WordPress Training
Allgemein

GDPR Compliance Checklist for Austrian Websites: The Quick Guide to Legally Sound Implementation

Table of contents

GDPR compliance checklist for German websites

✅ Measure Priority Legal basis Implementation note
Create a privacy policy 🔴 High Art. 13, 14 GDPR List the controller, purposes, retention periods, recipients and data subject rights in full
Cookie banner with opt-in 🔴 High Art. 6(1)(a) GDPR, ePrivacy Granular consent for marketing cookies, essential always active, block third-party
Record of processing activities (RoPA) 🔴 High Art. 30 GDPR Document all processing: contact forms, logs, newsletters, analytics
Add a legal notice (Impressum) 🔴 High § 5 TMG, Art. 13 GDPR Controller with contact details, name a data protection officer if applicable
Enable SSL encryption 🔴 High Art. 32 GDPR (TOM) HTTPS for the entire website, keep the certificate up to date
Data processing agreements (DPA) 🟠 Medium Art. 28 GDPR Conclude with hosting, newsletter tool and analytics providers
Consent management system (CMS) 🟠 Medium Art. 7 GDPR Log consents, make them revocable, store for 14 months
Implement data subject rights 🟠 Medium Art. 15-22 GDPR Establish processes for access, erasure, rectification and objection
Implement a deletion concept 🟠 Medium Art. 17 GDPR Set automatic deletion periods for logs, forms and newsletter data
Data protection impact assessment (DPIA) 🟡 Low Art. 35 GDPR Only for high-risk processing (e.g. extensive profiling, sensitive data)
Train staff 🟡 Low Art. 32 GDPR Annual training on data protection, secure passwords, phishing protection
Secure a backup strategy 🟡 Low Art. 32 GDPR (availability) Encrypted backups, carry out a recovery test every quarter

The data protection authority (DSB) in Vienna enforces more strictly. Fines of up to 20 million euros or 4% of turnover are possible. In my training sessions I see it again and again: most website operators have gaps. Unclear cookie banners, missing DPAs, incomplete privacy policies. This checklist shows you what needs to be done.

Anyone who builds data protection in from the start – Privacy by Design – saves themselves later rework. And earns users’ trust.

The most important takeaways

Privacy by Design as a core principle
Only process data that is necessary. Less data means less risk. Austrian websites benefit from a lower risk of fines and higher user loyalty.

Cookie banner with mandatory opt-in
Tracking cookies may only load after active consent. No pre-ticking. This protects against penalties in line with ECJ rulings.

Keep the privacy policy complete
Purposes, legal bases, recipients – everything must be in there. If something is missing, you risk warning letters.

Conclude a DPA with every service provider
Hosting, analytics, fonts – you need a data processing agreement for every service provider. For US transfers, SCCs on top.

Handle data subject rights quickly
Erasure or access requests must be answered within 30 days. Anyone who handles this promptly avoids escalation to the DSB.

Why this approach works

Prevention instead of rework. GDPR compliance protects against fines and improves the conversion rate through user trust.

ROI through risk minimisation

1–2 days of work for the checklist. That saves warning-letter costs (up to 50,000 euros under the TKG) and increases conversion rates by up to 20% through trust.

Future-proof instead of plugin-dependent

Generic privacy generators are risky. Individual adaptation to WKO templates also holds up when the law changes.

Comparison of approaches

Approach Advantages Disadvantages
This checklist Complete, Austria-specific, scalable Requires upfront effort
Free generators Fast Risk of warning letters, imprecise
Agency Expert knowledge High costs (from 2,000 euros)

Step-by-step guide

Step 1: Analyse the website

Check what data your website collects. Open the site in incognito mode. Use uMatrix or Ghostery to find trackers. Google Fonts, Analytics, Facebook Pixel – list everything.

  • This forms the basis for your record of processing activities.

Step 2: Create a privacy policy

Use the WKO templates as a starting point. Adapt: controller, purposes, rights, retention periods. Link to it in the footer.

  • Cover Art. 13 GDPR in full.
  • Add contact details and the DSB (if you have one).

Step 3: Set up a cookie banner

Install a CMP plugin such as Complianz or Consent Manager. No pre-ticking. Only load third-party scripts after consent.

  • Essential: legitimate interest. Marketing: only with consent.
  • Test: no tracking scripts before the banner.

Step 4: Check DPAs and SSL

Download DPA templates from the WKO. Conclude contracts with all service providers (hosting, Google, newsletter tool). Enable HTTPS via Let’s Encrypt.

  • For US transfers: check SCCs.

Step 5: Document processes

Create the record of processing activities in Excel. Define a workflow for data subject requests. Train your team in 30 minutes.

Frequently asked questions (FAQ)

Do I need a data protection officer (DSB)?

Only for systematic monitoring or sensitive data (Art. 37 GDPR). For standard websites, a self-assessment is enough.

Which cookies are allowed without consent?

Only technical cookies, e.g. session cookies for the shopping cart (§ 165 TKG). Google Analytics requires opt-in.

What to do about US tools like Google Analytics?

Conclude a DPA and SCCs. Anonymise the IP. Or switch to EU-hosted alternatives.

How often do I need to update the checklist?

Annually or whenever something changes. New plugin? Check immediately.

What does non-compliance cost?

Up to 20 million euros (GDPR) plus 50,000 euros (TKG). Prevention costs a fraction of that.

Does WordPress help with this?

Yes. Plugins like Complianz cover the technical part. You have to adapt the legal part yourself.

Frequently asked questions

Which GDPR requirements apply to Austrian websites?

Austrian websites are subject to the EU GDPR and the Austrian DSG (Data Protection Act). A legal notice, privacy policy, cookie banner with opt-in and DPAs are mandatory.

Are there differences from the German GDPR implementation?

The EU GDPR applies in the same way. Austria has its own additions in the DSG. The data protection authority in Vienna is responsible.

Which cookie consent tool is recommended for Austrian websites?

Borlabs Cookie, Complianz or CookieYes. All of them offer GDPR- and DSG-compliant solutions with opt-in and cookie categorisation.

Further reading