Anyone thinking about privacy on their own website thinks about the panel that opens on the first visit. That is understandable, because it is the only part you can see. It is also the part with the smallest ceiling and the least meaning. A flawless banner says nothing about whether the services behind it were ever properly contracted, where the data travels, or whether anything on the site actually describes what happens. That is exactly the order supervisory authorities are working through in 2026. This piece walks the three points of website privacy that genuinely matter, each with the provision you can read for yourself.
Why is the banner only the visible part?
Because it answers one narrow question: may anything be stored on or read from the visitor's device? In Germany that sits in section 25(1) TDDDG, headed "protection of privacy in terminal equipment". It is permitted only after consent given on the basis of clear and comprehensive information. Subsection 2 allows exactly two exceptions: carrying out the transmission of a message, and whatever is strictly necessary for a service the user has expressly requested. Austria carries the same rule in section 165(3) TKG 2021, and the Austrian data protection authority says the same thing in its FAQ on data protection and cookies: without consent, only what the requested service strictly needs.
Everything hangs on the phrase "strictly necessary". A basket qualifies, so does a login, so usually does a language preference. Analytics does not. Map services do not. Embedded videos do not. Fonts pulled from someone else's server do not. This is where a great many sites fail without noticing: the banner is present, it looks the part, and the scripts run before anyone has clicked anything. Whether a banner is built properly is decided not by its appearance but by what happens before the click. That is the craft behind consent management, and it is the only question worth testing.
How many third-party services does your site really load?
More than almost any owner would guess. The HTTP Archive measures this every year across a very large slice of the web. The 2025 result: between 90 and 92 per cent of pages surveyed embed at least one third party, and the median sits at 83 requests to third-party hosts on desktop and 79 on mobile.
Every one of those services that processes personal data on your behalf, and an IP address already counts as personal data, needs a contract. This is not a formality but Art. 28 GDPR: processing by a processor is lawful only on the basis of a contract setting out subject matter, duration, nature and purpose. With the larger providers such a contract usually sits ready as a clause in the terms and needs only to be actively accepted. That is precisely what often does not happen, because nobody goes looking. Processing on behalf is the point least often checked and most easily fixed.
The practical route there is unglamorous: open the site in a browser, run the network panel, write down every third-party domain. What remains is your contract list. There are usually fewer vendors than requests, often somewhere between five and fifteen, and half of them were added years ago for a test nobody switched off.
What happens when a tool sits in the United States?
Then you need a basis for the transfer itself. Since 10 July 2023 there has again been an adequacy decision from the European Commission, the EU-US Data Privacy Framework. For providers certified under it, the transfer is covered without additional contracts of your own. The decision stands, but it stands less firmly than the quiet of recent years suggests.
This does not mean you have to avoid US tools. It means you should know which ones you use and how quickly you could replace them. Two questions are enough: which service currently holds which data, and how long the move would take if the basis fell away. Anyone who can answer that for their three most important tools has third-country transfers under control without having bought legal advice.
Why are the authorities reading privacy notices in 2026?
Because they agreed to. The European Data Protection Board picks one topic each year for the national supervisory authorities to examine together. In 2023 it was cloud services in the public sector, in 2024 the position of data protection officers, in 2025 the right of access. On 19 March 2026 this year's action began: transparency and information obligations under Art. 12 to 14 GDPR, with 25 participating authorities.
Art. 12 to 14 are the least glamorous part of the regulation and the part you can repair fastest on your own. They require it to say, in clear and plain language, who processes what, for what purpose, on which legal basis, for how long, who receives it, and what rights people have. The typical privacy notice satisfies that formally and fails on currency: it names services that left long ago and stays silent about the ones added last year. If somebody asks in 2026, that comparison is the audit. This is the cheapest of the three points, because it costs nothing but an hour of honesty.
What does a mistake cost, and where?
It varies, and in a direction most people find back to front. In Germany the banner hangs on the TDDDG, where section 28 TDDDG sets a ceiling of 300,000 euros. The processing behind it hangs on the GDPR, whose Art. 83(5) reaches 20 million euros or 4 per cent of worldwide annual turnover, whichever is higher.
These are maximums, not a forecast for a trades business with eight staff. What they do show is the ranking the legislator applied, and it runs exactly counter to the attention each part usually receives. The panel in the foreground carries the smaller number. What runs behind it carries the larger one. In daily life the trouble rarely arrives from a regulator anyway: it arrives from a customer, a competitor or a job applicant who reads the notice and asks a question.
What do you do with this?
Three steps, in this order, and none of them needs a law firm.
First, pull the list. Open the site, run the network panel, note every third-party domain. It takes twenty minutes and everything else builds on it. Without the list you are guessing.
Second, halve the list. One question per entry: what is this for? Anything customers never see and nobody ever reads goes. Every service you delete saves a consent, a contract, a line in the notice and a little load time. It is the only step that makes the site faster and more lawful at the same time.
Third, write down what is left. The remainder goes into the privacy notice, contracts get accepted where they sit ready, and the banner gets configured so that genuinely nothing loads before the click. After that, pull the list once a year and hold it against the notice.
Website privacy is not a legal project but a stocktake with three columns: what loads, who is allowed to, where it is written down. Do the stocktake once and an hour a year keeps it current. If you like, we will walk your site with you and hand the list back as a file, including the lines you can strike out yourself 🙂
