Compliance
GDPR Mistakes on Websites: These 8 Issues Can Lead to Legal Action
These 8 GDPR mistakes are common on SME websites and can trigger legal warnings. With a real example from a trade company.
More than five years after the GDPR came into force, many SME websites are still not correctly set up. That is not a minor issue: a review of 949 websites by Germany's consumer protection organisation found that one in ten cookie banners was unlawful - leading to 98 formal legal warnings from that review alone. Across Europe, approximately 1.2 billion euros in GDPR fines were imposed in 2024 (DLA Piper, 2025).
For SME owners, it is rarely high-profile data scandals that cause problems. It is the everyday technical errors on their own website - often built in during the original launch and left untouched since. Germany has established particularly strict GDPR enforcement standards, and rulings from German courts are frequently referenced by regulators and practitioners elsewhere in the EU.
This article identifies the eight most common ones. Directly, without legal jargon, with a clear explanation of the risk involved and what to do about it.
Note: This article describes common technical errors on websites in relation to data protection law. It does not constitute legal advice. For legal matters, please consult a qualified data protection lawyer.
Mistake 1: No Equivalent Reject Button on the Cookie Banner
This is the most frequent error - and since a ruling by the Administrative Court of Hanover in March 2025, the legal position is unambiguous: if an "Accept" button appears on the first layer of a cookie banner, an equivalent "Decline" button must appear on the same layer. A hidden "continue without consent" option buried in small print is not sufficient.
Many banners are designed to make declining unnecessarily difficult - multiple clicks, hard-to-read text, pre-ticked boxes. These are so-called dark patterns. They do not generate valid consent under GDPR and are subject to enforcement.
What to do: Have the cookie banner reviewed for equal prominence of accept and decline options. If "Accept" is more visible or accessible than "Decline", the banner is non-compliant.
Mistake 2: Google Fonts Loaded Directly from Google's Servers
This is one of the most underestimated errors. Many websites embed Google Fonts - typefaces - via a direct link to Google's servers. With each page visit, the visitor's IP address is automatically transmitted to Google's servers, without the user having consented to this.
The Regional Court of Munich ruled in 2022 that this practice violates GDPR without prior consent. e-recht24 has documented the ruling and its consequences in detail. Since then, there have been documented waves of legal warnings targeting website operators.
What to do: Host Google Fonts locally on your own server rather than loading them from an external source. This is technically straightforward - but the error must first be identified.
Mistake 3: Missing or Incomplete Legal Notice (Impressum)
A legal notice (Impressum) is mandatory for all commercial websites in Germany and Austria, without exception. This is a specific requirement under the German DDG (Digitale-Dienste-Gesetz, §5) - the law that replaced the former Telemedia Act (TMG) in 2024. Austria has an equivalent provision. Neither has a direct equivalent in UK or US law, which makes it an easy oversight for internationally operating businesses.
Common issues: missing required information such as the VAT registration number where applicable, the responsible supervisory authority for regulated professions, or a directly visible email address. The legal notice must also be reachable in no more than two clicks from any page on the site. A missing or incomplete legal notice is actionable and is a frequent basis for legal warnings by competitors.
What to do: Check the legal notice using our free Impressum generator (German) or with a lawyer. Pay particular attention to completeness of required details and accessibility from all pages.
Mistake 4: No SSL Certificate or Inconsistent HTTPS Use
Websites that operate contact forms, login areas or other data inputs without SSL encryption transmit that data unencrypted - violating GDPR's requirement for appropriate technical security measures (Art. 32 GDPR).
Although SSL certificates are now available cheaply or free of charge (for example via Let's Encrypt), websites running on HTTP rather than HTTPS still exist, as do websites where individual subpages are served without encryption.
What to do: Check that the entire website is consistently accessible over HTTPS. The browser address bar shows a padlock symbol when encrypted. No padlock or a security warning means action is required.
Mistake 5: Outdated Privacy Policy
The privacy policy must list all services, tools and third-party providers in use on the website. For most SME websites, this was drafted once - and has not been updated since, despite additional plugins, changed analytics tools or modified contact forms.
A privacy policy that does not accurately reflect the data processing activities on the website is a clear GDPR violation.
What to do: Compare the privacy policy against all currently active services. Common gaps: Google Analytics, contact form plugins, embedded YouTube videos, WhatsApp widgets, newsletter tools.
Mistake 6: Contact Forms Without a Privacy Notice
Any contact form on a website collects personal data. The user must be informed before submitting what will happen with their data - and who is responsible for it.
A simple reference such as "Your data will be processed in accordance with our privacy policy" with a link to that policy is the minimum requirement. A pre-ticked checkbox or the complete absence of any notice is not sufficient.
What to do: Check every form: is there a privacy notice directly visible near the form, with a link to the full privacy policy?
Mistake 7: Tracking Fires Before Consent Is Given
Google Analytics 4 and similar tracking tools may only become active after the user has given explicit consent. This has been legally clear for years and is technically implementable through Google Consent Mode v2.
Despite this, one of the most common errors remains: tracking begins from the first second, before the user has clicked "Accept" - often because the consent management was not configured correctly or the Tag Manager was implemented without consent conditions.
The Administrative Court of Hanover also confirmed in 2025 that the Google Tag Manager itself requires consent when it triggers cookies or trackers.
What to do: Have it technically verified that tracking tools only fire after consent has been granted. This requires a correct implementation of Consent Mode and a clean Tag Manager configuration.
Mistake 8: Social Media Embeds Transmit Data on First Page Load
An embedded Instagram feed or a Facebook like button on a website looks harmless. Technically, it transmits data to Meta the moment the page is loaded - regardless of whether the user interacts with the element.
Without prior consent, this is not permissible. The clean solution is either a two-click approach or embedding via a privacy-compliant service that only loads after consent has been given.
What to do: Remove social media embeds, replace them with static screenshots, or implement a two-click approach that only establishes connections to third-party servers after active user confirmation.
Real Example: What We Found at a Trade Business
At a client from the trades sector - an electrical company with a website that had been in place for years - we identified exactly these errors during a technical GDPR audit: Google Fonts loaded from external servers, a cookie banner without a decline option on the first layer, tracking running without proper consent configuration, and a privacy policy that made no mention of the contact form plugin in active use.
Every single one of these issues was fixable. None was intentional. They arose simply because the website was set up once and never systematically reviewed again.
Alongside the GDPR corrections, we rebuilt the entire SEO structure from scratch. The result after ten months: from 8 to 87 organic clicks per month, from 400 to over 3,100 impressions.
What You Should Do Now
The good news: all eight mistakes are fixable. The less good news: they do not resolve themselves, and a legal warning rarely comes with advance notice.
A structured website review identifies technical GDPR issues before someone else does. If you would like to know how your website stands on these points, we are happy to look at this together.
Data protection is not the only new obligation either: since June 2025, the BFSG website requirements also create accessibility duties for many German business websites.
Note: For legal protection, we recommend additionally consulting a lawyer specialised in data protection law. We handle the technical side - the legal review is the responsibility of qualified legal counsel.
Yes. GDPR applies to all organisations that process personal data of EU residents, regardless of company size or sector. As soon as your website has a contact form, Google Analytics or a cookie banner, you are processing personal data and GDPR applies.
It varies considerably. Legal warnings issued by competitors or consumer associations typically include costs of between 500 and over 2,000 euros, plus an injunction to cease the infringing practice. Regulatory fines under GDPR can reach up to 20 million euros or 4% of global annual turnover - in practice, fines for SMEs tend to fall in the four to five-figure range.
A cookie banner is necessary, but far from sufficient. Compliance also requires an up-to-date privacy policy, a complete legal notice (Impressum), no tracking before consent, locally hosted external resources such as fonts, and privacy notices on all forms. The banner is the most visible element - but not the only one.
A first indicator is the browser developer tools (F12, Network tab): if the page loads external resources such as Google domains, Facebook or YouTube on the very first visit before anything is accepted, that is a clear signal. For a full assessment, a structured technical review is the reliable approach - this is also one of the services seosath provides as part of a website audit.
Sources:
- vzbv.de: Review of 949 websites, one in ten banners unlawful, 98 legal warnings issued (2021)
- DLA Piper: 1.2 billion euros in GDPR fines across Europe in 2024 (January 2025)
- VG Hannover, March 2025: equivalent decline button mandatory on first layer
- VG Hannover, 2025: Google Tag Manager itself requires consent
- e-recht24.de: Regional Court of Munich 2022, Google Fonts without consent constitutes GDPR violation
- DDG §5 (legal notice obligation); TDDDG §25 (consent requirement for cookies and trackers)
- Fine ranges: TDDDG up to 300,000 €; GDPR up to 20 million € or 4% of global annual turnover
Get in touch
Send us a quick message.
Two-line brief, real reply within a working day. Or use the full enquiry form on the contact page.