Technical GDPR Audit
GDPR check for your website - cookies, tracking and consent done right.
If your visitors come from the EU, your tracking probably fires before consent - and your analytics is probably less reliable than you think. We audit the entire technical layer: scripts, cookies, consent flows, third-party services and data flows. You keep visibility into the business while staying compliant.
What we audit
Five audit layers that become one coherent fix-list.
Cookie inventory
A real, complete cookie audit - first-party, third-party, persistent, session - categorised by purpose and provider.
Consent flow
How consent is requested, recorded, withdrawn and respected. Common failure modes: pre-consent firing, no withdrawal, dark patterns.
Tracking & analytics
Google Analytics 4, Meta Pixel, LinkedIn Insight, hotjar / heatmaps and similar - wired up to consent properly.
Third-party scripts
Embeds, fonts, maps, chat widgets, video players - every script that calls home from your domain reviewed and labelled.
Data flows
Forms, lead capture, CRM and email-platform integrations. Where data goes, who processes it, and what disclosure is needed.
Documentation hooks
A brief that your privacy policy, cookie policy and DPA inventory can be aligned against - without asking your legal team to reverse-engineer the site.
Why it matters
Compliant tracking is also better tracking.
A proper consent setup doesn’t kill analytics - it makes the data you do collect trustworthy. And it removes a class of legal risk that many businesses simply ignore until something goes wrong.
For non-EU businesses serving European clients, this isn’t optional. For DACH-facing companies, it’s the minimum to operate legally.
- Find the scripts firing before consent - and stop them.
- Map every cookie to a purpose and a legal basis.
- Tighten consent UX so it isn’t a dark pattern, but isn’t a friction wall either.
- Get analytics that’s consented, accurate and explainable.
- Hand legal a brief they can actually use.
What gets surfaced - typical findings
The eight failure modes we see in nearly every audit.
After dozens of websites, the pattern is depressingly stable. None of these are theoretical risks - they are the issues that have already cost real DACH businesses real money in cease-and-desist letters, fines and lost rankings.
1. Google Fonts loaded externally
A 2022 LG Munich ruling made this a documented EUR 100/case fine risk. We still find it on roughly half the sites we audit. Fix: self-host the font files; one-time CSS swap.
2. Analytics fires before consent
GA4 is loaded directly in <head>, not gated by the consent layer. Every visitor is tracked before they have a chance to refuse. The data isn’t even legally usable.
3. Maps / video embeds load on page-view
Google Maps and YouTube embeds set cookies and transmit IPs the moment the page renders. Both must sit behind explicit consent or be replaced with click-to-load placeholders.
4. Consent layer that doesn’t actually gate
A common pattern: a banner that looks compliant but loads scripts before "Accept" is clicked, or doesn’t honour withdrawal. The legal status equals having no banner at all.
5. Contact-form sender mismatch
Form goes to a personal Gmail, the privacy policy names a different processor, the Impressum lists a third address. We see all three diverging on the same site routinely.
6. Faulty or missing Impressum
DE/AT requires a complete Impressum with real legal entity, person, address, contact, registry numbers and VAT-ID where applicable. Missing fields are a §5 TMG violation - cease-and-desist territory. Quick self-check with our free Impressum generator.
7. Cookie banner with no withdrawal path
If a visitor can’t change their mind without clearing cookies manually, the consent isn’t valid. We check that "withdraw consent" is reachable in two clicks, on every page.
8. Third-party scripts no one remembers adding
Marketing pixels from old campaigns, A/B-test snippets from a tool no longer in use, chat widgets from a discontinued vendor. Each one is a data leak with no business value left.
FAQ
Frequently asked questions.
If you serve EU/EEA visitors, customers or users, the GDPR applies - regardless of where your business is registered. Most non-EU companies with European clients are within scope.
No. We audit the technical implementation: cookies, consent flows, third-party scripts, tracking, data flows. We coordinate with your legal counsel on policy wording - we don’t replace it.
Yes - better, in fact. Properly consented analytics is more reliable than half-broken tracking that fires before consent. We help you keep visibility while staying compliant.
Yes, optionally. Many clients implement themselves; others ask us to deliver the fixes alongside the audit. Both work.
Who runs the GDPR audit
Patrick Sosath, founder & strategist.
Trained IT business specialist, Management & Technology at OTH Regensburg. Career background in B2B software at Cubefinity GmbH and Step Ahead AG.
We do the GDPR audit personally. Compliance work handled by the same team that also builds websites gives you something rare: a technical read that understands what’s actually fixable in a day versus what needs a vendor change.
Get the audit
Send us your URL. We’ll send back a fixed scope.
If you’d rather start broader, a Clarity Session is the right entry point - we cover GDPR red flags as part of the technical lens.
Get in touch
Send us a quick message.
Two-line brief, real reply within a working day. Or use the full enquiry form on the contact page.