Contemporary workspace with controlled data paths behind a glass structure

WordPress and GDPR

Privacy is a real responsibility

Your website processes personal data through forms, cookies, analytics and embedded services. We check what is collected and shared, verify that consent works correctly and make the necessary technical changes.

Enquire about your project

We protect your visitors’ data

The General Data Protection Regulation, or GDPR, has governed the handling of personal data across the European Union since 2018. It applies to private websites, small businesses and large companies.

The steps your website needs depend on its features. Forms, cookies, analytics, videos, maps, fonts and plugins process data in different ways. Website owners quickly lose track of what is happening.

We help you with the technical work. We check your website, explain the problems we find and make the required changes. You then receive a clear overview of the services in use.

We do not provide legal advice. Your privacy lawyer receives all technical details needed for the next review.

Privacy audit at a contemporary workspace with a specialist seen from behind

Privacy problems we often find

New plugins, forms and external services are easy to add. Over time, connections appear that nobody is keeping track of.

01

Data goes to unknown providers

Services start when the page loads and transfer data. The recipient and purpose are often unclear.

02

Tracking loads before consent

Analytics and marketing start even though the visitor has not made a choice yet.

03

Plugins send data elsewhere

Plugins for forms, shops, security and page design connect to external servers or store personal data.

04

Forms ask for too much data

Many forms contain unnecessary required fields. Clear details about delivery, storage and deletion are often missing.

05

The consent banner blocks nothing

A banner only helps when technical blocking works. Rejecting and withdrawing must be as easy as accepting.

06

The privacy policy is out of date

The website loads services that the policy does not mention. New plugins and other changes are missing.

eRecht24 Agency Partner seal on a stone table in a contemporary office

Legally compliant websites with eRecht24

As an eRecht24 Agency Partner, we combine technical privacy optimization with established solutions for legally compliant websites. This helps consent management, legal texts and technical implementation work together coherently.

We handle the clean integration on your website and provide the technical details required for legal review. We do not provide individual legal advice.

What we check on your website

We check every function that processes personal data or connects to an external provider.

01

Cookies and consent banners

We check which cookies your website sets and whether the consent banner controls them correctly. Accepting, rejecting and withdrawing must work reliably.

02

Analytics, advertising and affiliate links

We check Google Analytics, online advertising and paid affiliate links. Services that require consent remain blocked until the visitor agrees.

03

Forms, newsletters and comments

We check required fields, notices, secure transfer, storage and deletion. For newsletters, we also check the email confirmation process.

04

Videos, maps and social media

We block maps, videos, social media posts, chats and spam protection until consent. A content blocker handles this process.

05

Google Fonts and external files

Where possible, we host fonts and icons locally. The browser then avoids sending unnecessary data to external servers while the page loads.

06

Plugins, hosting and external providers

We record every provider that processes personal data. This includes hosting, newsletter services, cloud storage and security services. Existing agreements are added to the overview.

Next step

Let’s talk about your project.

Enquire about your project
Specialist consciously controlling individual technical connections at a contemporary media wall

External content loads after consent

Maps, videos, social media posts, chats and captchas connect to external providers. A content blocker stops them from loading automatically. Visitors first see a notice and choose whether to load the content.

Additional services

We take care of these points too

GDPR involves other tasks. We check which ones matter for your website and who should handle each task.

01

SSL encryption

We check the certificate, secure redirects and mixed content. Forms and pages should transfer data over an encrypted connection.

02

Privacy policy and legal notice

We compare the services in use with your legal texts. Your privacy lawyer handles the legal wording.

03

Data protection officer

We clarify whether a data protection officer is already involved. We provide the technical documentation for their review.

04

Data processing agreements

We list providers that process data on your behalf. This shows which services require a data processing agreement to be checked.

05

External links

We check external links and notices for third-party content. Visitors should recognise when they are leaving your website.

06

Support after a legal complaint

Have you received a formal complaint? We check the technical issue, record the current setup and implement agreed changes quickly.

Google Fonts belong on your own server

When your website loads fonts directly from Google, the browser connects to Google and transfers the visitor’s IP address. We check the setup, store the required fonts on your web server and remove the external request.

01

No connection to Google

The fonts are stored on your web server. The browser no longer contacts Google while the page loads and sends no connection data to Google.

02

Host the fonts locally

We download only the required font families and weights, add them to your website and check every page for remaining connections to Google.

03

Fewer external requests

Local fonts remove the extra request to Google. This simplifies the setup and often improves your website’s loading time.

Organised technical structure in a contemporary workspace

New plugins often create new privacy problems

One new form, analytics tool or plugin may connect your website to another provider. We check important changes as soon as they are installed. You then know which connection was added and whether the consent banner blocks it correctly.

Next step

Let’s talk about your project.

Enquire about your project

How we check your website

First, we record the current setup. Then we make the changes and document the results in plain language.

Scan the website

We record external connections, cookies, local storage, scripts, plugins, forms, media, fonts and tracking.

Assign each service

For each service, we record its purpose, the data it processes, the recipient, retention and consent requirements.

Test the consent banner

We test accepting, rejecting and withdrawing consent. Services that require consent must remain blocked until the visitor makes a choice.

Adjust the technology

We host fonts locally, reduce external services, update forms, organise scripts and remove unnecessary plugins.

Document the changes

You receive an overview of the services in use, our changes and open points for legal review.

Check the website again

After updates, new plugins, campaigns or tracking changes, we test the affected functions again.

FAQ

Common questions about privacy optimization

Answers about GDPR, cookies, consent, fonts, plugins and forms.

Do you provide legal advice?

No. We check and change the technology on your website. A lawyer or privacy officer should review legal texts and individual legal questions. Our documentation provides the technical details for this review.

Is a consent banner enough?

No. The banner must block services that require consent until the visitor makes a choice. Rejecting and withdrawing must be as easy as accepting.

Which external services do you check?

We check services such as Google Fonts, maps, videos, analytics, marketing pixels, captchas, chats and social media content. These services often transfer IP addresses or device information to external providers.

Does every website need a consent banner?

No. A website without cookies, tracking or external services that require consent may not need a full banner. Our scan shows what loads when someone visits the page.

Do you check WordPress plugins?

Yes. We check which plugins store data, contact external servers or set cookies. We remove unnecessary plugins after discussing it with you. For required features, we look for a more privacy-friendly option.

What do you check in contact forms?

We check required fields, notices, SSL encryption, delivery, storage and deletion. The form should only collect the data you need to handle the message.

Do I need to update the privacy policy?

Often, yes. Removed, new or locally hosted services change the information required in the privacy policy. The responsible legal professional handles the legal review.

When should I get the website checked again?

Check the website after adding plugins, forms, campaigns, tracking codes or external content. Major updates may also change how a service behaves.