Back to blog overview

GDPR-Compliant Website: Practical Checklist for Businesses

Use this practical GDPR website checklist to review your privacy policy, cookie consent, Google Fonts, contact forms, hosting, and legal notices step by step.

GDPR-compliant website – checklist with legal notice, privacy policy and cookie consent for businesses

A tradesperson has a new website built, everything looks good – and weeks later a warning letter arrives about a missing legal notice and Google Fonts loaded straight from Google’s servers. Exactly these avoidable issues are why a GDPR-compliant website feels like a bureaucratic monster to many businesses. It isn’t. Most points can be worked through cleanly with a clear GDPR website checklist.

First, a note on scope: the GDPR applies to organisations established in the EU when they process personal data as part of their activities. For organisations outside the EU, it applies in particular when they offer goods or services to people in the EU or monitor their behaviour there.

The good news: the leaner a website is built, the closer it already is to compliance. If you embed no tracking services, no unnecessary plugins and no third-party servers, you simply collect less data – and have less to secure.

This article works through the typical issues in practice: legal notice, privacy policy, cookie consent, external services, contact forms and hosting. At the end you’ll find a checklist to work through.

One thing up front: this text offers orientation and does not replace legal advice. For sensitive data or special cases, get professional counsel.

Many countries require commercial websites to publish a legal notice – often called an imprint – that identifies who is behind the site. The exact requirements vary by country, legal form and type of business.

A legal notice typically includes:

  • Name and address of the business (not just a PO box)
  • Authorised representative, such as a director or owner
  • Contact: an email address and ideally a phone number
  • Registration data: company or trade register number where applicable
  • VAT identification number, if you have one
  • For regulated professions: professional title and the relevant regulatory body

The important part is that the legal notice is reachable from every page with a single click – a footer link is standard. Don’t bury it in a submenu. Regulated fields such as law firms, medical practices or tax advisors carry extra professional disclosures that you set up once and rarely need to touch again.

Privacy policy: explain what actually happens

When your website processes personal data, you must tell visitors about that processing in a transparent way. This often includes server logs created when a page is requested. A privacy policy should describe which data you process, for what purpose and on what legal basis.

Typical contents are:

  • Data controller and contact details
  • Hosting and server log files
  • Contact form and email communication
  • Services in use: analytics, maps, embedded videos, fonts
  • Data subject rights: access, erasure, objection
  • Where relevant, newsletter or booking systems

The most common mistake is a copied template that describes services you don’t use – or, worse, omits ones you do. A privacy policy has to reflect your actual website. A reputable generator is a decent starting point, but it must be adapted to your reality. The European Commission’s data protection guidance explains the legal framework, core concepts and data subject rights.

This is where the biggest misunderstanding sits: not every website needs a cookie banner. A consent banner is typically required when you use cookies or services that are not strictly necessary – analytics tools, marketing pixels, embedded videos with tracking and similar services. The exact assessment depends on the technical setup and the national rules that apply.

Strictly necessary cookies – for a shopping cart or session handling, say – need no prior consent. For everything else the rule holds: without active, freely given consent, those services must not load beforehand.

That leads to a point many people miss: a website with no tracking at all often needs no banner whatsoever. This is not a shortcoming but a quality signal. No annoying overlay on the first visit, less data collection, a smaller attack surface. If you do want analytics, there are data-minimising alternatives that work without personal tracking and, depending on the setup, without consent.

If you do need a banner, make sure that:

  • Rejecting is as easy as accepting – no hidden routes
  • No pre-ticked boxes and no loading before consent
  • No nudging through a highlighted accept button next to a buried reject option

External services: the most common stumbling block

Most unintended privacy problems come from external services that quietly send data to third-party servers in the background. The classics are fonts, maps and videos loaded directly from third parties.

Self-host Google Fonts

When Google Fonts are loaded straight from Google’s servers, every page view transmits the visitor’s IP address. The clean solution is to download the fonts and serve them locally from your own server. Visually identical, but with no data leaving your site – and the same applies to other external font and script libraries.

YouTube and Maps embeds

An embedded YouTube video or a Google Maps map loads data from the provider as soon as the page opens. Two practical routes:

  • The privacy-enhanced mode for YouTube, or a two-click solution where the embed only loads after an active click
  • Instead of an interactive map, a linked preview image or simply the address with a link to the map

Analytics without ballast

If you want to know how your site is used, it doesn’t have to be a heavyweight tracking suite. Data-minimising analytics tools measure in aggregate without building personal profiles – often with no cookies, and so, depending on the setup, no banner.

Contact forms: encryption and data minimisation

A contact form processes personal data, so two ground rules apply: secure transmission and as little data as possible.

  • SSL/TLS encryption: the site must run over HTTPS. A valid certificate is standard today and usually included free with hosting.
  • Data minimisation: ask only for what you actually need. Keep required fields to the essentials and make the rest optional.
  • Notice and consent: a short note with a link to the privacy policy beside the form creates transparency.
  • Purpose limitation: don’t hoard enquiries indefinitely; delete them after a sensible period once they’re handled.

A frequent mistake is overloaded forms asking for date of birth, title and company size when an email address would be enough for a simple enquiry. Fewer fields mean less risk – and, as a bonus, more completed forms.

Hosting location and data processing agreements

Where your website is hosted is a data protection matter, because your host processes personal data on your behalf – through server logs, for example. Two points are central.

First, location: hosting within the EU or EEA spares you the more complex questions around transferring data to third countries. Servers in Europe are simply the more straightforward path here.

Second, the data processing agreement (DPA): with your host and any other providers that process data on your behalf, you need such an agreement in place. Reputable providers offer one as standard – check that it exists and has been concluded.

The building blocks at a glance

The table below sums up the main building blocks – including the mistakes we see most often in practice.

Building blockRequired?Common mistakeFix
Legal noticeYes (commercial sites)Missing, incomplete or hard to findComplete, reachable via footer link from every page
Privacy policyYesCopied template doesn’t match the siteAdapt to the services actually in use
Cookie bannerOnly for non-essential cookiesBanner without tracking, or loading before consentNo tracking, no banner; otherwise a real choice
Google FontsLoaded directly from Google’s serversSelf-host the fonts
YouTube/Maps embedsLoads data as the page opensTwo-click solution or preview image
Contact formNo HTTPS, too many required fieldsSSL and data minimisation
HostingServers outside the EU, no DPAHosting in Europe, conclude a DPA

Why a lean website is easier to keep compliant

The thread running through every point: data protection is not a bureaucratic monster but a question of clean execution. And that gets easier the less unnecessary ballast a website carries.

A site built around WordPress and a sprawl of plugins often pulls in third-party servers unprompted, loads fonts externally and sets cookies nobody remembers the purpose of. A lean, individually built website does the opposite: it loads only what it needs, keeps fonts and scripts local, and skips tracking that no one uses.

JetPages is a custom-built business website with a self-manageable CMS, without WordPress. Our sites are built without unnecessary tracking ballast, fonts and scripts are self-hosted, and the legal notice and privacy policy are cleanly integrated. If you’re unsure where your existing site stands, our website check gives you a quick read; the technical approach is shown on our solution page.

Checklist: GDPR-compliant website

Work through it from top to bottom:

  • Legal notice complete and reachable via footer link from every page
  • For regulated professions, extra professional disclosures added
  • Privacy policy adapted to the services actually in use
  • Checked whether any non-essential cookies are in use at all
  • If no tracking: deliberately skipped the banner
  • If a banner is needed: rejecting as easy as accepting, no pre-loading
  • Google Fonts and other external resources self-hosted
  • YouTube and Maps embeds switched to two-click or preview image
  • Analytics – if wanted – solved in a data-minimising, cookieless way
  • Contact form over HTTPS with minimal required fields
  • Hosting in Europe and a data processing agreement concluded

Work through the list thoroughly once and most of it is done. The rest is upkeep: when you add a new service, check whether it sends data out – and update the privacy policy. For a binding assessment of your specific situation, seek professional advice when in doubt.

Lean tech, minimal data collection

A website that is privacy-friendly from the ground up

JetPages is a custom-built business website with a self-manageable CMS, without WordPress. We build it without unnecessary tracking ballast, with self-hosted fonts and cleanly integrated legal texts. Let's talk, with no obligation, about a technically clean and privacy-friendly website.

Talk about a privacy-friendly website

FAQs

Does every website need a cookie banner?

No. A consent banner is typically needed when your website uses cookies or services that are not strictly necessary – for example analytics tools, marketing pixels or embedded videos with tracking. A lean website without those services may need no consent banner, depending on its technical setup and the national rules that apply.

Are Google Fonts GDPR compliant?

Google Fonts are fine when you self-host the font files on your own server. If they are loaded directly from Google's servers instead, each page view sends the visitor's IP address to a third party, and you would usually need a legal basis for that. The clean solution is almost always to serve fonts and other external resources locally from your own domain.

What must a privacy policy include?

A privacy policy describes which personal data you process, for what purpose and on what legal basis. It typically covers the data controller, hosting, contact forms, any services such as analytics or maps, and the rights of data subjects. The key point is that the policy reflects your actual website rather than simply copying a generic template.

Does a GDPR-compliant website replace legal advice?

No. This article offers practical orientation, but it does not replace individual legal advice. For a binding assessment of your specific situation – for instance with sensitive data, tracking or sector-specific obligations – you should consult a qualified data protection or IT lawyer when in doubt.

Free website check

How healthy is your website really?

Send us the address of your website, a developer reviews it personally, and you get a clear, plain-language report within two business days. Free and no obligation.

Reviewed by a developer
Report in 2 business days
Free and no obligation
Design examples

See what your website could look like

30 example websites across industries — live and clickable, each with five color schemes. A starting point for your custom design.

Browse all design examples →

A good match for this industry: