Skip to content
Fixed price from 390 € – no subscription lock-in
Law & data protection

GDPR Basics for the Small Website

Set up legal notice, privacy, cookies and forms compliantly: how small businesses, clubs and freelancers start without warning-letter risk.

12 min read DSGVODatenschutzImpressumRecht

Having a website is standard today for small businesses, clubs and the self-employed – and it comes with legal duties that many underestimate. A legal notice, a privacy policy, cookie consent and secure forms are not optional extras but legally required. Ignoring them risks warning letters, claims for damages and, in serious cases, fines. In 2024 alone, around 1.2 billion euros (DLA Piper) in GDPR fines were imposed across Europe, and since May 2018 penalties total 5.88 billion euros (DLA Piper). The good news: for a small, clearly structured website, a legally sound basis is achievable with manageable effort – if you think through the four core areas from the start instead of fixing them later at cost. This guide explains what matters in plain language, without legal jargon. It does not replace individual legal advice, but it lays the foundation to launch your fixed-price website cleanly and without unnecessary risk.

A legally sound basis for the small websiteThe four building blocks1Legal noticeprovider details,complete and easy to find2Privacy policyexplains which datais processed and why3Cookies & consentonly with consent,reject as easy as accept4Formsencrypted, data-minimal,with a privacy noteOnline without warning-letter risk4/4duties coveredlegal notice completeprivacy policy currentcookie banner correctforms encryptedno US services without asking1.2 bneuro GDPR fines in 2024100 €damages in Google Fonts rulingfrom 390euro fixed price incl. legal textsLegal notice + privacy + cookies + formsbuilt in from the start instead of fixed later at cost

Key takeaways

  • Four areas form the legal basis of any small website: legal notice, privacy policy, cookie consent and secure forms.
  • The legal notice is the most common reason for warning letters because it can be checked automatically – completeness and easy findability matter.
  • Cookies and external services may only load after active consent; technically necessary cookies are exempt.
  • Building the duties in from the start is cheaper than expensive retrofitting and clearly lowers the risk of warning letters.

Why legal compliance matters even for small websites

A common misconception is that a small club site or a sole trader's business-card website is too insignificant to attract authorities or warning-letter specialists. The opposite is true. Many obligations apply regardless of company size. The cookie rules under Section 25 TDDDG, for example, apply to every provider of telemedia – that is, every website using cookies or tracking, from a blog to a small business (Haendlerbund). Small sites in particular often become targets of automated mass warning letters, because formal errors can be detected by machine.

Almost all companies rate the effort for data protection as high: 97 percent (Bitkom) consider it high, and 84 percent (Bitkom) report increased effort since the GDPR came into force. For small organisations without a legal department this is a hurdle – but one that a thoughtful, lean website handles well. Anyone who collects only the data they truly need and avoids questionable third-party services significantly reduces the attack surface. For what a lean yet complete page structure looks like, see our guide to the five most important pages of any website.

Duty, not a nice-to-have

A legal notice and a privacy policy are not optional service pages but legally required. They belong on every commercially or club-operated website from day one – even on a single page without an online shop.

The legal notice, legally the provider identification, is the easiest duty to verify – and precisely for that reason the most common trigger for warning letters (advocado). Specialised law firms and competitors systematically scan websites for missing or incomplete notices (eRecht24). A complete legal notice must be reachable from every page within a few clicks, usually via a clearly labelled link in the footer.

Exactly which details belong in it depends on the legal form. For most small providers the core items are: full name or company name, a postal address where documents can be served (no PO box), a quick means of contact such as email and phone, the register and registration number for registered entities, and where applicable the VAT identification number. Clubs name the board, regulated professions add chamber and supervisory details.

Who runs the site

Full name or company name; for clubs, the authorised board. Anonymous business presences are not permitted.

Serviceable address

A real address where mail can be delivered. A mere PO box is not enough for provider identification.

Quick contact channels

At least email and usually phone, so visitors and authorities can make contact directly.

Register and tax

For registered entities, the commercial or club register plus number, and the VAT ID where applicable.

Profession-specific details

Regulated professions such as health practitioners name the responsible chamber, job title and relevant professional rules.

Easy to find

A clearly labelled link reachable from every subpage within a few clicks – typically placed in the footer.

Keeping it current matters: if the business moves or changes legal form, the legal notice must follow. With a fixed-price website, a properly set up, complete legal notice is part of the scope from the start – as is the permanently reachable footer link. For which other pages count as essential, read our article on the five most important pages of any company website.

Building block 2: Setting up an understandable privacy policy

As soon as a website processes personal data – which begins with the very first page load, since a visitor's IP address is involved – it needs a privacy policy under the GDPR. This transparently explains which data is processed for which purpose and on what legal basis, how long it is stored, and what rights data subjects have, such as access, correction and erasure.

For a small website the privacy policy is usually manageable if you stick to the essentials. Typical points are: access via server log files, the contact form, possibly a newsletter, embedded fonts, maps or videos, plus hosting and where applicable reach measurement. The decisive thing is that the policy matches exactly what the site actually does. A generic template that lists services not in use – or conversely hides services that are used – creates more risk than security.

  • Which data is processed on a mere page load (server log files, IP address)?
  • Which forms exist and which fields are truly necessary?
  • Are external services embedded (fonts, maps, videos, reach measurement)?
  • Where is the hosting located and is there a data processing agreement for it?
  • Are the data subject rights and a point of contact clearly named?
  • Does the policy match exactly the site's actual functionality?

Beware US services without consent

If external content such as fonts or maps loads directly from servers outside the EU, visitor data flows there – often without anyone noticing. Such embeds should be reviewed and, in doubt, hosted locally or loaded only after consent. This is exactly where entire waves of warning letters arose in the past.

Building block 3: Implementing cookies and consent correctly

Under Section 25 TDDDG, cookies and comparable technologies may only access the visitor's device once they have actively consented. Technically necessary cookies, for example for login or shopping cart, are exempt (Cortina Consult). The former TTDSG was renamed to TDDDG on 13 May 2024 (Cortina Consult), while the cookie rules of Section 25 remained unchanged in substance. In practice this means: anyone using reach measurement, maps, embedded videos or fonts from third-party servers generally needs a consent banner.

A compliant banner has to meet certain conditions. Rejecting must be just as easy as accepting – already on the first level, without hidden submenus. Pre-ticked boxes are not permitted, and non-essential services may only load after consent, not beforehand in the background. The simplest and safest option for a small website is often to do without consent-requiring third-party services entirely and to handle fonts, maps or statistics in a data-minimal or local way. Then a slim notice is often enough instead of a complex banner.

AspectRisky implementationCompliant implementation
Loading external servicesImmediately on page loadOnly after active consent
Reject optionHidden or several clicks deepEqual on the first level
Default settingBox ticked in advanceNo preselection, opt-in
Fonts and mapsDirectly from third-party serverHosted locally or after consent
Effort for the bannerComplex, error-proneSlim, because little requires consent

Data minimisation beats banner acrobatics

The most reliable path to a cookie-light, compliant site is not the perfect banner but doing without everything that requires consent. A small website often works without tracking and without externally loaded third-party services – which noticeably simplifies data protection and makes the site faster at the same time.

Building block 4: Securing forms and data transfer

On many small websites the contact form is the only place where personal data is actively collected. That is exactly why it deserves special attention. Three principles go a long way: encryption, data minimisation and transparency. Transmission should run over an encrypted connection (HTTPS), so that inputs do not travel across the network in plain text.

Data minimisation means asking only for the fields truly needed to handle the enquiry. A phone number as a mandatory field is rarely necessary if the reply goes by email anyway. Transparency, finally, means a short note at the form that links to the privacy policy and explains what the data is used for. A checkbox to be actively ticked only makes sense where it is genuinely needed – a plain note is enough in many standard cases.

Encrypted transmission

Send form data exclusively over HTTPS. A valid certificate is part of our fixed-price website.

Only necessary fields

Ask sparingly: name and message are often enough. Every extra mandatory field raises the data protection effort.

Clear privacy note

A short sentence at the form linking to the privacy policy creates transparency for visitors.

Processing in the EU

Email dispatch and data storage preferably in Germany or the EU, with a matching data processing agreement.

Spam protection

Simple, data-minimal spam defence instead of questionable third-party services that send extra data to external servers.

Deletion concept

Do not keep enquiries forever. Regular clean-up keeps the data volume and therefore the risk low.

Hosting in Germany lowers the effort

Hosting the website and form dispatch in Germany or the EU avoids the tricky questions around data transfers to third countries. Our fixed-price packages include hosting in Germany – one less building block for you to worry about.

Avoiding warning letters: what really lowers the risk

The best-known wave of warning letters in recent years concerned embedded fonts loaded directly from a US server. A court awarded an affected person 100 euros (Munich Regional Court / heise) in damages because their IP address had been transmitted without consent. Law firms then sent out warning letters en masse, with claims usually between 150 and 500 euros (heise). Later decisions classified deliberately provoking such violations as an abuse of rights (Munich Regional Court / shopbetreiber-blog) – but the underlying problem remains: anyone who carelessly embeds third-party services makes themselves vulnerable.

The most effective prevention is unspectacular. A lean, data-minimal site without unnecessary external embeds offers little attack surface. Add a complete legal notice, a privacy policy matching the site, correct consent behaviour and secure forms. This basis covers the most common reasons for warning letters. Data protection is considered the biggest obstacle to digitalisation – 77 percent (Bitkom) of companies name it as a hurdle – yet for a small website it is manageable if the site is built cleanly from the start.

  • Legal notice complete, current and reachable from the footer of every page.
  • Privacy policy matches the site's actual functionality exactly.
  • No consent-requiring third-party services load before consent.
  • Cookie banner with an equal reject option on the first level – or no banner needed at all.
  • Forms encrypted, data-minimal and with a privacy note.
  • Hosting and data processing in Germany or the EU.

Cost plays into this too: a site set up to be compliant from the start is cheaper than expensive retrofitting under time pressure after a warning letter. How fixed price and hourly rate differ here is explained in our article on website costs between fixed price and hourly rate. With a fixed price, the legal texts and their clean integration are planned in from the outset.

Legal compliance does not come from the one perfect banner, but from a site that from the start does only what it really needs – and makes that transparent.

Guiding principle for compliant small websites

One more note on the wider picture: in Germany around 69 percent (Federal Statistical Office) of companies most recently had their own website, so almost a third did not yet. Anyone starting now can get the legal foundations right from the beginning, instead of laboriously retrofitting a grown, cluttered site. A lean fixed-price website is made exactly for this – a good moment to look at our services at a glance.

This article is based on data from: DLA Piper (GDPR fines study 2024), Bitkom (data protection effort and obstacles to digitalisation), Cortina Consult (TDDDG and cookie consent under Section 25), Haendlerbund and eRecht24 (cookie and legal notice duties), advocado (warning letters over the legal notice), Munich Regional Court / heise online and shopbetreiber-blog (Google Fonts ruling and warning-letter wave) as well as the Federal Statistical Office (share of companies with a website). This article is general information and does not replace individual legal advice.

Related Articles