WordPress Training
Allgemein

GDPR Compliance Checklist for German Websites: The Quick Guide to a Legally Sound Setup

Table of contents

GDPR compliance checklist for German websites

โœ… Measure Priority Legal basis Implementation note
Create a privacy policy ๐Ÿ”ด High Art. 13, 14 GDPR List the controller, purposes, retention periods, recipients and data-subject rights in full
Cookie banner with opt-in ๐Ÿ”ด High Art. 6(1)(a) GDPR, ePrivacy Granular consent for marketing cookies, essential always active, block third-party
Record of processing activities (RoPA) ๐Ÿ”ด High Art. 30 GDPR Document all processing: contact forms, logs, newsletters, analytics
Add a legal notice (Impressum) ๐Ÿ”ด High ยง 5 TMG, Art. 13 GDPR Controller with contact details, appoint a data protection officer where required
Enable SSL encryption ๐Ÿ”ด High Art. 32 GDPR (TOMs) HTTPS for the entire website, keep the certificate up to date
Data processing agreements (DPAs) ๐ŸŸ  Medium Art. 28 GDPR Conclude with hosting, newsletter tool and analytics providers
Consent management platform (CMP) ๐ŸŸ  Medium Art. 7 GDPR Log consents, make them revocable, store for 14 months
Implement data-subject rights ๐ŸŸ  Medium Art. 15-22 GDPR Establish processes for access, erasure, rectification and objection
Implement an erasure concept ๐ŸŸ  Medium Art. 17 GDPR Set automatic retention periods for logs, forms and newsletter data
Data protection impact assessment (DPIA) ๐ŸŸก Low Art. 35 GDPR Only for high-risk processing (e.g. extensive profiling, sensitive data)
Train staff ๐ŸŸก Low Art. 32 GDPR Annual training on data protection, strong passwords and phishing protection
Secure a backup strategy ๐ŸŸก Low Art. 32 GDPR (availability) Encrypted backups, run a quarterly restore test

Fines of up to 4% of annual turnover. Data protection authorities such as the BayLDA are scrutinising more actively than ever. In my training sessions I regularly see that website operators are unsure: what exactly do I need to do? This checklist gives you the answer. Step by step. Without an expensive consultant.

Anyone who sees data protection not just as an obligation but uses it as a trust signal gains an advantage. Customers prefer to buy from providers they trust. A clean data protection setup pays off.

Key takeaways

  • Privacy policy first: It informs users about how their data is processed. Without one, you risk warning letters. A complete policy dramatically reduces the risk of cease-and-desist claims and builds trust.
  • Cookie banner with opt-in: Tracking cookies may only load after consent. Without a correct banner you risk fines. Google has paid 100 million euros. You don't want to be next.
  • Record of processing activities (RoPA): Documents all processes. Protects you during audits. Saves consultancy costs because you keep the overview.
  • Train your team: The most common data protection breaches happen internally. Regular short training sessions noticeably reduce error rates.
  • Data protection impact assessment (DPIA): Only needed for high-risk processing, e.g. profiling. An early risk assessment avoids costly rework.

Why this approach works

This checklist relies on prevention rather than reaction. GDPR compliance brings measurable benefits: higher trust, less legal risk, better conversion rates.

Legal certainty and protection from fines

With this checklist you cover Art. 5โ€“32 GDPR. Including the eConsent guideline. Through correct cookie implementation, small and medium-sized businesses save thousands of euros in cease-and-desist fees every year.

Competitive advantage through trust

Users prefer GDPR-compliant websites. Studies show 30% higher loyalty. Your website becomes a trust signal.

Scalability

Plugin solutions alone are not enough. This approach grows with your business. Even with international expansion.

Step-by-step guide

Step 1: Create a privacy policy
Install a data protection plugin such as Complianz or GDPR Cookie Consent. Adapt the mandatory information: controller, purposes, data-subject rights. Link the policy in the footer.

  • Cover Art. 13/14 GDPR in full.
  • Check completeness with the BayLDA checklist.

Step 2: Set up a cookie banner
Set up a banner with granular opt-in. Essential cookies stay active. Marketing cookies only after consent. Third-party scripts are blocked until consent is given.

  • Install Complianz or CookieYes.
  • Test with cookiebot.de/scan.

Step 3: Keep a record of processing activities
List all data processing. Contact forms, server logs, newsletters, analytics. Maintain the register in Excel or with tools such as DataGuard.

  • Update monthly.
  • Store server-side.

Step 4: Optimise consent management
Consents must be revocable. Add a revocation link in the footer (Art. 7 GDPR). Log consents for 14 months.

  • Run the Complianz wizard.
  • Check performance with GTmetrix.

Step 5: Audit and training
Check your website with DSGVO-Check.de. Train your team using the free resources from the LfDI.

Frequently asked questions (FAQ)

1. What happens in the event of a GDPR breach?

Fines of up to 20 million euros or 4% of turnover. H&M paid 746,000 euros. Regular audits protect you.

2. Is a plugin enough for full compliance?

No. Plugins such as Complianz help, but you need an individual privacy policy and a RoPA. Both must be tailored to your project.

3. How often do I need to update the privacy policy?

Immediately when something changes. Installed a new plugin? Update the privacy policy. Review it at least once a year.

4. Do I need a data protection officer?

For sensitive data or more than 250 employees: yes (Art. 37 GDPR). For most small websites: no.

5. How do I scan cookies on my website?

Use cookie-script.com or the browser DevTools. That way you can see which trackers are active.

6. What is the difference from the ePrivacy directive?

The GDPR governs data processing. ePrivacy governs cookies. You solve both with a good opt-in banner.

Frequently asked questions

Which GDPR requirements apply to German websites?

Legal notice, privacy policy, cookie banner with opt-in, SSL encryption and data-subject rights (access, erasure). That is the minimum.

Do I need a cookie banner for my website?

Yes, as soon as you set non-technical cookies. Google Analytics, Facebook Pixel โ€“ everything requires prior consent. Mandatory since the CJEU ruling.

What happens in the event of a GDPR breach?

Fines of up to 20 million euros or 4% of worldwide annual turnover. Plus warning letters and damages.

Further reading