Table of contents
GDPR compliance checklist for German websites
| โ Measure | Priority | Legal basis | Implementation note |
|---|---|---|---|
| Create a privacy policy | ๐ด High | Art. 13, 14 GDPR | List the controller, purposes, retention periods, recipients and data-subject rights in full |
| Cookie banner with opt-in | ๐ด High | Art. 6(1)(a) GDPR, ePrivacy | Granular consent for marketing cookies, essential always active, block third-party |
| Record of processing activities (RoPA) | ๐ด High | Art. 30 GDPR | Document all processing: contact forms, logs, newsletters, analytics |
| Add a legal notice (Impressum) | ๐ด High | ยง 5 TMG, Art. 13 GDPR | Controller with contact details, appoint a data protection officer where required |
| Enable SSL encryption | ๐ด High | Art. 32 GDPR (TOMs) | HTTPS for the entire website, keep the certificate up to date |
| Data processing agreements (DPAs) | ๐ Medium | Art. 28 GDPR | Conclude with hosting, newsletter tool and analytics providers |
| Consent management platform (CMP) | ๐ Medium | Art. 7 GDPR | Log consents, make them revocable, store for 14 months |
| Implement data-subject rights | ๐ Medium | Art. 15-22 GDPR | Establish processes for access, erasure, rectification and objection |
| Implement an erasure concept | ๐ Medium | Art. 17 GDPR | Set automatic retention periods for logs, forms and newsletter data |
| Data protection impact assessment (DPIA) | ๐ก Low | Art. 35 GDPR | Only for high-risk processing (e.g. extensive profiling, sensitive data) |
| Train staff | ๐ก Low | Art. 32 GDPR | Annual training on data protection, strong passwords and phishing protection |
| Secure a backup strategy | ๐ก Low | Art. 32 GDPR (availability) | Encrypted backups, run a quarterly restore test |
Fines of up to 4% of annual turnover. Data protection authorities such as the BayLDA are scrutinising more actively than ever. In my training sessions I regularly see that website operators are unsure: what exactly do I need to do? This checklist gives you the answer. Step by step. Without an expensive consultant.
Anyone who sees data protection not just as an obligation but uses it as a trust signal gains an advantage. Customers prefer to buy from providers they trust. A clean data protection setup pays off.
Key takeaways
- Privacy policy first: It informs users about how their data is processed. Without one, you risk warning letters. A complete policy dramatically reduces the risk of cease-and-desist claims and builds trust.
- Cookie banner with opt-in: Tracking cookies may only load after consent. Without a correct banner you risk fines. Google has paid 100 million euros. You don't want to be next.
- Record of processing activities (RoPA): Documents all processes. Protects you during audits. Saves consultancy costs because you keep the overview.
- Train your team: The most common data protection breaches happen internally. Regular short training sessions noticeably reduce error rates.
- Data protection impact assessment (DPIA): Only needed for high-risk processing, e.g. profiling. An early risk assessment avoids costly rework.
Why this approach works
This checklist relies on prevention rather than reaction. GDPR compliance brings measurable benefits: higher trust, less legal risk, better conversion rates.
Legal certainty and protection from fines
With this checklist you cover Art. 5โ32 GDPR. Including the eConsent guideline. Through correct cookie implementation, small and medium-sized businesses save thousands of euros in cease-and-desist fees every year.
Competitive advantage through trust
Users prefer GDPR-compliant websites. Studies show 30% higher loyalty. Your website becomes a trust signal.
Scalability
Plugin solutions alone are not enough. This approach grows with your business. Even with international expansion.
Step-by-step guide
Step 1: Create a privacy policy
Install a data protection plugin such as Complianz or GDPR Cookie Consent. Adapt the mandatory information: controller, purposes, data-subject rights. Link the policy in the footer.
- Cover Art. 13/14 GDPR in full.
- Check completeness with the BayLDA checklist.
Step 2: Set up a cookie banner
Set up a banner with granular opt-in. Essential cookies stay active. Marketing cookies only after consent. Third-party scripts are blocked until consent is given.
- Install Complianz or CookieYes.
- Test with cookiebot.de/scan.
Step 3: Keep a record of processing activities
List all data processing. Contact forms, server logs, newsletters, analytics. Maintain the register in Excel or with tools such as DataGuard.
- Update monthly.
- Store server-side.
Step 4: Optimise consent management
Consents must be revocable. Add a revocation link in the footer (Art. 7 GDPR). Log consents for 14 months.
- Run the Complianz wizard.
- Check performance with GTmetrix.
Step 5: Audit and training
Check your website with DSGVO-Check.de. Train your team using the free resources from the LfDI.
Frequently asked questions (FAQ)
1. What happens in the event of a GDPR breach?
Fines of up to 20 million euros or 4% of turnover. H&M paid 746,000 euros. Regular audits protect you.
2. Is a plugin enough for full compliance?
No. Plugins such as Complianz help, but you need an individual privacy policy and a RoPA. Both must be tailored to your project.
3. How often do I need to update the privacy policy?
Immediately when something changes. Installed a new plugin? Update the privacy policy. Review it at least once a year.
4. Do I need a data protection officer?
For sensitive data or more than 250 employees: yes (Art. 37 GDPR). For most small websites: no.
5. How do I scan cookies on my website?
Use cookie-script.com or the browser DevTools. That way you can see which trackers are active.
6. What is the difference from the ePrivacy directive?
The GDPR governs data processing. ePrivacy governs cookies. You solve both with a good opt-in banner.
Frequently asked questions
Which GDPR requirements apply to German websites?
Legal notice, privacy policy, cookie banner with opt-in, SSL encryption and data-subject rights (access, erasure). That is the minimum.
Do I need a cookie banner for my website?
Yes, as soon as you set non-technical cookies. Google Analytics, Facebook Pixel โ everything requires prior consent. Mandatory since the CJEU ruling.
What happens in the event of a GDPR breach?
Fines of up to 20 million euros or 4% of worldwide annual turnover. Plus warning letters and damages.