Let's talk

GDPR checklist for your website in Austria: 8 things to check

A practical checklist for GDPR on your website: cookie consent, fonts, forms, embeds, hosting and privacy policy, with the rulings and rules behind each point.

Patryk WisniewskiLead developer
Published
Topic
Websites
Reading time
9 min read

Key takeaways

  • Non-essential cookies and trackers need consent before they load; rejecting must be as easy as accepting (Austrian data protection authority).
  • Load Google Fonts from your own server. In 2022 the Regional Court of Munich awarded €100 damages for a site that loaded them from Google without consent.
  • Embeds such as maps and videos, forms and analytics are the usual sources of trouble; check each one.
  • This article is general information, not legal advice.

Short answer: for a GDPR-compliant website in Austria, check eight things: cookie consent, Google Fonts, analytics, embeds, forms, hosting and processors, the privacy policy and the imprint. The most important rule: anything that sets non-essential cookies or sends visitor data to third parties needs consent first, and the choice to refuse must be as easy as to accept. This is general information, not legal advice (keine Rechtsberatung).

Most GDPR problems on small business websites are not exotic. They come from a few third-party services that were added without much thought: a font loaded from Google, a map, a video, an analytics script. This checklist goes through them. Where we state a rule or a ruling, we name the source; check your own case with a lawyer.

Cookie consent that really blocks

In Austria, § 165 (3) of the Telecommunications Act 2021 requires consent for cookies, with an exception for technically necessary ones. The Austrian data protection authority (DSB) states on its website that a valid banner must obtain consent before non-necessary cookies are set, offer accept and reject with equal prominence, allow granular choices, explain how to withdraw, and avoid pre-ticked boxes and manipulative design.

  • No consent needed: technically necessary cookies, such as the shopping cart, login status, language setting or storing the consent itself.
  • Consent needed: analytics and tracking, remarketing, social media plugins, video and map embeds, according to the WKO.
  • Test it: open your site in a private window, do not click anything and check in the browser’s developer tools whether trackers load anyway.

Self-host Google Fonts

If a page loads fonts directly from Google’s servers, the visitor’s IP address is sent to Google. The Regional Court of Munich I (judgment of 20 January 2022, case 3 O 17493/20) held that loading Google Fonts dynamically without consent violated the GDPR and awarded the plaintiff €100 damages. The court reasoned that the fonts can be hosted locally, so there was no legitimate interest in the transfer.

This is a German first-instance ruling, so it does not bind Austrian courts, but it shows the risk and the fix is cheap: serve the font files from your own domain. On our Next.js sites fonts are self-hosted by default.

Analytics and tracking tools

In January 2022 the Austrian DSB found, in a case brought by the organisation noyb, that the use of Google Analytics violated the GDPR because personal data was transferred to the USA without adequate protection at the time. Since then the EU-US Data Privacy Framework has been in place, and the EU General Court dismissed a challenge to it on 3 September 2025; an appeal is pending at the Court of Justice. The legal situation can change again. Whichever tool you use, you need consent unless it works without personal data and without storing anything on the device, and you must name it in the privacy policy.

Maps, videos and social plugins

Embedded maps, YouTube videos and social media buttons contact third parties as soon as the page loads. The WKO counts them among the services that need consent. The usual fix is a two-click solution: show a placeholder and load the content only after the visitor agrees. Alternatives are a static map image with a link or videos hosted on your own server.

Contact and enquiry forms

  • Collect only what you need to answer the enquiry.
  • Link the privacy policy next to the form and state why the data is used.
  • Do not pre-tick any box; marketing consent must be separate and voluntary.
  • Check where the form data is sent and which provider processes it.
  • Be careful with captchas: according to the WKO, the Federal Administrative Court ruled that Google reCAPTCHA cookies are not technically necessary.

EU hosting and processors

Hosting inside the EU is not required by the GDPR as such, but it avoids a whole class of transfer questions. Whatever you use, every provider that processes personal data for you (hosting, forms, e-mail, analytics) needs a data processing agreement, and you should know where the data goes. All our sites run in the EU. More in our web design service.

A privacy policy that matches reality

Commercial website operators must inform users which personal data they collect, on which legal basis and for which purposes, and for how long they store it (§ 165 TKG 2021, according to the WKO). WKO also advises a separate, prominent privacy section instead of hiding it in the imprint. Typical parts: who is responsible, purposes and legal bases, recipients and processors, retention, visitor rights and the right to complain to the data protection authority. The most common mistake is a generic text that lists tools the site no longer uses or omits ones it does.

Imprint and accessibility

Not GDPR, but part of the same legal basics: a complete imprint, see imprint requirements, and for many businesses accessibility duties, see the Accessibility Act and your website.

Have your website checked

Our free website check shows technical and SEO problems. For the legal side, ask us in a free 30-minute call what we set up in every project.

Frequently asked questions

Do I need a cookie banner in Austria?

Only if you use non-essential cookies or similar technologies, such as analytics, marketing or third-party embeds. Then you need consent before they load. A site with only technically necessary cookies does not need a consent banner.

Is Google Fonts allowed under the GDPR?

Loading the fonts from Google’s servers without consent was ruled a violation by the Regional Court of Munich in 2022. Hosting them on your own server avoids the issue.

Is Google Analytics legal in Austria?

The Austrian DSB ruled against it in 2022 under the legal situation at that time. Today you must at least have valid consent and an adequate transfer basis, and the legal situation is still developing. Check your case.

Does my website have to be hosted in the EU?

The GDPR does not strictly require it, but EU hosting simplifies the legal side. You still need a processing agreement with your provider.

What does a GDPR violation cost?

It depends on the case. The Munich ruling awarded the plaintiff €100 in damages, which shows that even a small violation can get expensive. Regulators can also impose fines under the GDPR.

Written byPatryk WisniewskiLead developer

Keep reading

More lessons from our projects in Vienna.

Let’s work
together

Tell us about your project. Christoph gets back to you personally.

Christoph Speiser, Project lead & sales

What can we help with?

Pick as many as you like.