Skip to content

Technical GDPR check and consent management for websites.

Cookies, external services and consents in view.

We check which services your website integrates, which information it stores in the browser and how the consent settings are implemented technically. You receive a clear overview and concrete recommendations for necessary adjustments.

On request, we then take over the technical implementation. The legal assessment is carried out by your legal advisers or your data protection officer; we provide the technical information for this.

Starting point

A cookie banner alone is not enough.

A cookie banner shows which choices visitors have. Whether these settings take effect technically has to be checked separately. For example, an analytics tool may already transmit data even though the required consent has not yet been given.

With new functions, forms or campaigns, the integrated services also change. We give you an overview of the current state and show where adjustments are sensible or necessary.

Our stance

Check integrations and simplify them in a targeted way.

First we look at which services your website actually needs. Fonts and suitable scripts can often be provided directly via your own web server. This eliminates the corresponding connections to external providers. Integrations that are no longer needed can be removed.

For functions that require consent, we set up consent management accordingly. Visitors can make their choice and later change or revoke it. Whether consent is required depends on the respective function and data processing – not solely on which server it is located on.

What we check and implement.

We agree the scope with you. The check covers the agreed pages and functions and their behaviour before consent, after consent or refusal and after revocation. We implement necessary changes after a separate order.

We record which external services the checked pages call – for example for fonts, maps, videos or forms. We then check technical alternatives and document for which integrations the legal requirements need to be clarified.

We examine which information is stored in or read from the browser and when this happens. We check whether access requiring consent is prevented according to the selected settings.

We configure services and categories, adapt the design to your website and implement the agreed consent texts. We then check the technical function of consent, refusal and revocation.

For contact, application and newsletter forms, we check the data requested and its transmission. We technically implement the agreed requirements for mandatory fields, data protection notices and any consents required.

On the basis of the technical check and existing documents, we record the services involved, data flows and known processing locations. This information supports the check of required data processing agreements. We include agreed interfaces to specialist systems. Where hosting and operation are included, we work with providers with data centres in Germany; more on this under Maintenance and support.

We compile the recorded services, connections and storage accesses. We add information on purposes and storage duration on the basis of available documents and mark open points. This gives your legal advisers a technical basis for the privacy policy.

Collaboration

How the technical check works.

Together we define which pages, forms, language versions and functions we examine. You do not need a finished technical concept for this. We help you define the right scope of the check.

Check

We examine the agreed pages and functions in the defined consent states. We record observed connections and storage accesses in a traceable way.

Recommendations

You receive concrete proposals for technical adjustments, ordered by urgency and effort. You clarify questions on the legal classification with your legal advisers or your data protection officer; we provide the technical information for this.

Implementation

After your order, we adapt integrations and configure consent management. We then check again whether the agreed settings take effect technically.

Documentation

We document the results and recommended measures. After an ordered implementation, we add the changes made and the result of the re-check. This makes it clear what was checked and which points are still open.

The result

A clear basis for the next steps.

After the check, you know which technical integrations and storage accesses we found within the agreed scope and which adjustments we recommend. You can plan the next steps better and have a documented basis for coordination with your legal advisers.

If we then implement changes, we check their technical effect again. Removing unnecessary integrations can also reduce the maintenance effort and improve loading times.

FAQ

Frequently asked questions about the technical data protection check.

The check shows the technical state within the agreed scope and names possible adjustments. Full GDPR compliance cannot be confirmed by this alone. This also includes legal and organisational questions, such as legal bases, information obligations and contracts. We provide the technical information for your legal advisers or your data protection officer and implement agreed changes after an order.

We work with an established consent management system that we operate for several clients via our agency account. If you already use a solution, we first check whether it can be configured suitably. We regulate licence costs and the handover in the event of a change of agency in the agreement.

Not every website needs a cookie banner. What matters is whether functions are used for which consent is required. We check the technical integrations and possible alternatives. Which consents are needed is clarified with your legal advisers. Local fonts or doing without external content can reduce integrations, but do not answer this question on their own.

The report names the checked pages, functions and consent states as well as the connections and storage accesses observed. Added to this are technical recommendations and open questions. We add information on providers, purposes and storage duration as far as it can be determined or is documented. We list check, implementation and re-check separately in the quote.

We provide the technical information on the recorded services and data processing. Your legal advisers create or check the legal text. If the website changes, we update the technical information within the agreed scope of support.

A re-check makes particular sense when new services, forms or analytics functions are added or their configuration changes. We can agree regular checks as part of ongoing support.

Yes. The technical check of the integrations and storage accesses recognisable in the browser is independent of the content management system used. We carry out adjustments to TYPO3 websites ourselves. For other systems, we coordinate the recommended measures with your responsible service provider.

Let us take a look at your website.

Send us the address of your website and, if available, your questions about it. For an initial orientation, we look at the integrations on first load free of charge and without obligation. We then offer you a detailed technical check with a report separately.