General | Tutorials and know-how

Website Check 2026: GDPR Checklist for Websites

Eckhard Schneider
Published by Decareto
·
4 min read
·
August 18, 2026
DSGVO / GDPR website checklist
Table of Contents

If you run or are setting up a website for a business, you must comply with various legal requirements. Of particular importance is the General Data Protection Regulation (GDPR), which has been in force since 2018 and governs the handling of personal data on websites.
To help you understand which points are relevant for a GDPR-compliant website, we have put together a practical checklist for you. With this website check, you can check step by step whether your website complies with data protection regulations and where adjustments may still be needed.
Our GDPR checklist for websites helps you systematically review relevant data protection requirements. This allows you to quickly identify which areas have already been properly implemented and where there may still be a need for action.

1. Privacy policy and legal notice in accordance with the GDPR

Under the GDPR, website owners are obliged to include a privacy policy and a legal notice on their website. Both documents must be clearly visible and easy to find. One way to position the privacy policy and the legal notice is to place them side by side in the website’s footer.

Ensure that both the privacy policy and the legal notice are also accessible on the mobile version of the website.

Privacy Policy

The privacy policy contains, on the one hand, the name and contact details of the data controllers and, on the other hand, information about the processing of website visitors’ personal data. The privacy policy sets out what data is collected, how it is collected, what it is used for and how long it is stored.

Furthermore, in accordance with the GDPR, the privacy policy sets out users’ rights and provides details on hosting and the use of cookies. You must also provide information on the analytics tools used, sharing on social media, the plug-ins used and any newsletter service you may offer.

Legal Notice

If you offer services or products on your website, it is necessary to include a GDPR-compliant legal notice on your website alongside the privacy policy. Here, you must provide all the details (first name, surname, street, postcode, town/city, telephone number, email) of the website operator. The VAT registration number and the company’s authorised representative must also be included in the legal notice.

2. Cookie Banner

When using a cookie banner, there are several ways to inform users about the use of cookies on the website. Which banner you use depends on the types of cookies you employ on your website.

Some cookies are essential. These include, for example, those that are technically necessary or required for obtaining consent to the processing of personal data via the contact form or newsletter. Without these, you are not permitted to collect this data.

Other cookies, which relate to tracking or the analysis of user behaviour, are used exclusively for website analysis. Obtaining consent for this is absolutely essential. Examples of tracking tools include Google Analytics or Google Tag Manager.

Regardless of which cookies you use, you must inform visitors of this and also list them in your privacy policy in accordance with the GDPR.

3. Data collected via the contact form

As soon as you provide a contact form on your website that allows visitors to get in touch with you, it is important to obtain the user’s consent to the processing of their data.

When it comes to contact forms, data minimisation is key. Mandatory fields should be limited to those whose information you actually need – for a simple enquiry via email, you do not need the user’s telephone number or their first AND last name. You must disclose the data collected via the contact form in your privacy policy.

4. Newsletter

Just as with the contact form, when users sign up for the newsletter you must also obtain their confirmation that you may process their data and that they wish to receive the newsletter regularly. You should also ensure that the newsletter software you use is GDPR-compliant.

You must also provide users with further information in the privacy policy regarding the personal data collected via the newsletter.

5. Third-party plug-ins

Social plug-ins

Any social media button, such as the ‘Like’ thumb icon on LinkedIn and Facebook, the ‘Post’ icon on X, or similar methods enabling visitors to share website content on social networks, is referred to as a third-party plug-in or social plug-in.

However, the use of these plug-ins requires a cookie through which the user must consent to data being stored and passed on to the respective social networks in accordance with the GDPR.

Videos

Embedding and subsequently playing videos from, for example, YouTube on websites also requires the user’s consent via a cookie. The user thereby agrees to their data being passed on to YouTube or the relevant platform.

6. Encrypted website

As you are obliged to protect all data collected from visitors, it is essential to encrypt websites using an SSL certificate. This ensures that unauthorised persons cannot access personal data.

You can recognise an encrypted or secure website by the padlock icon before the URL or the prefix https://. This ensures that data collected via the contact form, for example, is sent securely and in encrypted form.

Tip: An SSL-encrypted website is one of Google’s ranking factors. A secure website therefore leads to a higher ranking on Google.

7. Prohibition on coupled data collection

The principle of data minimisation in contact forms goes hand in hand with the prohibition on coupled data collection. On the one hand, a contact form must not collect too much data; on the other hand, however, the user must not be automatically added to the newsletter mailing list, in accordance with the GDPR.

Whether this is when purchasing a product or contacting the website operator: users who provide their personal data must give their explicit consent to receiving the newsletter on a regular basis. This can be done simply by ticking a box. If you do not have this consent, you must not add the user to the newsletter mailing list.

8. Google Analytics

Using Google Analytics or similar web analytics tools, you can track a visitor’s online behaviour via their IP address. However, under the GDPR, you may not do this without the user’s consent.

Accordingly, you must enable visitors to consent to or refuse this data collection by means of a cookie. This must be stated in the privacy policy.

It is also necessary to anonymise users’ IP addresses. To do this, simply add ‘anonymizeIP’ to the Google Analytics code and embed it in the website’s source code.

Finally, you must enter into a GDPR-compliant data processing agreement with Google (Analytics) to authorise Google Analytics to collect your visitors’ data.

9. Data Processing Agreement

A so-called Data Processing Agreement under the GDPR must always be concluded whenever personal data collected by a website is passed on to third parties or external service providers for processing. For example, when using Google tools (e.g. Analytics), newsletter tools or cloud providers, you must conclude such an agreement with them for data processing.

10. Stock photos

If you wish to use photos on websites, they must comply with the GDPR. To avoid copyright issues, you should consider using stock photos where necessary. If companies do not have their own videos or photos, they tend to use so-called stock photo agencies.

Generally speaking, there is nothing to prevent the use of stock photos on websites; however, it is essential to pay close attention to the licence terms and conditions of the respective agencies and, where necessary, to provide credit for the images.

What happens if the website is not GDPR-compliant?

If the website is not GDPR-compliant, fines may be imposed. This includes, amongst other things, insufficient information on data collection, an incomplete or missing privacy policy and legal notice, copyright infringements or a lack of website encryption.

Other GDPR breaches could also include failing to provide notice of cookie usage and the use of analytics tools such as Google Analytics, as well as failing to mention these in the privacy policy. If such GDPR breaches occur, this may result in fines or a formal warning.

Our article GDPR Check: How to check your website for GDPR compliance shows you step by step how to review your website for compliance with data protection laws.

Do you have any questions about the GDPR checklist for websites?

We very much hope that the GDPR checklist for websites has been helpful to you and that you have found useful information in it. By following this checklist, you can avoid fines and formal warnings for your website.

Please pay particular attention to ensuring your privacy policy is complete, as it must set out everything important regarding data protection on your website.

If you still have any questions or would like further information on this topic, please feel free to arrange a no-obligation consultation.

Social Share:

Explore more related blogs

4 min read
·
August 10, 2026
Keyboard accessibility is one of the most important fundamentals of digital accessibility and determines whether ...
4 min read
·
August 5, 2026
decareto hat die deutschen Websites von 25 Pharmaunternehmen automatisiert auf DSGVO- und TDDDG-Konformität untersucht. Das ...
4 min read
·
July 27, 2026
Credit institutions and banks are subject to comprehensive compliance and regulatory requirements. In addition to ...