Data goes to unknown providers
Services start when the page loads and transfer data. The recipient and purpose are often unclear.
WordPress and GDPR
Your website processes personal data through forms, cookies, analytics and embedded services. We check what is collected and shared, verify that consent works correctly and make the necessary technical changes.
Enquire about your projectThe General Data Protection Regulation, or GDPR, has governed the handling of personal data across the European Union since 2018. It applies to private websites, small businesses and large companies.
The steps your website needs depend on its features. Forms, cookies, analytics, videos, maps, fonts and plugins process data in different ways. Website owners quickly lose track of what is happening.
We help you with the technical work. We check your website, explain the problems we find and make the required changes. You then receive a clear overview of the services in use.
We do not provide legal advice. Your privacy lawyer receives all technical details needed for the next review.
New plugins, forms and external services are easy to add. Over time, connections appear that nobody is keeping track of.
Services start when the page loads and transfer data. The recipient and purpose are often unclear.
Analytics and marketing start even though the visitor has not made a choice yet.
Plugins for forms, shops, security and page design connect to external servers or store personal data.
Many forms contain unnecessary required fields. Clear details about delivery, storage and deletion are often missing.
A banner only helps when technical blocking works. Rejecting and withdrawing must be as easy as accepting.
The website loads services that the policy does not mention. New plugins and other changes are missing.
We check every function that processes personal data or connects to an external provider.
We check which cookies your website sets and whether the consent banner controls them correctly. Accepting, rejecting and withdrawing must work reliably.
We check Google Analytics, online advertising and paid affiliate links. Services that require consent remain blocked until the visitor agrees.
We check required fields, notices, secure transfer, storage and deletion. For newsletters, we also check the email confirmation process.
We block maps, videos, social media posts, chats and spam protection until consent. A content blocker handles this process.
Where possible, we host fonts and icons locally. The browser then avoids sending unnecessary data to external servers while the page loads.
We record every provider that processes personal data. This includes hosting, newsletter services, cloud storage and security services. Existing agreements are added to the overview.
Additional services
GDPR involves other tasks. We check which ones matter for your website and who should handle each task.
We check the certificate, secure redirects and mixed content. Forms and pages should transfer data over an encrypted connection.
We compare the services in use with your legal texts. Your privacy lawyer handles the legal wording.
We clarify whether a data protection officer is already involved. We provide the technical documentation for their review.
We list providers that process data on your behalf. This shows which services require a data processing agreement to be checked.
We check external links and notices for third-party content. Visitors should recognise when they are leaving your website.
Have you received a formal complaint? We check the technical issue, record the current setup and implement agreed changes quickly.
When your website loads fonts directly from Google, the browser connects to Google and transfers the visitor’s IP address. We check the setup, store the required fonts on your web server and remove the external request.
The fonts are stored on your web server. The browser no longer contacts Google while the page loads and sends no connection data to Google.
We download only the required font families and weights, add them to your website and check every page for remaining connections to Google.
Local fonts remove the extra request to Google. This simplifies the setup and often improves your website’s loading time.
First, we record the current setup. Then we make the changes and document the results in plain language.
We record external connections, cookies, local storage, scripts, plugins, forms, media, fonts and tracking.
For each service, we record its purpose, the data it processes, the recipient, retention and consent requirements.
We test accepting, rejecting and withdrawing consent. Services that require consent must remain blocked until the visitor makes a choice.
We host fonts locally, reduce external services, update forms, organise scripts and remove unnecessary plugins.
You receive an overview of the services in use, our changes and open points for legal review.
After updates, new plugins, campaigns or tracking changes, we test the affected functions again.
FAQ
Answers about GDPR, cookies, consent, fonts, plugins and forms.
No. We check and change the technology on your website. A lawyer or privacy officer should review legal texts and individual legal questions. Our documentation provides the technical details for this review.
No. The banner must block services that require consent until the visitor makes a choice. Rejecting and withdrawing must be as easy as accepting.
We check services such as Google Fonts, maps, videos, analytics, marketing pixels, captchas, chats and social media content. These services often transfer IP addresses or device information to external providers.
No. A website without cookies, tracking or external services that require consent may not need a full banner. Our scan shows what loads when someone visits the page.
Yes. We check which plugins store data, contact external servers or set cookies. We remove unnecessary plugins after discussing it with you. For required features, we look for a more privacy-friendly option.
We check required fields, notices, SSL encryption, delivery, storage and deletion. The form should only collect the data you need to handle the message.
Often, yes. Removed, new or locally hosted services change the information required in the privacy policy. The responsible legal professional handles the legal review.
Check the website after adding plugins, forms, campaigns, tracking codes or external content. Major updates may also change how a service behaves.