Since the GDPR (General Data Protection Regulation), running a website in Europe comes with privacy obligations – and ignoring them risks warnings, fines and trouble with regulators. For SMBs this is often a blind spot: the website was set up once and runs – but whether it is actually compliant, no one really knows.
Here are the nine most common GDPR mistakes on small and mid-sized business websites – and how to fix them quickly.
Note: this article is not legal advice. For specific legal questions consult a specialist data-protection lawyer. The measures described here are technical and organisational recommendations based on current best practice.
Google Fonts loaded via external servers
The problem: many websites embed Google Fonts directly via Google servers (fonts.googleapis.com). The visitor's IP is sent to Google – without consent. According to several German court rulings this is a GDPR violation. Mass warning letters have already hit many SMBs.
The fix: embed Google Fonts locally (store them on your own server). Then no IP leaves your site. The fonts look identical.
Cookie banner missing or wrongly configured
The problem: tracking, marketing or analytics cookies may only be set after active consent. A cookie banner that defaults to "accept all" or only offers one option is unlawful.
The fix: a legally compliant consent management tool (e.g. Cookiebot, Usercentrics, borlabs Cookie) with clear opt-in logic. Important: technically necessary cookies don't need consent.
Missing or outdated privacy policy
The problem: the GDPR requires a complete privacy policy that describes every processing activity: contact form, cookies, analytics, hosting provider, newsletter, ordering systems. Not having one – or using a 2018 version – violates the GDPR.
The fix: a current, complete privacy policy – ideally reviewed by a data-protection lawyer or built and kept current with a serious generator like activeMind Legal or Dr. Schwenke.
Google Analytics without proper integration
The problem: Google Analytics (and GA4) transfers data to the US. After the Schrems II ruling this is critical. In addition, its use must be declared in the cookie banner and made dependent on consent.
The fix: either correct integration with consent management and IP anonymisation – or switch to a GDPR-friendly alternative like Matomo (self-hosted) or Plausible Analytics (EU servers).
No data processing agreement (DPA) with the host
The problem: running your website on a hosting provider means data (visitor IPs, log files) is processed on your behalf. The GDPR requires a DPA. Many companies never signed one.
The fix: sign a DPA with your hosting provider. All reputable German providers (IONOS, Hetzner, Strato, etc.) offer one – often online in a few clicks.
Contact form without a privacy notice
The problem: if you collect personal data through a form (name, email, phone) you must inform users how it will be used. A simple form without a privacy notice and checkbox is non-compliant.
The fix: under every form: link to your privacy policy, brief information about the use of the data, possibly a checkbox with an opt-in. Store data only as long as necessary.
Embedded YouTube videos without consent
The problem: standard YouTube embeds set cookies the moment the page loads – regardless of whether the user clicks play. Without consent that's not allowed.
The fix: use YouTube's "privacy-enhanced mode" (youtube-nocookie.com) or load videos only after a click (click-to-play). Alternatively: self-host the videos or use compliant hosting like Vimeo (with a DPA).
Hosting on US servers without safeguards
The problem: many cheap hosts (GoDaddy, Cloudflare, certain AWS configurations) process data in the US. After Schrems II this is only allowed under strict conditions – which many fail to meet.
The fix: move to a German or European host with a DPA and a clear EU data-processing guarantee (IONOS, Hetzner, netcup, Strato). Alternatively: Cloudflare with EU server configuration and a proper DPA.
Missing or wrong imprint
The problem: not GDPR but almost as important: the imprint. Mandatory contents are: full name/company, address, phone, email, possibly company register number, VAT ID, responsible person. Violations can be pursued with warning letters.
The fix: fill the imprint completely, reachable in at most two clicks from any page. Check it regularly (e.g. after a move or change of legal form).
GDPR quick check: self-test for your website
- Google Fonts hosted locally (not via googleapis.com)?
- Cookie banner with opt-in logic (no pre-selected "accept all")?
- Privacy policy current, complete and reachable from every page?
- Google Analytics (if used) only active after consent?
- DPA signed with your hosting provider?
- Contact form has a privacy notice?
- YouTube videos without automatic cookies?
- Hosting on EU servers or with sufficient safeguards?
- Imprint complete, correct and easy to find?
If you can answer yes to all nine: congratulations! Your website privacy is at a solid level. If not: the sooner you act, the better. Most points can be fixed in a few hours.
Conclusion
GDPR compliance is not a one-off project – it must be reviewed and adjusted continuously when case law, tools or your website change. For SMBs without an internal IT department or DPO we recommend: pick a trustworthy web partner who designs with GDPR from day one, and consult a data-protection lawyer for specific questions.
At Klarspur, GDPR compliance is not an add-on – it is the standard. Every site we build is hosted on German servers, with proper cookie management, locally hosted fonts and full documentation.
