Having a website is standard today for small businesses, clubs and the self-employed – and it comes with legal duties that many underestimate. A legal notice, a privacy policy, cookie consent and secure forms are not optional extras but legally required. Ignoring them risks warning letters, claims for damages and, in serious cases, fines. In 2024 alone, around 1.2 billion euros (DLA Piper) in GDPR fines were imposed across Europe, and since May 2018 penalties total 5.88 billion euros (DLA Piper). The good news: for a small, clearly structured website, a legally sound basis is achievable with manageable effort – if you think through the four core areas from the start instead of fixing them later at cost. This guide explains what matters in plain language, without legal jargon. It does not replace individual legal advice, but it lays the foundation to launch your fixed-price website cleanly and without unnecessary risk.
Key takeaways
- Four areas form the legal basis of any small website: legal notice, privacy policy, cookie consent and secure forms.
- The legal notice is the most common reason for warning letters because it can be checked automatically – completeness and easy findability matter.
- Cookies and external services may only load after active consent; technically necessary cookies are exempt.
- Building the duties in from the start is cheaper than expensive retrofitting and clearly lowers the risk of warning letters.
Why legal compliance matters even for small websites
A common misconception is that a small club site or a sole trader's business-card website is too insignificant to attract authorities or warning-letter specialists. The opposite is true. Many obligations apply regardless of company size. The cookie rules under Section 25 TDDDG, for example, apply to every provider of telemedia – that is, every website using cookies or tracking, from a blog to a small business (Haendlerbund). Small sites in particular often become targets of automated mass warning letters, because formal errors can be detected by machine.
Almost all companies rate the effort for data protection as high: 97 percent (Bitkom) consider it high, and 84 percent (Bitkom) report increased effort since the GDPR came into force. For small organisations without a legal department this is a hurdle – but one that a thoughtful, lean website handles well. Anyone who collects only the data they truly need and avoids questionable third-party services significantly reduces the attack surface. For what a lean yet complete page structure looks like, see our guide to the five most important pages of any website.
Duty, not a nice-to-have
Building block 1: The legal notice – a duty and the top warning-letter reason
The legal notice, legally the provider identification, is the easiest duty to verify – and precisely for that reason the most common trigger for warning letters (advocado). Specialised law firms and competitors systematically scan websites for missing or incomplete notices (eRecht24). A complete legal notice must be reachable from every page within a few clicks, usually via a clearly labelled link in the footer.
Exactly which details belong in it depends on the legal form. For most small providers the core items are: full name or company name, a postal address where documents can be served (no PO box), a quick means of contact such as email and phone, the register and registration number for registered entities, and where applicable the VAT identification number. Clubs name the board, regulated professions add chamber and supervisory details.
Who runs the site
Full name or company name; for clubs, the authorised board. Anonymous business presences are not permitted.
Serviceable address
A real address where mail can be delivered. A mere PO box is not enough for provider identification.
Quick contact channels
At least email and usually phone, so visitors and authorities can make contact directly.
Register and tax
For registered entities, the commercial or club register plus number, and the VAT ID where applicable.
Profession-specific details
Regulated professions such as health practitioners name the responsible chamber, job title and relevant professional rules.
Easy to find
A clearly labelled link reachable from every subpage within a few clicks – typically placed in the footer.
Keeping it current matters: if the business moves or changes legal form, the legal notice must follow. With a fixed-price website, a properly set up, complete legal notice is part of the scope from the start – as is the permanently reachable footer link. For which other pages count as essential, read our article on the five most important pages of any company website.
Building block 2: Setting up an understandable privacy policy
As soon as a website processes personal data – which begins with the very first page load, since a visitor's IP address is involved – it needs a privacy policy under the GDPR. This transparently explains which data is processed for which purpose and on what legal basis, how long it is stored, and what rights data subjects have, such as access, correction and erasure.
For a small website the privacy policy is usually manageable if you stick to the essentials. Typical points are: access via server log files, the contact form, possibly a newsletter, embedded fonts, maps or videos, plus hosting and where applicable reach measurement. The decisive thing is that the policy matches exactly what the site actually does. A generic template that lists services not in use – or conversely hides services that are used – creates more risk than security.
- Which data is processed on a mere page load (server log files, IP address)?
- Which forms exist and which fields are truly necessary?
- Are external services embedded (fonts, maps, videos, reach measurement)?
- Where is the hosting located and is there a data processing agreement for it?
- Are the data subject rights and a point of contact clearly named?
- Does the policy match exactly the site's actual functionality?
Beware US services without consent
Building block 3: Implementing cookies and consent correctly
Under Section 25 TDDDG, cookies and comparable technologies may only access the visitor's device once they have actively consented. Technically necessary cookies, for example for login or shopping cart, are exempt (Cortina Consult). The former TTDSG was renamed to TDDDG on 13 May 2024 (Cortina Consult), while the cookie rules of Section 25 remained unchanged in substance. In practice this means: anyone using reach measurement, maps, embedded videos or fonts from third-party servers generally needs a consent banner.
A compliant banner has to meet certain conditions. Rejecting must be just as easy as accepting – already on the first level, without hidden submenus. Pre-ticked boxes are not permitted, and non-essential services may only load after consent, not beforehand in the background. The simplest and safest option for a small website is often to do without consent-requiring third-party services entirely and to handle fonts, maps or statistics in a data-minimal or local way. Then a slim notice is often enough instead of a complex banner.
| Aspect | Risky implementation | Compliant implementation |
|---|---|---|
| Loading external services | Immediately on page load | Only after active consent |
| Reject option | Hidden or several clicks deep | Equal on the first level |
| Default setting | Box ticked in advance | No preselection, opt-in |
| Fonts and maps | Directly from third-party server | Hosted locally or after consent |
| Effort for the banner | Complex, error-prone | Slim, because little requires consent |
Data minimisation beats banner acrobatics
Building block 4: Securing forms and data transfer
On many small websites the contact form is the only place where personal data is actively collected. That is exactly why it deserves special attention. Three principles go a long way: encryption, data minimisation and transparency. Transmission should run over an encrypted connection (HTTPS), so that inputs do not travel across the network in plain text.
Data minimisation means asking only for the fields truly needed to handle the enquiry. A phone number as a mandatory field is rarely necessary if the reply goes by email anyway. Transparency, finally, means a short note at the form that links to the privacy policy and explains what the data is used for. A checkbox to be actively ticked only makes sense where it is genuinely needed – a plain note is enough in many standard cases.
Encrypted transmission
Send form data exclusively over HTTPS. A valid certificate is part of our fixed-price website.
Only necessary fields
Ask sparingly: name and message are often enough. Every extra mandatory field raises the data protection effort.
Clear privacy note
A short sentence at the form linking to the privacy policy creates transparency for visitors.
Processing in the EU
Email dispatch and data storage preferably in Germany or the EU, with a matching data processing agreement.
Spam protection
Simple, data-minimal spam defence instead of questionable third-party services that send extra data to external servers.
Deletion concept
Do not keep enquiries forever. Regular clean-up keeps the data volume and therefore the risk low.
Hosting in Germany lowers the effort
Avoiding warning letters: what really lowers the risk
The best-known wave of warning letters in recent years concerned embedded fonts loaded directly from a US server. A court awarded an affected person 100 euros (Munich Regional Court / heise) in damages because their IP address had been transmitted without consent. Law firms then sent out warning letters en masse, with claims usually between 150 and 500 euros (heise). Later decisions classified deliberately provoking such violations as an abuse of rights (Munich Regional Court / shopbetreiber-blog) – but the underlying problem remains: anyone who carelessly embeds third-party services makes themselves vulnerable.
The most effective prevention is unspectacular. A lean, data-minimal site without unnecessary external embeds offers little attack surface. Add a complete legal notice, a privacy policy matching the site, correct consent behaviour and secure forms. This basis covers the most common reasons for warning letters. Data protection is considered the biggest obstacle to digitalisation – 77 percent (Bitkom) of companies name it as a hurdle – yet for a small website it is manageable if the site is built cleanly from the start.
- Legal notice complete, current and reachable from the footer of every page.
- Privacy policy matches the site's actual functionality exactly.
- No consent-requiring third-party services load before consent.
- Cookie banner with an equal reject option on the first level – or no banner needed at all.
- Forms encrypted, data-minimal and with a privacy note.
- Hosting and data processing in Germany or the EU.
Cost plays into this too: a site set up to be compliant from the start is cheaper than expensive retrofitting under time pressure after a warning letter. How fixed price and hourly rate differ here is explained in our article on website costs between fixed price and hourly rate. With a fixed price, the legal texts and their clean integration are planned in from the outset.
Legal compliance does not come from the one perfect banner, but from a site that from the start does only what it really needs – and makes that transparent.
One more note on the wider picture: in Germany around 69 percent (Federal Statistical Office) of companies most recently had their own website, so almost a third did not yet. Anyone starting now can get the legal foundations right from the beginning, instead of laboriously retrofitting a grown, cluttered site. A lean fixed-price website is made exactly for this – a good moment to look at our services at a glance.