or expanding into the German-speaking market who want to explain their task once, not repeat it on every call.