Table of contents
GDPR compliance checklist for German websites
| ✅ Measure | Priority | Legal basis | Implementation note |
|---|---|---|---|
| Create a privacy policy | 🔴 High | Art. 13, 14 GDPR | List the controller, purposes, retention periods, recipients and data subject rights in full |
| Cookie banner with opt-in | 🔴 High | Art. 6(1)(a) GDPR, ePrivacy | Granular consent for marketing cookies, essential always active, block third-party |
| Record of processing activities (RoPA) | 🔴 High | Art. 30 GDPR | Document all processing: contact forms, logs, newsletters, analytics |
| Add a legal notice (Impressum) | 🔴 High | § 5 TMG, Art. 13 GDPR | Controller with contact details, name a data protection officer if applicable |
| Enable SSL encryption | 🔴 High | Art. 32 GDPR (TOM) | HTTPS for the entire website, keep the certificate up to date |
| Data processing agreements (DPA) | 🟠 Medium | Art. 28 GDPR | Conclude with hosting, newsletter tool and analytics providers |
| Consent management system (CMS) | 🟠 Medium | Art. 7 GDPR | Log consents, make them revocable, store for 14 months |
| Implement data subject rights | 🟠 Medium | Art. 15-22 GDPR | Establish processes for access, erasure, rectification and objection |
| Implement a deletion concept | 🟠 Medium | Art. 17 GDPR | Set automatic deletion periods for logs, forms and newsletter data |
| Data protection impact assessment (DPIA) | 🟡 Low | Art. 35 GDPR | Only for high-risk processing (e.g. extensive profiling, sensitive data) |
| Train staff | 🟡 Low | Art. 32 GDPR | Annual training on data protection, secure passwords, phishing protection |
| Secure a backup strategy | 🟡 Low | Art. 32 GDPR (availability) | Encrypted backups, carry out a recovery test every quarter |
The data protection authority (DSB) in Vienna enforces more strictly. Fines of up to 20 million euros or 4% of turnover are possible. In my training sessions I see it again and again: most website operators have gaps. Unclear cookie banners, missing DPAs, incomplete privacy policies. This checklist shows you what needs to be done.
Anyone who builds data protection in from the start – Privacy by Design – saves themselves later rework. And earns users’ trust.
The most important takeaways
Privacy by Design as a core principle
Only process data that is necessary. Less data means less risk. Austrian websites benefit from a lower risk of fines and higher user loyalty.
Cookie banner with mandatory opt-in
Tracking cookies may only load after active consent. No pre-ticking. This protects against penalties in line with ECJ rulings.
Keep the privacy policy complete
Purposes, legal bases, recipients – everything must be in there. If something is missing, you risk warning letters.
Conclude a DPA with every service provider
Hosting, analytics, fonts – you need a data processing agreement for every service provider. For US transfers, SCCs on top.
Handle data subject rights quickly
Erasure or access requests must be answered within 30 days. Anyone who handles this promptly avoids escalation to the DSB.
Why this approach works
Prevention instead of rework. GDPR compliance protects against fines and improves the conversion rate through user trust.
ROI through risk minimisation
1–2 days of work for the checklist. That saves warning-letter costs (up to 50,000 euros under the TKG) and increases conversion rates by up to 20% through trust.
Future-proof instead of plugin-dependent
Generic privacy generators are risky. Individual adaptation to WKO templates also holds up when the law changes.
Comparison of approaches
| Approach | Advantages | Disadvantages |
|---|---|---|
| This checklist | Complete, Austria-specific, scalable | Requires upfront effort |
| Free generators | Fast | Risk of warning letters, imprecise |
| Agency | Expert knowledge | High costs (from 2,000 euros) |
Step-by-step guide
Step 1: Analyse the website
Check what data your website collects. Open the site in incognito mode. Use uMatrix or Ghostery to find trackers. Google Fonts, Analytics, Facebook Pixel – list everything.
- This forms the basis for your record of processing activities.
Step 2: Create a privacy policy
Use the WKO templates as a starting point. Adapt: controller, purposes, rights, retention periods. Link to it in the footer.
- Cover Art. 13 GDPR in full.
- Add contact details and the DSB (if you have one).
Step 3: Set up a cookie banner
Install a CMP plugin such as Complianz or Consent Manager. No pre-ticking. Only load third-party scripts after consent.
- Essential: legitimate interest. Marketing: only with consent.
- Test: no tracking scripts before the banner.
Step 4: Check DPAs and SSL
Download DPA templates from the WKO. Conclude contracts with all service providers (hosting, Google, newsletter tool). Enable HTTPS via Let’s Encrypt.
- For US transfers: check SCCs.
Step 5: Document processes
Create the record of processing activities in Excel. Define a workflow for data subject requests. Train your team in 30 minutes.
Frequently asked questions (FAQ)
Do I need a data protection officer (DSB)?
Only for systematic monitoring or sensitive data (Art. 37 GDPR). For standard websites, a self-assessment is enough.
Which cookies are allowed without consent?
Only technical cookies, e.g. session cookies for the shopping cart (§ 165 TKG). Google Analytics requires opt-in.
What to do about US tools like Google Analytics?
Conclude a DPA and SCCs. Anonymise the IP. Or switch to EU-hosted alternatives.
How often do I need to update the checklist?
Annually or whenever something changes. New plugin? Check immediately.
What does non-compliance cost?
Up to 20 million euros (GDPR) plus 50,000 euros (TKG). Prevention costs a fraction of that.
Does WordPress help with this?
Yes. Plugins like Complianz cover the technical part. You have to adapt the legal part yourself.
Frequently asked questions
Which GDPR requirements apply to Austrian websites?
Austrian websites are subject to the EU GDPR and the Austrian DSG (Data Protection Act). A legal notice, privacy policy, cookie banner with opt-in and DPAs are mandatory.
Are there differences from the German GDPR implementation?
The EU GDPR applies in the same way. Austria has its own additions in the DSG. The data protection authority in Vienna is responsible.
Which cookie consent tool is recommended for Austrian websites?
Borlabs Cookie, Complianz or CookieYes. All of them offer GDPR- and DSG-compliant solutions with opt-in and cookie categorisation.