Pharmaceutical Companies’ Websites in the 2026 Data Protection Check: 88% with Data Protection Issues

decareto hat die deutschen Websites von 25 Pharmaunternehmen automatisiert auf DSGVO- und TDDDG-Konformität untersucht. Das Ergebnis: Alle Unternehmen setzen Consent-Banner ein — dennoch weisen die meisten Datenschutzmängel bei Cookie-Konfiguration, externen Diensten und Datenschutzerklärungen auf. Die Analyse deutet darauf hin, dass viele Pharmaunternehmen zentrale Anforderungen der DSGVO und des TDDDG nicht vollständig umsetzen.
Privacy policy generator for up-to-date privacy policies in 24 languages

This blogpost shows how a privacy policy generator supports the creation, maintenance and updating of privacy policies using automated website scans and a structured workflow.
Privacy policy generator: create a dynamic privacy policy in 5 steps

Create, review and update dynamic privacy policies based on website scans – using templates and an approval process.
How to check the transport encryption of a website

Secure transport encryption (TLS) protects data transmission between the browser and the web server and is a fundamental requirement for data protection and IT security. In this article, you will learn how to check your website’s transport encryption using free tools, identify typical vulnerabilities and address potential security risks at an early stage.
How to find problematic cookies on a website

Not all cookies and local storage entries may be set without consent – not even if a consent banner is in place. In this article, you will learn how to use browser developer tools to identify problematic cookies, analyse their origin and assess whether they are technically necessary or raise data protection concerns.
How to Avoid the 6 Most Common Mistakes When Designing Your Consent Banner

A GDPR-compliant consent banner should enable users to make an informed and freely given choice while meeting the requirements of the GDPR and the German TDDDG. This article highlights the six most common design and implementation mistakes and provides practical guidance on how to avoid legal risks and ensure a compliant user experience.
Strictly necessary cookies: How do you recognize them?

Not every cookie is considered strictly necessary—its classification depends on its actual purpose rather than its technical characteristics. This article explains how to distinguish between necessary and non-essential cookies, what indicators can help with their assessment, and why careful evaluation is essential for data protection compliance.
Non-deletable cookies on social media

When websites are opened from within social media apps, they often run inside an embedded browser (WebView) rather than your device’s default browser. This article explains how WebViews handle cookies differently, why this can affect users’ control over stored data, and what to consider when managing cookie consent in these environments.
How SMEs can check their websites for security vulnerabilities

Regularly testing websites for security vulnerabilities is an essential part of cybersecurity, especially for small and medium-sized businesses. This article provides an overview of manual and automated penetration testing, explains their advantages and limitations, and outlines how organizations can choose the most appropriate approach for identifying and addressing potential security risks.
