A GDPR Check for Your Website: The Gaps That Are Almost Always There
Simon Heistermann
Owner
This article was written with AI assistance and editorially reviewed.
Privacy on websites rarely fails on intent and almost always on convenience. A typeface from someone else's network, an embedded map, an analytics script that starts before anyone has seen the consent button: three lines of code nobody deliberately ordered, handing on your visitors' data before anyone was asked. That is not a scandal, it is a default setting - which is exactly why it can be switched off.
In short
The most common gaps are technical rather than legal, and you can check them yourself in half an hour: what loads before you have clicked anything? We deliver the technical implementation; the legal assessment of your particular case stays with a solicitor.
Why this is almost never deliberate
Hardly anyone decides to pass on visitor data. What actually happens is far less dramatic. A theme ships with a font embed. A plugin pulls its library from an external network. An editor adds a map because it shows people how to get there. Each of those decisions made sense on its own, and none of them was ever framed as a privacy question.
So the most productive starting point is not legal research, it is a stocktake: which third-party servers does your site contact, when, and with what data? Everything else follows from that. Without that list, you are discussing a website you do not know.
Fonts, maps and videos: what leaks before consent
The three classics are quickly explained, because they share one pattern. As soon as the browser fetches a file from a third-party server, it transmits the visitor's IP address in the process - whether that file is a font, a map tile or a video player.
On fonts the legal position is still moving. In a much-cited 2022 judgment, a German regional court awarded a claimant 100 EUR in damages because a font was embedded dynamically from a third-party server. In 2025, Germany's Federal Court of Justice referred central questions to the Court of Justice of the European Union, so the last word is still outstanding. That changes little for your decision, because the technical fix is unchanged, simple and free: serve fonts from your own server.
Maps and videos follow the same logic in two stages. First you show a static preview image with a note saying what a click will do. Only the click loads the actual service. Incidentally, that is also the faster option: an embedded video player above the fold costs more load time than almost anything else on a page, as the article on Core Web Vitals shows. Here, for once, privacy and speed pull in the same direction.
The banner that offers no real choice - and what loads before it
A consent banner does its job when rejecting is as easy as agreeing. Supervisory authorities have held that line for years, and a German administrative court confirmed in 2025 that a reject button belongs on the first level and must be visually equivalent. A banner with a coloured "accept all" and a grey "settings" link beside it does not meet that standard.
The second and more common failure sits behind the banner. A great many sites display the banner correctly and have nevertheless already loaded the analytics script before the visitor could click anything. That is no longer a design question, it is an implementation fault - and it is the point where a technically clean setup genuinely takes work. If you want measurement without collecting consent, server-side analysis that does not touch the device is an option; whether that holds up in your specific case belongs back on your legal adviser's desk.
What applies to the website applies to everything hanging off it: a newsletter needs a documented sign-up, and a chat assistant processes what your visitors type. On the first we have written GDPR in email marketing, and on the second our overview of AI chatbots.
US services: where data transfers actually stand
The situation is more stable than the tone of some articles suggests, and less settled than others claim. The European Commission adopted an adequacy decision for the EU-US Data Privacy Framework in 2023. The General Court of the European Union dismissed a challenge to that decision in September 2025, and an appeal against that ruling was most recently pending before the Court of Justice. In parallel, specialists point out that some of the US oversight institutions the decision relies on are currently not fully operational.
The consequence for you is practical, not panicked: check whether the specific provider is certified under the framework, record the decision, and where it makes no difference, prefer the European provider. Where your website itself sits, and what belongs to hosting contractually, is covered in website hosting for businesses.
Want to know what your website passes on before anyone agrees?
Get in touchThe list you can check
- Fonts sit on your own server, and no font is pulled from an external network
- Maps, videos and social embeds load only after a deliberate click, with a preview image before that
- Before consent, the page opens no connection to analytics, advertising or chat services
- The banner offers reject on the same level, at the same size and in the same style as accept
- Consent once given can be withdrawn as easily as it was given
- Forms transmit encrypted, ask only for what is needed, and state the purpose
- Every embedded service has a processing agreement and an entry in the record of processing activities
- The privacy notice names each of those services and matches what the site actually does
You can check most of that list yourself. Open your site in a fresh browser window, open the developer tools, reload, and look at which external addresses are contacted before you have clicked anything. What appears there is your real starting position - not what the privacy notice says.
Concrete steps for the next 90 days
- Days 1-30: take the browser stocktake and note every external connection made before consent
- Days 1-30: have fonts served locally, the fastest item on the list
- Days 31-60: switch maps and videos to a click-to-load preview
- Days 31-60: check the banner: reject on the first level, equivalent in design, withdrawal possible at any time
- Days 61-90: collect processing agreements and bring the record of processing activities up to date
- Days 61-90: have the revised privacy notice reviewed by a solicitor, with the service list attached
Conclusion
The difference between a clean and an unclean website is usually not one big decision but a handful of defaults nobody ever questioned. That is exactly why the work is manageable: local fonts, embeds only after a click, no script before consent, a complete list of services. Four points, not a debate about principles.
And the boundary stays where it belongs. We deliver the technical implementation, as described on our page on GDPR and privacy. The legal assessment of your specific case belongs with a solicitor - and they work considerably faster when they can review a list instead of guessing.
You might also like
WordPress or Custom Build? Run the Five-Year Numbers
WordPress powers a large share of the web, and for good reasons. What it actually costs to run, where it wins outright, and when a custom build makes sense.
Websites for IT Service Providers: Your Own Site Is the Work Sample
An IT provider with a slow, insecure website refutes its own pitch. What an IT manager checks in the first few minutes, and what follows from it.
Website Maintenance in 2026: What It Costs and What Must Be In It
What website maintenance actually covers, what the market charges for it, and how to spot an empty maintenance contract before you sign it.
Website Hosting for Businesses: What Actually Matters in 2026
Shared hosting, managed hosting or a platform: what the difference means for load time and resilience - and who actually owns the domain at the end.
SEO Costs 2026: What Visibility Really Costs
What SEO realistically costs small and mid-sized businesses: one-off optimisation versus ongoing management, and what should be included in the price.
Blog Posts That Rank: Structure, Length and Citability in 2026
How a blog post needs to be built to rank in Google and get cited by ChatGPT and Perplexity in 2026 - structure, length, schema and internal links.
Frequently asked questions

Simon Heistermann
Owner
Heistermann Solutions is the web studio run by Simon Heistermann. We build custom websites for small and medium-sized businesses that want to achieve more online.
Every article grows out of day-to-day project work and is reviewed editorially before publication.
- Borken, Münsterland region
- simon@heistermann-solutions.de
Get it for free
Enter your email address. You'll immediately receive a confirmation link - after clicking it the checklist is available right away.
Let's talk about your project
Free introductory call