GDPR Website Check

Your website is visible to everyone, including the supervisory authorities.

Finding your way around the complex world of data protection regulations can be overwhelming, especially when it comes to your online presence. That’s why we offer a comprehensive GDPR website check to ensure that your website is compliant with the General Data Protection Regulation (GDPR) and other relevant laws such as the Telecommunications-Digital Services-Data Protection Act (TDDDG) in Germany it is compliant.

GDPR Website Check
ISO 9001
BvD member
GDD member
Made in Germany
20 years of experience
  • Federal Office for Information Security
  • Compliant with GDPR
  • BvD member
  • GDD member
  • Made in Germany

✓ ISO 9001 certified

✓ on the market since 2003 ✓ from Berlin, active throughout Germany
Our website check

Meet your accountability obligations with the GDPR Website Check.


We offer you two different GDPR website checks that are carefully and manually created and take into account the privacy regulations applicable to your website.

Automated scanning often isn't enough Automated tools are limited and often not sufficient to verify your website’s compliance with data protection regulations. Many cookies can only be verified manually, as they are only activated after user interaction. Also, verifying legal information and compliance requirements requires human review.
Structured towards the goal

Through a structured report, you will receive a detailed overview of all relevant audit aspects that are specific to your website. Additionally, you will receive concrete recommendations for implementation so that your website complies with data protection regulations.

The packages

Two checks, tailored to your needs.

Both the BASIS and PLUS checks provide a clear and comprehensive report that provides you with detailed insights into the privacy status of your website.

Website Check BASIS

Recording and evaluating compliance with data protection regulations on your website, with concrete recommendations for implementation.

from

299€

  • Checking the data processing that takes place automatically when building the website (encryption, referrer, third-party requests)
  • Testing the technologies used to store and retrieve data on end devices and required for this. Testing the requirements for the design, functionality, and information obligations of cookie banners.
  • Checking the requirements for the design, functionality, and information obligations of web forms
  • Checking the requirements for the privacy information and the imprint

Website Check PLUS

Popular

All the services of the Website Check BASIS are also included in the PLUS package.

from

499€

  • Website Check BASIS
  • PLUS individual recommendation for cookie banners and web forms
  • PLUS Adaptation of the privacy information
  • Upon request: Examination of online shops

Additionally included in the PLUS check

Flexible addition – suitable for every package.

Consent management

Guidelines for consent management for all cookies and similar technologies such as web storage (design and functionality of the cookie banner, information obligation).

Web forms

Creation of data protection-compliant templates for newsletter forms, contact forms, and logins.

Data protection information

Adaptation or creation of the privacy information to fulfill the information obligations.

Upon request: Online shop

Checking the data protection requirements for online stores, including implementation guidelines.

* Depending on the scope of the website (number of sub-pages and technologies used). Contact us for a non-binding request.

The report

Meet your accountability obligations with the GDPR Website Check Report

It doesn't matter whether your company runs a purely informational website, a platform, or an online store. Our report evaluates all aspects that are relevant to the GDPR and other relevant laws.

Accountability is a general principle that GDPR requires organizations to take appropriate technical and organizational measures and to be able to demonstrate, upon request, what they have done and to prove the effectiveness of their actions. This accountability leads to a documentation obligation. According to this, it must be documented in an appropriate manner which data are processed in which manner, for what purpose and for how long. Furthermore, the responsible entity, in this case your company, must document which technical measures have been taken to comply with data protection regulations.

The GDPR Website Check Report makes an important contribution to the documentation requirement. Furthermore, our report serves both internal reporting and external management (e.g., web agencies).

Insight

Here you can find excerpts from our GDPR website check

Three pages from an anonymized sample report – so you can see what you’ll get before you commit.

Summary

Test subject, test result, and tested sections at a glance

Cookies in detail

Each cookie found is evaluated individually, with purpose, duration, and recommendations for action.

Concrete implementation

Commented screenshots with ready-made phrasing suggestions to adopt.

20+

With more than 20 years of experience in data protection in various industries, we offer transparency as well as relevant and certified expertise.

Frequently asked questions about the GDPR Website Check

What is checked during the GDPR website check?

Everything that flows into your website when you visit it is being examined: automatically triggered processing, encryption, requests to third parties, and the behavior of the referrer; embedded analytics tools; maps, video, and chat; cookies and comparable technologies, including web storage, cookie banners, and consent management; all forms; and privacy information and contact details.


What do I get as a result?

You will receive a report that individually evaluates each aspect of the audit and provides a specific implementation recommendation for each finding. Upon request, we will also create or revise privacy information and form texts, and provide templates for the banner configuration and consent texts.


Do analysis, mapping, or video services require consent?

As a rule, yes. Services that are not technically necessary to provide the website you request are only allowed to be loaded after obtaining valid consent. The decisive factor here is not the service itself, but how it is integrated. We examine this in detail when assessing the specific structure of your page.

What does the TDDDG regulate in addition to the GDPR?

The General Data Protection Regulation (GDPR) regulates the processing of personal data. The Telecommunications Digital Services Data Protection Act (TDDDG) also regulates the storage of information on end devices and access to it, i.e., cookies and similar technologies, even without personal reference. Both regulations overlap in a website context.


How often should a website be audited?

There is no fixed deadline. It is useful to conduct a review after each major change: new theme, new plugin, new shop, new tracking, and more regularly thereafter. We offer a review after implementation, or on request on a recurring basis.


Who is responsible for data protection violations on the website?

The operator of the website is responsible, even if the agency, hoster, or plugin provider caused the error. Therefore, we check the delivered result and not only the settings in the backend. Our ongoing support includes assistance from our External Data Protection Officer, During a deep-level inspection, the Data Protection Audit.

Jan Käding • Senior Consultant

How is your website doing?

Non-binding · 15 minutes · Free

more SERVICES

Data protection services that are available
It fits your company