Awwwards
404media is now part of Awwwards. Find our studio profile and work there.
A practical checklist for GDPR on your website: cookie consent, fonts, forms, embeds, hosting and privacy policy, with the rulings and rules behind each point.
Patryk WisniewskiLead developerShort answer: for a GDPR-compliant website in Austria, check eight things: cookie consent, Google Fonts, analytics, embeds, forms, hosting and processors, the privacy policy and the imprint. The most important rule: anything that sets non-essential cookies or sends visitor data to third parties needs consent first, and the choice to refuse must be as easy as to accept. This is general information, not legal advice (keine Rechtsberatung).
Most GDPR problems on small business websites are not exotic. They come from a few third-party services that were added without much thought: a font loaded from Google, a map, a video, an analytics script. This checklist goes through them. Where we state a rule or a ruling, we name the source; check your own case with a lawyer.
In Austria, § 165 (3) of the Telecommunications Act 2021 requires consent for cookies, with an exception for technically necessary ones. The Austrian data protection authority (DSB) states on its website that a valid banner must obtain consent before non-necessary cookies are set, offer accept and reject with equal prominence, allow granular choices, explain how to withdraw, and avoid pre-ticked boxes and manipulative design.
If a page loads fonts directly from Google’s servers, the visitor’s IP address is sent to Google. The Regional Court of Munich I (judgment of 20 January 2022, case 3 O 17493/20) held that loading Google Fonts dynamically without consent violated the GDPR and awarded the plaintiff €100 damages. The court reasoned that the fonts can be hosted locally, so there was no legitimate interest in the transfer.
This is a German first-instance ruling, so it does not bind Austrian courts, but it shows the risk and the fix is cheap: serve the font files from your own domain. On our Next.js sites fonts are self-hosted by default.
In January 2022 the Austrian DSB found, in a case brought by the organisation noyb, that the use of Google Analytics violated the GDPR because personal data was transferred to the USA without adequate protection at the time. Since then the EU-US Data Privacy Framework has been in place, and the EU General Court dismissed a challenge to it on 3 September 2025; an appeal is pending at the Court of Justice. The legal situation can change again. Whichever tool you use, you need consent unless it works without personal data and without storing anything on the device, and you must name it in the privacy policy.
Embedded maps, YouTube videos and social media buttons contact third parties as soon as the page loads. The WKO counts them among the services that need consent. The usual fix is a two-click solution: show a placeholder and load the content only after the visitor agrees. Alternatives are a static map image with a link or videos hosted on your own server.
Hosting inside the EU is not required by the GDPR as such, but it avoids a whole class of transfer questions. Whatever you use, every provider that processes personal data for you (hosting, forms, e-mail, analytics) needs a data processing agreement, and you should know where the data goes. All our sites run in the EU. More in our web design service.
Commercial website operators must inform users which personal data they collect, on which legal basis and for which purposes, and for how long they store it (§ 165 TKG 2021, according to the WKO). WKO also advises a separate, prominent privacy section instead of hiding it in the imprint. Typical parts: who is responsible, purposes and legal bases, recipients and processors, retention, visitor rights and the right to complain to the data protection authority. The most common mistake is a generic text that lists tools the site no longer uses or omits ones it does.
Not GDPR, but part of the same legal basics: a complete imprint, see imprint requirements, and for many businesses accessibility duties, see the Accessibility Act and your website.
Our free website check shows technical and SEO problems. For the legal side, ask us in a free 30-minute call what we set up in every project.
Only if you use non-essential cookies or similar technologies, such as analytics, marketing or third-party embeds. Then you need consent before they load. A site with only technically necessary cookies does not need a consent banner.
Loading the fonts from Google’s servers without consent was ruled a violation by the Regional Court of Munich in 2022. Hosting them on your own server avoids the issue.
The Austrian DSB ruled against it in 2022 under the legal situation at that time. Today you must at least have valid consent and an adequate transfer basis, and the legal situation is still developing. Check your case.
The GDPR does not strictly require it, but EU hosting simplifies the legal side. You still need a processing agreement with your provider.
It depends on the case. The Munich ruling awarded the plaintiff €100 in damages, which shows that even a small violation can get expensive. Regulators can also impose fines under the GDPR.

More lessons from our projects in Vienna.
Websites • • 9 min read
Patryk WisniewskiWebsites • • 8 min read
Christoph SpeiserWebsites • • 9 min read
Christoph Speiser
Tell us about your project. Christoph gets back to you personally.
Christoph Speiser, Project lead & sales