← Blog|Law & Security11 min read··01

GDPR & website: 9 pitfalls that cost you money.

Cookie banner, Google Fonts, tracking tools, hosting location – the most common mistakes on SMB websites and how to safely avoid warning letters. Includes a self-check list.

Abstract Klarspur brand graphic with a sweeping clear track

Since the GDPR (General Data Protection Regulation), running a website in Europe comes with privacy obligations – and ignoring them risks warnings, fines and trouble with regulators. For SMBs this is often a blind spot: the website was set up once and runs – but whether it is actually compliant, no one really knows.

Here are the nine most common GDPR mistakes on small and mid-sized business websites – and how to fix them quickly.

Note: this article is not legal advice. For specific legal questions consult a specialist data-protection lawyer. The measures described here are technical and organisational recommendations based on current best practice.

Pitfall 01

Google Fonts loaded via external servers

The problem: many websites embed Google Fonts directly via Google servers (fonts.googleapis.com). The visitor's IP is sent to Google – without consent. According to several German court rulings this is a GDPR violation. Mass warning letters have already hit many SMBs.

The fix: embed Google Fonts locally (store them on your own server). Then no IP leaves your site. The fonts look identical.

Pitfall 02

Cookie banner missing or wrongly configured

The problem: tracking, marketing or analytics cookies may only be set after active consent. A cookie banner that defaults to "accept all" or only offers one option is unlawful.

The fix: a legally compliant consent management tool (e.g. Cookiebot, Usercentrics, borlabs Cookie) with clear opt-in logic. Important: technically necessary cookies don't need consent.

Pitfall 03

Missing or outdated privacy policy

The problem: the GDPR requires a complete privacy policy that describes every processing activity: contact form, cookies, analytics, hosting provider, newsletter, ordering systems. Not having one – or using a 2018 version – violates the GDPR.

The fix: a current, complete privacy policy – ideally reviewed by a data-protection lawyer or built and kept current with a serious generator like activeMind Legal or Dr. Schwenke.

Pitfall 04

Google Analytics without proper integration

The problem: Google Analytics (and GA4) transfers data to the US. After the Schrems II ruling this is critical. In addition, its use must be declared in the cookie banner and made dependent on consent.

The fix: either correct integration with consent management and IP anonymisation – or switch to a GDPR-friendly alternative like Matomo (self-hosted) or Plausible Analytics (EU servers).

Pitfall 05

No data processing agreement (DPA) with the host

The problem: running your website on a hosting provider means data (visitor IPs, log files) is processed on your behalf. The GDPR requires a DPA. Many companies never signed one.

The fix: sign a DPA with your hosting provider. All reputable German providers (IONOS, Hetzner, Strato, etc.) offer one – often online in a few clicks.

Pitfall 06

Contact form without a privacy notice

The problem: if you collect personal data through a form (name, email, phone) you must inform users how it will be used. A simple form without a privacy notice and checkbox is non-compliant.

The fix: under every form: link to your privacy policy, brief information about the use of the data, possibly a checkbox with an opt-in. Store data only as long as necessary.

Pitfall 07

Embedded YouTube videos without consent

The problem: standard YouTube embeds set cookies the moment the page loads – regardless of whether the user clicks play. Without consent that's not allowed.

The fix: use YouTube's "privacy-enhanced mode" (youtube-nocookie.com) or load videos only after a click (click-to-play). Alternatively: self-host the videos or use compliant hosting like Vimeo (with a DPA).

Pitfall 08

Hosting on US servers without safeguards

The problem: many cheap hosts (GoDaddy, Cloudflare, certain AWS configurations) process data in the US. After Schrems II this is only allowed under strict conditions – which many fail to meet.

The fix: move to a German or European host with a DPA and a clear EU data-processing guarantee (IONOS, Hetzner, netcup, Strato). Alternatively: Cloudflare with EU server configuration and a proper DPA.

Pitfall 09

Missing or wrong imprint

The problem: not GDPR but almost as important: the imprint. Mandatory contents are: full name/company, address, phone, email, possibly company register number, VAT ID, responsible person. Violations can be pursued with warning letters.

The fix: fill the imprint completely, reachable in at most two clicks from any page. Check it regularly (e.g. after a move or change of legal form).

GDPR quick check: self-test for your website

  • Google Fonts hosted locally (not via googleapis.com)?
  • Cookie banner with opt-in logic (no pre-selected "accept all")?
  • Privacy policy current, complete and reachable from every page?
  • Google Analytics (if used) only active after consent?
  • DPA signed with your hosting provider?
  • Contact form has a privacy notice?
  • YouTube videos without automatic cookies?
  • Hosting on EU servers or with sufficient safeguards?
  • Imprint complete, correct and easy to find?

If you can answer yes to all nine: congratulations! Your website privacy is at a solid level. If not: the sooner you act, the better. Most points can be fixed in a few hours.

Conclusion

GDPR compliance is not a one-off project – it must be reviewed and adjusted continuously when case law, tools or your website change. For SMBs without an internal IT department or DPO we recommend: pick a trustworthy web partner who designs with GDPR from day one, and consult a data-protection lawyer for specific questions.

At Klarspur, GDPR compliance is not an add-on – it is the standard. Every site we build is hosted on German servers, with proper cookie management, locally hosted fonts and full documentation.

And what would this look like in your business?

If you'd like to go through this topic for your own situation: call or write to me. 20–30 minutes, free, no preparation needed – I'll tell you honestly what's worth doing in your case.

Get in touch – no obligation
Related servicesWhat I actually offer on this topic.

More articles