Compliance Series • Post 12/20
GDPR-Compliant Website — the 12 Mandatory Building Blocks for 2026
A GDPR-compliant website requires 12 building blocks: from cookie consent to privacy policy to data processing agreements. The complete checklist with implementation help for SMEs.
TL;DR
- GDPR-Compliant Website — the 12 Mandatory Building Blocks for 2026 — a practical guide for the DACH region.
- Covers "gdpr compliant" with concrete examples.
- Covers "data protection website" with concrete examples.
- At least 2 snippet-bait patterns for better SERP visibility.
A GDPR-compliant website fulfills all requirements of the EU General Data Protection Regulation: transparent data processing, informed consent from users, technical and organizational protective measures and enforceable data subject rights at all times.
The 12 mandatory building blocks of a GDPR-compliant website
- SSL/TLS encryption — HTTPS for all pages, HSTS header set
- Privacy policy — complete, current, easy to understand, in German
- Imprint with GDPR-relevant information — including data protection officer
- Cookie consent — opt-in, granular, documented, revocable
- Data processing agreements (DPA) — for hosting, analytics, newsletter
- Data subject rights — access, rectification, erasure, data portability
- Data minimization — Only collect what is really necessary
- Privacy by Design / by Default — Default settings data protection friendly
- Server location in EU or adequate data protection level — no US hosting without SCC
- Deletion concept — automated deletion periods for all data categories
- Data protection impact assessment (DPIA) — for high-risk processing
- Data protection officer — appointed, accessible, independent
How mekyn.com automatically fulfills 10 of 12 building blocks
mekyn websites are static-first and cookieless — this eliminates the most complex GDPR building blocks:
- No cookie banner needed: Plausible Analytics does not collect personal data — no opt-in required
- No data processors except hosting: Hosting at Hetzner (DE), CDN at Cloudflare (with EU standard contractual clauses)
- Automatic deletion concept: Form data is deleted after 30 days, server logs after 7 days
- Privacy by Design: No tracking IDs, no fingerprinting, no third-party cookies
The remaining two building blocks — imprint and data protection officer — are the operator’s responsibility.
The biggest GDPR mistakes we see
- Google Fonts from CDN: Every page load sends the user’s IP to Google servers in the US. Self-host fonts as
.woff2files. - YouTube embeds without privacy mode: YouTube sets tracking cookies. Use
youtube-nocookie.comor lazy-load after consent. - Google Analytics without consent: GA4 is still personal data processing. Use cookieless alternatives or get explicit consent.
- Missing data processing agreements: Every service that processes user data needs a DPA. Hosting, email, analytics — all of it.
- Privacy policy copied from competitors: Copyright violation plus potentially wrong information. Write your own or use a generator.
Server location: Why it matters
The server location determines which jurisdiction applies. For GDPR compliance:
- EU servers: GDPR applies directly. No additional measures needed.
- US servers: Schrems II ruling invalidated Privacy Shield. Standard Contractual Clauses (SCC) required, plus additional technical measures.
- Other third countries: Adequacy decision by EU Commission required, or SCC + technical measures.
mekyn hosting is exclusively in Germany (Hetzner) with Cloudflare CDN (EU data centers for European customers). This eliminates the Schrems II problem entirely.
When you need a data protection officer
A data protection officer is mandatory under GDPR Art. 37 when:
- Public authority: Government agencies always need one.
- Systematic monitoring: Core business involves regular, systematic monitoring of individuals (e.g., tracking, profiling).
- Special categories: Core business involves processing sensitive data (health, religion, political views) on a large scale.
- 20+ employees: In Germany, companies with 20+ employees involved in automated data processing typically need one.
For most SMEs with a simple marketing website, a data protection officer is not mandatory — but having an external consultant on call is good practice.
Frequently Asked Questions
What does a GDPR-compliant website need?
12 mandatory building blocks: SSL encryption, privacy policy, imprint, cookie consent, data processing agreements, data subject rights, data minimization, privacy by design, correct server location choice, deletion concept, DPIA where necessary and a data protection officer.
Do I need a cookie banner?
Yes, if your website uses tracking cookies or third-party services that process personal data. Cookieless analytics (Plausible, Umami) does not require a banner.
What does GDPR compliance cost?
Initial: €500–2,000 for legal advice and technical implementation. Ongoing: €50–200/month for data protection officer and monitoring.
Further reading on mekyn.com
→ Pillar page: GDPR → Related: The BFSG Explained → Related: GDPR Cookie Banner (German) → Tool: Contrast Checker (German)
External sources:
No credit card · 14-day trial · Anti-lock-in