🔍

GDPR Website Check – Findings Explained

What do the indicators in the scan result mean?

The GDPR Website Check automatically analyses websites for data protection-relevant characteristics. Results are displayed as colour-coded indicators. This page explains what each indicator means and what consequences may follow.

Important: An automated check cannot replace legal advice and provides hints that require manual review by a qualified professional.

📋 Indicators in Detail
🍪
Cookies

Cookies are small data packets that a website stores in the visitor's browser. Technically necessary cookies (e.g. for login or shopping cart) are permitted without consent. Marketing and tracking cookies, however, require an active, voluntary consent from the user.

Green – No cookies found, or only technically necessary, non-critical cookies detected.
Yellow – Potentially critical cookies found. Further investigation is needed to conclusively assess the consent requirement.
Red – Cookies are set before or without consent, even though a consent requirement is likely.
⚙️
Unsafe Tools

Plugins, scripts, and embedded services that may transfer data to third countries – particularly the USA – are classified as "unsafe tools". Whether such a data transfer is permissible depends largely on whether the respective provider is certified under the EU-US Data Privacy Framework (EU-US DPF).

Non-certified providers cannot be used in a legally compliant manner without appropriate safeguards (e.g. Standard Contractual Clauses). Individual review is recommended in every case.
Yellow – Tools found that may cause US data transfers. Further investigation regarding DPF certification and contractual basis is required.
Red – Tools found for which no sufficient legal basis for the data transfer is identifiable.
🚨
Critical Tools

Critical tools are plugins, scripts, and services that must not be used without the prior, explicit consent of users. These typically include analytics, advertising, and social media services that collect or process personal data.

Merely embedding such a script – even without active use – may already constitute a data protection violation if no valid consent has been obtained.
Red – Consent-required tools were found without a recognisable consent solution (e.g. cookie banner).
📄
Availability of Privacy Policy

Under the GDPR (Art. 13/14), privacy notices must be easily accessible to users at all times and from every sub-page of the website. The check verifies whether a corresponding link is present and reachable.

Green – Privacy policy is linked and accessible.
Red – The privacy policy may not be linked or accessible from every page. Further investigation required.
🔗
External Files

When loading a webpage, resources (images, scripts, fonts, etc.) may be fetched from external servers. This is relevant under data protection law, as the visitor's IP address is transmitted to third-party servers in the process.

Files are listed that:

  • could not be assigned to the site's own top-level domain or a known, classified service,
  • are loaded from subdomains of the checked website (these may be own servers, but also third-party providers).
External resources require a legal basis and should be named in the privacy policy. Unknown third-party sources should be examined carefully.
🔵
Google Tools

Google services have their own indicator because they are known to collect particularly extensive user data. Cookies on general Google domains (e.g. google.de, google.com) are especially critical, as their behaviour depends on the visitor's browsing history – the website operator has no full control or transparency over this.

Google is also certified under the EU-US DPF; however, the data-protection-compliant integration of many Google services (in particular Google Analytics, Google Ads, Google Fonts via CDN) remains legally contested. A consent solution is generally required.
👁️
Tracking

Tracking scripts monitor the behaviour of website visitors across page views, clicks, scroll activity, or across devices. Regardless of whether cookies are used, a consent requirement must be assumed.

Typical examples include: analytics services (e.g. Matomo without anonymisation, Hotjar), retargeting pixels (e.g. Meta Pixel, LinkedIn Insight Tag), or session recording tools.

Using trackers without consent is one of the most common causes of cease-and-desist letters and complaints to data protection authorities.
🔒
SSL / Transport Encryption

SSL/TLS encryption protects the transmission of data between the browser and the web server from eavesdropping and tampering. Art. 32 GDPR requires appropriate technical protective measures – a current, correctly configured HTTPS connection is the minimum standard.

Green – SSL certificate present, valid, redirect to HTTPS working, no issues detected.
Yellow – Encryption strength may be insufficient, or the SSL provider is considered less trustworthy. Depends on configuration – further review recommended.
Red – No valid SSL certificate present, certificate expired, or HTTPS redirect not consistently configured.