Zur Hauptnavigation springen Zum Inhalt springen

GDPR-Compliant Websites – Data Protection from the Start

Data protection is not an option, but a legal obligation—and violations of the GDPR can result in hefty fines. NET.THINKS develops GDPR-compliant websites that are designed with data protection in mind from the very beginning: “Privacy by Design” and “Privacy by Default” aren’t just buzzwords for us—they’re standard practice.

From legally compliant cookie consent and GDPR-compliant contact forms to the proper integration of external services such as Google Analytics, YouTube, or Google Maps—we understand the technical requirements and implement them correctly. We work closely with data protection officers and can refer you to experienced GDPR consultants in your region if needed.

Data Protection Implemented Technically

An Overview of Our GDPR Services

An overview of our services for GDPR-compliant websites:

  • Cookie Consent Management: Legally compliant consent management with a data protection-compliant opt-in solution
  • GDPR-Compliant Forms: Encrypted transmission via SSL, data minimization, correct consent texts, and secure data storage
  • Hosting in Germany: Your data remains on German servers—no data transfer to third countries
  • Integrating external services in compliance with data protection regulations: Two-click solutions or server-side proxies for Google Maps, YouTube, Vimeo, and others
  • Privacy Policy: Technical foundations for legally compliant drafting by your attorney or DPO
  • Data Processing Agreement (DPA): We provide you with a DPA for our hosting and support services

Want to make your website GDPR-compliant?

Technical Data Protection – What We Do for You in Practice

Data protection begins at the design stage and extends throughout the entire technical implementation. Here are the most important technical measures we implement to ensure our websites comply with the GDPR:

  • IP anonymization: When using analytics solutions, we automatically anonymize IP addresses
  • Local hosting of fonts: Google Fonts and other external fonts are embedded locally—no data is transferred to Google
  • Data minimization in forms: Only necessary required fields, appropriate retention periods, and secure transmission via SSL
  • Cookie categorization: Clear separation of necessary, functional, and marketing cookies with an opt-in solution
  • Secure integration of external services: YouTube (no-cookie URL), Google Maps (two-click), embedded social media content only after consent
  • Data protection-compliant contact forms: No unencrypted transmission, mandatory consent, clear statement of purpose

Frequently Asked Questions About GDPR-Compliant Websites

  • Is my existing TYPO3 website automatically GDPR-compliant?

    Not necessarily. Many websites have data protection issues despite good intentions: loading Google Fonts directly from Google’s servers, missing or incorrect cookie consent, Google Maps without opt-in, or contact forms without GDPR-compliant consent. We’d be happy to conduct a free quick data protection check of your website and point out specific areas where action is needed.

  • Do I need separate consent for each type of cookie?

    Yes—technically necessary cookies may be set without consent; for all other categories (statistics, marketing, preferences), active user consent is required. The cookie consent tool must be configured so that no non-essential cookies are set before the user has given consent—not even when the page is first loaded.

  • Do you also handle the creation of the privacy policy?

    The privacy policy is a legal document—its preparation is the responsibility of an attorney or data protection officer. However, we provide the complete technical foundation: a list of all tools, cookies, and data transfers used, which your legal advisor will need to draft the policy. Upon request, we can also connect you with an experienced GDPR consultant in your region.