A tradesperson has a new website built, everything looks good – and weeks later a warning letter arrives about a missing legal notice and Google Fonts loaded straight from Google’s servers. Exactly these avoidable issues are why a GDPR-compliant website feels like a bureaucratic monster to many businesses. It isn’t. Most points can be worked through cleanly with a clear GDPR website checklist.
First, a note on scope: the GDPR applies to organisations established in the EU when they process personal data as part of their activities. For organisations outside the EU, it applies in particular when they offer goods or services to people in the EU or monitor their behaviour there.
The good news: the leaner a website is built, the closer it already is to compliance. If you embed no tracking services, no unnecessary plugins and no third-party servers, you simply collect less data – and have less to secure.
This article works through the typical issues in practice: legal notice, privacy policy, cookie consent, external services, contact forms and hosting. At the end you’ll find a checklist to work through.
One thing up front: this text offers orientation and does not replace legal advice. For sensitive data or special cases, get professional counsel.
Legal notice and imprint requirements
Many countries require commercial websites to publish a legal notice – often called an imprint – that identifies who is behind the site. The exact requirements vary by country, legal form and type of business.
A legal notice typically includes:
- Name and address of the business (not just a PO box)
- Authorised representative, such as a director or owner
- Contact: an email address and ideally a phone number
- Registration data: company or trade register number where applicable
- VAT identification number, if you have one
- For regulated professions: professional title and the relevant regulatory body
The important part is that the legal notice is reachable from every page with a single click – a footer link is standard. Don’t bury it in a submenu. Regulated fields such as law firms, medical practices or tax advisors carry extra professional disclosures that you set up once and rarely need to touch again.
Privacy policy: explain what actually happens
When your website processes personal data, you must tell visitors about that processing in a transparent way. This often includes server logs created when a page is requested. A privacy policy should describe which data you process, for what purpose and on what legal basis.
Typical contents are:
- Data controller and contact details
- Hosting and server log files
- Contact form and email communication
- Services in use: analytics, maps, embedded videos, fonts
- Data subject rights: access, erasure, objection
- Where relevant, newsletter or booking systems
The most common mistake is a copied template that describes services you don’t use – or, worse, omits ones you do. A privacy policy has to reflect your actual website. A reputable generator is a decent starting point, but it must be adapted to your reality. The European Commission’s data protection guidance explains the legal framework, core concepts and data subject rights.
Cookie consent: only where it’s genuinely needed
This is where the biggest misunderstanding sits: not every website needs a cookie banner. A consent banner is typically required when you use cookies or services that are not strictly necessary – analytics tools, marketing pixels, embedded videos with tracking and similar services. The exact assessment depends on the technical setup and the national rules that apply.
Strictly necessary cookies – for a shopping cart or session handling, say – need no prior consent. For everything else the rule holds: without active, freely given consent, those services must not load beforehand.
That leads to a point many people miss: a website with no tracking at all often needs no banner whatsoever. This is not a shortcoming but a quality signal. No annoying overlay on the first visit, less data collection, a smaller attack surface. If you do want analytics, there are data-minimising alternatives that work without personal tracking and, depending on the setup, without consent.
If you do need a banner, make sure that:
- Rejecting is as easy as accepting – no hidden routes
- No pre-ticked boxes and no loading before consent
- No nudging through a highlighted accept button next to a buried reject option
External services: the most common stumbling block
Most unintended privacy problems come from external services that quietly send data to third-party servers in the background. The classics are fonts, maps and videos loaded directly from third parties.
Self-host Google Fonts
When Google Fonts are loaded straight from Google’s servers, every page view transmits the visitor’s IP address. The clean solution is to download the fonts and serve them locally from your own server. Visually identical, but with no data leaving your site – and the same applies to other external font and script libraries.
YouTube and Maps embeds
An embedded YouTube video or a Google Maps map loads data from the provider as soon as the page opens. Two practical routes:
- The privacy-enhanced mode for YouTube, or a two-click solution where the embed only loads after an active click
- Instead of an interactive map, a linked preview image or simply the address with a link to the map
Analytics without ballast
If you want to know how your site is used, it doesn’t have to be a heavyweight tracking suite. Data-minimising analytics tools measure in aggregate without building personal profiles – often with no cookies, and so, depending on the setup, no banner.
Contact forms: encryption and data minimisation
A contact form processes personal data, so two ground rules apply: secure transmission and as little data as possible.
- SSL/TLS encryption: the site must run over HTTPS. A valid certificate is standard today and usually included free with hosting.
- Data minimisation: ask only for what you actually need. Keep required fields to the essentials and make the rest optional.
- Notice and consent: a short note with a link to the privacy policy beside the form creates transparency.
- Purpose limitation: don’t hoard enquiries indefinitely; delete them after a sensible period once they’re handled.
A frequent mistake is overloaded forms asking for date of birth, title and company size when an email address would be enough for a simple enquiry. Fewer fields mean less risk – and, as a bonus, more completed forms.
Hosting location and data processing agreements
Where your website is hosted is a data protection matter, because your host processes personal data on your behalf – through server logs, for example. Two points are central.
First, location: hosting within the EU or EEA spares you the more complex questions around transferring data to third countries. Servers in Europe are simply the more straightforward path here.
Second, the data processing agreement (DPA): with your host and any other providers that process data on your behalf, you need such an agreement in place. Reputable providers offer one as standard – check that it exists and has been concluded.
The building blocks at a glance
The table below sums up the main building blocks – including the mistakes we see most often in practice.
| Building block | Required? | Common mistake | Fix |
|---|---|---|---|
| Legal notice | Yes (commercial sites) | Missing, incomplete or hard to find | Complete, reachable via footer link from every page |
| Privacy policy | Yes | Copied template doesn’t match the site | Adapt to the services actually in use |
| Cookie banner | Only for non-essential cookies | Banner without tracking, or loading before consent | No tracking, no banner; otherwise a real choice |
| Google Fonts | – | Loaded directly from Google’s servers | Self-host the fonts |
| YouTube/Maps embeds | – | Loads data as the page opens | Two-click solution or preview image |
| Contact form | – | No HTTPS, too many required fields | SSL and data minimisation |
| Hosting | – | Servers outside the EU, no DPA | Hosting in Europe, conclude a DPA |
Why a lean website is easier to keep compliant
The thread running through every point: data protection is not a bureaucratic monster but a question of clean execution. And that gets easier the less unnecessary ballast a website carries.
A site built around WordPress and a sprawl of plugins often pulls in third-party servers unprompted, loads fonts externally and sets cookies nobody remembers the purpose of. A lean, individually built website does the opposite: it loads only what it needs, keeps fonts and scripts local, and skips tracking that no one uses.
JetPages is a custom-built business website with a self-manageable CMS, without WordPress. Our sites are built without unnecessary tracking ballast, fonts and scripts are self-hosted, and the legal notice and privacy policy are cleanly integrated. If you’re unsure where your existing site stands, our website check gives you a quick read; the technical approach is shown on our solution page.
Checklist: GDPR-compliant website
Work through it from top to bottom:
- Legal notice complete and reachable via footer link from every page
- For regulated professions, extra professional disclosures added
- Privacy policy adapted to the services actually in use
- Checked whether any non-essential cookies are in use at all
- If no tracking: deliberately skipped the banner
- If a banner is needed: rejecting as easy as accepting, no pre-loading
- Google Fonts and other external resources self-hosted
- YouTube and Maps embeds switched to two-click or preview image
- Analytics – if wanted – solved in a data-minimising, cookieless way
- Contact form over HTTPS with minimal required fields
- Hosting in Europe and a data processing agreement concluded
Work through the list thoroughly once and most of it is done. The rest is upkeep: when you add a new service, check whether it sends data out – and update the privacy policy. For a binding assessment of your specific situation, seek professional advice when in doubt.