Skip to content

Legally compliant website redesign

Getting data protection, consent and mandatory legal information right in a redesign lowers the risk of cease-and-desist letters and fines.

Background

Cease-and-desist letters often stem from tracking without valid consent, third-party services with no legal basis and out-of-date legal pages. In a redesign, we implement these points correctly. Your lawyers or data protection officer make the legal call.

Since 28 June 2025, the European Accessibility Act has required many online shops and other consumer services to be accessible. Germany implements it through the BFSG. WCAG 2.2 AA is therefore part of the plan from the start.

Data protection under GDPR and TDDDG

  • Non-essential cookies and tracking only after consent (Section 25 TDDDG)

  • Fonts, maps and videos served locally or loaded only after consent

  • EU hosting with data processing agreements

  • Forms that ask for little data and transmit it encrypted

A consent tool asks for consent in plain language and records it. Declining is as easy as accepting. Consent Mode v2 for Google services is taken into account.

The legal notice under Section 5 of Germany's Digital Services Act (DDG) is linked from every page. Your team maintains the privacy policy and terms in the CMS. The texts come from your lawyers.

Tracking plan

The plan sets out which data you need and which tool collects it. Data-minimising options include Matomo and server-side tagging. It is documented for audits.

After launch

We check regularly whether new services or changed requirements call for adjustments.

Project enquiry

Back to top