GDPR-Compliant Website — Complete Checklist 2026
The complete GDPR checklist for your website: imprint, privacy policy, cookies, SSL, and more. Avoid fines up to €20 million.
Why GDPR Compliance Matters
The General Data Protection Regulation (GDPR) applies to all websites accessible by EU citizens. Violations can be expensive: fines of up to €20 million or 4% of global annual revenue are possible. Small businesses and freelancers are also affected.
The good news: With the right checklist and a modern website builder like Velo, GDPR compliance is straightforward.
1. Imprint (Legal Notice)
Every business website in Germany must have an imprint (§ 5 TMG). This applies to freelancers, associations, and blogs with advertising revenue.
Your imprint must include: Full name, postal address, email, phone number, VAT ID (if applicable), trade register number.
Important: The imprint must be accessible from every page within 2 clicks. Best linked in the footer.
2. Privacy Policy
The privacy policy is mandatory under Art. 13 GDPR. It must explain in plain language what data you collect and why.
Required content: Who is responsible, what data is collected, why, how long it's stored, third-party sharing, user rights (access, deletion, objection), cookie and tracking details.
3. Cookie Banner
If your website sets non-essential cookies (tracking, marketing), you need a cookie banner with active consent (opt-in).
Requirements: Clear information about cookies, ability to reject categories, no dark patterns, documented consent, withdrawal possible at any time.
Velo solution: Velo doesn't set tracking cookies by default.
4. SSL Encryption
SSL (HTTPS) is mandatory under GDPR whenever you transmit personal data — any contact form, newsletter signup, or login.
Velo solution: Every Velo website gets a free SSL certificate automatically.
5. Data Processing Agreement
If a third party has access to your visitors' personal data (hosting provider, email service, analytics tool), you need a data processing agreement under Art. 28 GDPR.
Velo solution: Velo provides a DPA for all customers. Data is hosted in the EU.
6. EU Hosting
GDPR requires personal data to be processed in the EU — or that an adequate level of protection exists in the third country.
Velo solution: All Velo websites are hosted on servers in Germany.
7. GDPR-Compliant Contact Forms
Contact forms collect personal data and must be GDPR-compliant.
Checklist: Only necessary fields, reference to privacy policy, SSL active, limited data retention.
8. Right to Deletion
Every visitor has the right to request deletion of their data under Art. 17 GDPR. You must respond within one month.
9. Social Media & External Services
When embedding social media buttons, YouTube videos, Google Maps, or fonts, data is often transferred to third parties.
GDPR-compliant approach: Social media links instead of share buttons, YouTube in enhanced privacy mode, host Google Fonts locally.
Velo solution: Velo loads external services in a privacy-friendly way. Fonts are served locally.
10. Fines for Violations
| Violation | Possible Fine |
|---|---|
| Missing imprint | €500 – €50,000 |
| Missing privacy policy | up to €50,000 |
| No SSL with contact form | up to €50,000 |
| Missing cookie consent | up to €300,000 |
| Severe GDPR violations | up to €20 million |
GDPR Checklist
- Imprint present and linked
- Privacy policy present and linked
- SSL certificate active (HTTPS)
- Cookie banner for non-essential cookies
- Data processing agreement with hosting provider
- Hosting in the EU
- Contact forms with privacy notice
- Deletion process for customer data
- Social media privacy-friendly
- No unnecessary data collection
Conclusion
With Velo, the most important technical requirements are already covered: SSL, EU hosting, privacy-friendly external services. You just need to create your imprint and privacy policy content.