General | Reports

Pharmaceutical Companies’ Websites in the 2026 Data Protection Check: 88% with Data Protection Issues

Eckhard Schneider
Published by Decareto
·
4 min read
·
August 5, 2026
Pharmaceutical Companies’ Websites in the 2026 Data Protection Check: 88% with Data Protection Issues
Table of Contents

decareto has automatically assessed the German websites of 25 pharmaceutical companies for compliance with the GDPR and the TDDDG. The result: all companies use consent banners — yet most still have data protection issues with cookie configuration, external services and privacy policies. The analysis suggests that many pharmaceutical companies are not fully implementing key requirements of the GDPR and the TDDDG.

Pharmaceutical companies are subject to comprehensive regulatory requirements. In addition to sector-specific regulations for medicinal products, data protection, information security, digital accessibility and the legally compliant operation of websites are also becoming increasingly important. Compliance requirements therefore affect not only production and research but also the company’s entire digital presence.
This makes the results of a recent analysis by decareto all the more surprising: despite high compliance requirements, numerous pharmaceutical companies’ websites exhibit significant shortcomings in the implementation of data protection regulations. Many of the websites examined fail to adequately meet key requirements of the General Data Protection Regulation (GDPR) and the German Telecommunications-Digital Services Data Protection Act (TDDDG).

25 pharmaceutical companies examined

For the study, decareto analysed the German websites of 25 pharmaceutical companies with regard to their technical data protection configuration. The focus was on compliance with the consent requirements under Section 25 of the TDDDG – in particular:

  • the use of consent banners and consent management platforms
  • the loading of external services
  • the setting of cookies
  • the completeness of privacy policies

The results show that data protection shortcomings are widespread despite the presence of consent banners and comprehensive privacy policies.

88% of consent banners are incorrectly configured

A consent banner, also known as a cookie banner, serves to obtain and manage consent for data processing operations on websites that require consent, and is intended to ensure that such processing only takes place after the user has given valid consent.
All the pharmaceutical companies examined use a consent banner or consent management software. However, the technical implementation of the consent banner often fails to meet legal requirements.
On 22 out of 25 websites (88 per cent), services or cookies requiring consent were already activated upon the first page view – even before visitors had given their consent. As a result, the consent banner loses its intended protective function.

88 per cent set non-essential cookies without consent

Cookies are one of several technologies used to store or retrieve information on end devices. According to the TDDDG, only cookies that are strictly necessary for the basic functionality of the site (e.g. a shopping basket) are permitted.
The analysis revealed that 22 of the 25 pharmaceutical companies (88 per cent) set non-essential cookies even before users had given their consent.
According to the case law of the European Court of Justice and the Federal Court of Justice, such cookies may, in principle, only be set after valid consent has been given.
Particularly concerning: the majority of the websites in question give the impression, via a cookie banner, that they are waiting for the user’s decision, yet are already processing personal data beforehand.

84% load external services requiring consent before consent is given

External third-party services are integrated without consent slightly less frequently than cookies, as not all services requiring consent also set cookies.
21 out of 25 pharmaceutical companies (84%) loaded at least one external service requiring consent as soon as the page was loaded.
These are predominantly services from the following areas:

  • Web analytics
  • Marketing
  • Advertising
  • Content delivery
  • Tag managementDelivery

These technologies regularly transfer personal data to third parties and therefore often require prior consent.

Lack of transparency in privacy policies on 80% of pharmaceutical companies’ websites

In addition to the technical analysis, decareto also examined the pharmaceutical companies’ privacy policies.
The result: 20 out of 25 websites (80 %) contained references to the use of external services that were not mentioned, or not clearly mentioned, in the respective privacy policy.
This may constitute a breach of the information obligations under Article 13 of the GDPR, which requires data controllers to transparently specify the recipients or categories of recipients of personal data.

Used without consent: Google services dominate technology

The investigation reveals a clear concentration on a small number of major technology providers.
Among the most frequently identified providers of third-party services used without consent are:

Rank / Provider / Categories
1 / Google / Web analytics, marketing, advertising, tag management
2 / Adobe / Advertising, tag management
3 / Cloudflare / Content delivery
4 / Akamai Technologies / Content delivery
5 / Matomo / Web analytics
6 / Siteimprove / Website optimisation & analytics
7 / New Relic / Performance monitoring
8 / Crazy Egg / Behavioural analysis
9 / Hotjar / Behavioural analysis
10 / Kloudend / Consent management
11 / Meta / Marketing & advertising
12 / Reddit / Marketing
13 / LinkedIn / Marketing
14 / Vimeo / External media
15 / Kaltura / External media

What is striking is Google’s strong dominance. 19 out of 25 pharmaceutical companies examined (76 per cent) load Google services even before consent is given. The services identified include, amongst others:

  • Google Tag Manager
  • Google Analytics
  • Google Ads
  • Google AdSense
  • Google Fonts
  • Google Maps
  • Google reCAPTCHA
  • Google Cloud Platform
  • YouTube

In addition, marketing and web analytics technologies from Adobe, Cloudflare and Akamai Technologies are regularly used.

Data transfers to the US remain a relevant issue

Even following the introduction of the EU-US Data Privacy Framework in July 2023, data transfers to the US remain a sensitive issue under data protection law.
Although the European Commission’s adequacy decision permits data transfers to certified US companies, the use of many tracking, marketing and analytics services continues to require prior consent in accordance with Section 25 of the TDDDG and, as a rule, Article 6(1)(a) of the GDPR.
Regardless of the permissibility of international data transfers, the correct technical implementation of consent solutions therefore remains crucial.

Overall assessment of the pharmaceutical companies’ websites

The overall assessment of the websites examined is correspondingly critical.

  • Two of the pharmaceutical companies’ websites achieved the top grade of A.
  • B: 3, C: 3, D: 7, E: 10

This means that most of the pharmaceutical company websites examined exhibit technical or organisational data protection shortcomings.

Key findings of the analysis

  • 88% set non-essential cookies without consent.
  • 84% load external third-party services before consent is given.
  • 80% do not fully disclose identified external services in their privacy policy.
  • 88% of consent banners do not fully fulfil their protective function.

Google is the most frequently identified third-party service loaded without consent on 19 out of 25 pharmaceutical company websites.

About the analysis

For the analysis, decareto examined the websites of 25 pharmaceutical companies in Germany in July 2026. The decareto platform for website compliance analysis was used for this purpose.
The assessment covered the technical implementation of consent mechanisms, the use of external services, the setting of cookies, and the transparency of privacy policies. The assessment was based on the requirements of the GDPR and the TDDDG, as well as current European and German case law on the use of technologies requiring consent.

The following pharmaceutical companies were examined

Abbott, ALTANA, Amgen, AstraZeneca, Bayer, Berlin-Chemie, BioNTech, Eli Lilly, Fresenius Kabi, GSK, Grünenthal, Hexal, Roche, Janssen-Cilag, Merck, MSD, Mundipharma, Novartis, Novo Nordisk, Pfizer, ratiopharm, Sanofi, STADA, Takeda, UCB

Social Share:

Explore more related blogs

4 min read
·
June 16, 2026
An overview of five reliable solutions for testing WCAG criteria, digital accessibility, and website barriers. ...
4 min read
·
June 8, 2026
This blogpost shows how a privacy policy generator supports the creation, maintenance and updating of ...
4 min read
·
May 27, 2026
Create, review and update dynamic privacy policies based on website scans – using templates and ...