The GDPR Website Check automatically analyses websites for data
protection-relevant characteristics. Results are displayed as colour-coded indicators.
This page explains what each indicator means and what consequences may follow.
Important: An automated check cannot replace legal advice and provides
hints that require manual review by a qualified professional.
Cookies are small data packets that a website stores in the visitor's browser. Technically necessary cookies (e.g. for login or shopping cart) are permitted without consent. Marketing and tracking cookies, however, require an active, voluntary consent from the user.
Plugins, scripts, and embedded services that may transfer data to third countries – particularly the USA – are classified as "unsafe tools". Whether such a data transfer is permissible depends largely on whether the respective provider is certified under the EU-US Data Privacy Framework (EU-US DPF).
Critical tools are plugins, scripts, and services that must not be used without the prior, explicit consent of users. These typically include analytics, advertising, and social media services that collect or process personal data.
Under the GDPR (Art. 13/14), privacy notices must be easily accessible to users at all times and from every sub-page of the website. The check verifies whether a corresponding link is present and reachable.
When loading a webpage, resources (images, scripts, fonts, etc.) may be fetched from external servers. This is relevant under data protection law, as the visitor's IP address is transmitted to third-party servers in the process.
Files are listed that:
- could not be assigned to the site's own top-level domain or a known, classified service,
- are loaded from subdomains of the checked website (these may be own servers, but also third-party providers).
Google services have their own indicator because they are known to collect particularly
extensive user data. Cookies on general Google domains (e.g. google.de,
google.com) are especially critical, as their behaviour depends on the
visitor's browsing history – the website operator has no full control or transparency
over this.
Tracking scripts monitor the behaviour of website visitors across page views, clicks, scroll activity, or across devices. Regardless of whether cookies are used, a consent requirement must be assumed.
Typical examples include: analytics services (e.g. Matomo without anonymisation, Hotjar), retargeting pixels (e.g. Meta Pixel, LinkedIn Insight Tag), or session recording tools.
SSL/TLS encryption protects the transmission of data between the browser and the web server from eavesdropping and tampering. Art. 32 GDPR requires appropriate technical protective measures – a current, correctly configured HTTPS connection is the minimum standard.