Blog SEO Administration Webshops
Data protection on websites - netzwerk.design
Photo | Icket on AdobeStock

Data protection on websites

5 min.

As the website operator, we are responsible for our website. We must therefore implement the applicable data protection law. What exactly do we have to do?

I am constantly adding to this article and will take you step by step through the topics that may be important for your website. 

Disclaimer: This article does not constitute legal advice or a substitute for consulting a lawyer. It is based on my own research, training and experience on this topic. I cannot accept any liability for its accuracy. For comprehensive reading on the subject of data protection and WordPress, I also recommend the sources listed below.

The GDPR generally applies to every website operator, with the exception of purely private websites that are not publicly accessible.

Personal data

All personal data must be protected, including

  • Name
  • Address
  • Email address
  • Telephone number
  • Date of birth
  • Account details
  • Location information
  • IP addresses

Since the IP address is also transmitted when a website is accessed, it is clear that the EU regulation applies to every website.

The principles of data protection newly formulated in the GDPR are Lawfulness of data processing, data minimisation, purpose limitation, data security, transfer to third countries, rights of data subjects, independent supervision, effective enforcement.

Personal data may be processed if a) there is a legal basis or b) explicit consent has been given, otherwise not. Only data that is really necessary for the respective purpose may be collected. And if this purpose no longer applies, the data must be deleted (e.g. cancellation of the newsletter subscription). This also has consequences for existing databases.

Step by step

WordPress and data protection

Some of the following list is self-evident, but it should be mentioned again here anyway. For example, as a website operator, you are not ensuring the best possible data protection according to the state of the art if you do not regularly install the latest updates.

  1. Always keep WordPress, your theme and all plugins up to date (Update administration).
  2. Also all server-side technologies (PHP, MySQL, Linux, Apache, etc.). Check the hoster's settings and update if necessary.
  3. Encrypt the data transmission of your website (https / SSL).
  4. Choose a strong password for each WordPress login. Important!
  5. Regular data backups (backups). Daily is best. Find out about the possibility of importing backups, this saves time and nerves in an emergency.
  6. If you commission third parties to process the personal data collected from you, an order processing contract must be concluded with them; classic cases are your hoster, Google Analytics or newsletter services.
  7. Does your site use Google fonts? Probably yes! If so, you should integrate these fonts locally on your server and prevent access to the Google server, which provides both data security and speed benefits.
  8. Check all plugins used to see whether they collect and store personal data; examples include WooCommerce, newsletter plugins, analytics plugins, etc.
  9. Avoid plugins from services that transfer personal data (usually IP addresses) to servers outside the EU. Examples are MailChimp (newsletter service), iThemes Security (website protection).
  10. Anonymise the IP addresses in any analysis software (e.g. Google Analytics).
  11. Contact form: Integrate a consent checkbox for data processing as a mandatory field.
  12. Newsletter subscription function: integrate a consent checkbox for data processing as a mandatory field.
  13. Make sure that your web server sends outgoing mails encrypted, e.g. with an SMTP plugin (SMTP server port 465 or 587).
  14. Anonnymise IP transmission for blog comments.
  15. Deactivate the avatar display in WordPress.
  16. Update your privacy policy - regularly!
  17. Keep a register of data processing activities.
  18. In the event of a data breach (e.g. if your site has been hacked), contact the responsible supervisory authority (data protection officer of the respective federal state) within 72 hours

Link to the State Commissioner for Data Protection in Bavaria

I will advise and support you in implementing the new data protection law on your website

As an eRecht24 agency partner, I can support my customers in the implementation of a correct privacy policy in accordance with the GDPR and in the area of legal notices. Part of my services in the area of website creation is of course also the support in the implementation of a GDPR-compliant privacy policy and practical, lawyer-approved content on the GDPR.

As a web developer, I offer you the technical implementation and integration of legally compliant tools. The most frequently affected functional areas of a website are already mentioned here: Encryption, cookie notification, avoidance of external server access, form customisation, sharing function, local integration of Google fonts and symbol fonts, newsletter management, backup and update administration.

Copyrights (off-topic)

Something that is not thematically related to the GDPR, but which poses a risk of warnings for many websites, is German copyright law. Images, photos, videos, songs and texts are protected. Only self-created content can be used without any problems. If third-party content is used, a suitable licence agreement must be concluded with the author (e.g. photographer, copywriter) or the rights exploiter (e.g. picture agency). The author must also be named on the work; under German copyright law, naming the author in the legal notice is not sufficient. The latter is often not observed and should be corrected if necessary.

See also eRecht24 on copyright law

I offer my clients the correct copyright attribution for their website.

Read my article on this:

Why does the author belong to the work?

UST-ID and tax number (off-topic)

The tax number is also sometimes entered incorrectly on a website. So: Did you know? - If available, the VAT ID should be included in the legal notice. The following applies to small businesses according to §19 UStG: reference must be made to the small business status. But: the tax number does not belong on the website! It could possibly be used to obtain information about your tax affairs from your tax office.

See also the IHK guide to VAT identification numbers