How to find problematic cookies on a website

Not all cookies and local storage entries may be set without consent – not even if a consent banner is in place. In this article, you will learn how to use browser developer tools to identify problematic cookies, analyse their origin and assess whether they are technically necessary or raise data protection concerns.

Why companies should start checking their website for accessibility today

Very few companies in Europe have paid much attention to the topic of “accessible websites” to date, and we at decareto are no exception. To change this, the European Commission has passed the “European Accessibility Act” (EAA), which aims to make everyday products and services accessible to people with disabilities. This means that accessibility will […]

How to Avoid the 6 Most Common Mistakes When Designing Your Consent Banner

A GDPR-compliant consent banner should enable users to make an informed and freely given choice while meeting the requirements of the GDPR and the German TDDDG. This article highlights the six most common design and implementation mistakes and provides practical guidance on how to avoid legal risks and ensure a compliant user experience.

Shopify and GDPR Compliance

What is Shopify? Shopify is a cloud-based e-commerce platform that allows merchants to create and operate online stores without any programming knowledge. Shopify takes care of hosting and administration. Shopify stores can be easily expanded with accounting, logistics, marketing or legal security functions via an ecosystem of external “apps” that can be integrated into your […]

Cloudflare and GDPR Compliance

What does Cloudflare do? Cloudflare is a US company that provides a content delivery network (CDN) and other services that make websites more scalable and perform better. Cloudflare’s service essentially consists of DNS servers and “reverse proxies”. This ensures that websites are not delivered directly from the company to users, but via Cloudflare’s intermediary servers, […]

Strictly necessary cookies: How do you recognize them?

Not every cookie is considered strictly necessary—its classification depends on its actual purpose rather than its technical characteristics. This article explains how to distinguish between necessary and non-essential cookies, what indicators can help with their assessment, and why careful evaluation is essential for data protection compliance.

Non-deletable cookies on social media

When websites are opened from within social media apps, they often run inside an embedded browser (WebView) rather than your device’s default browser. This article explains how WebViews handle cookies differently, why this can affect users’ control over stored data, and what to consider when managing cookie consent in these environments.

How SMEs can check their websites for security vulnerabilities

Regularly testing websites for security vulnerabilities is an essential part of cybersecurity, especially for small and medium-sized businesses. This article provides an overview of manual and automated penetration testing, explains their advantages and limitations, and outlines how organizations can choose the most appropriate approach for identifying and addressing potential security risks.

Google Analytics Alternatives: 9 GDPR compliant tools

Overview of privacy-compliant tools Companies and private website providers in Germany and other countries can choose between several web tracking services that meet the requirements of the GDPR and European data protection authorities. Below, we present these privacy-friendly tracking providers in more detail. In doing so, we address the background of each provider as well […]