Free guide:winning new clients predictably in 2026 · 10 pages, freeGet it now

Website privacy: the three points that actually matter

The cookie banner is the visible part and the one with the smaller ceiling. An ordinary page loads a median of 79 third-party requests, 25 European supervisory authorities are checking transparency obligations in a coordinated action through 2026, and the legal basis for US tools rests on a decision now under appeal. The three points that matter, with the provisions you can look up.

Cover: Website privacy: the three points that actually matter

Anyone thinking about privacy on their own website thinks about the panel that opens on the first visit. That is understandable, because it is the only part you can see. It is also the part with the smallest ceiling and the least meaning. A flawless banner says nothing about whether the services behind it were ever properly contracted, where the data travels, or whether anything on the site actually describes what happens. That is exactly the order supervisory authorities are working through in 2026. This piece walks the three points of website privacy that genuinely matter, each with the provision you can read for yourself.

Why is the banner only the visible part?

Because it answers one narrow question: may anything be stored on or read from the visitor's device? In Germany that sits in section 25(1) TDDDG, headed "protection of privacy in terminal equipment". It is permitted only after consent given on the basis of clear and comprehensive information. Subsection 2 allows exactly two exceptions: carrying out the transmission of a message, and whatever is strictly necessary for a service the user has expressly requested. Austria carries the same rule in section 165(3) TKG 2021, and the Austrian data protection authority says the same thing in its FAQ on data protection and cookies: without consent, only what the requested service strictly needs.

Everything hangs on the phrase "strictly necessary". A basket qualifies, so does a login, so usually does a language preference. Analytics does not. Map services do not. Embedded videos do not. Fonts pulled from someone else's server do not. This is where a great many sites fail without noticing: the banner is present, it looks the part, and the scripts run before anyone has clicked anything. Whether a banner is built properly is decided not by its appearance but by what happens before the click. That is the craft behind consent management, and it is the only question worth testing.

How many third-party services does your site really load?

More than almost any owner would guess. The HTTP Archive measures this every year across a very large slice of the web. The 2025 result: between 90 and 92 per cent of pages surveyed embed at least one third party, and the median sits at 83 requests to third-party hosts on desktop and 79 on mobile.

Bar chart with four values: all sites on mobile 79 third-party requests at the median, all sites on desktop 83, top 1,000 on mobile 106, top 1,000 on desktop 129. Note beneath: 90 to 92 per cent of all pages surveyed load at least one third party.
All sites mobile 79, all sites desktop 83, top 1,000 mobile 106, top 1,000 desktop 129 requests to third-party hosts at the median; 90 to 92 per cent of pages embed at least one third party. Source: HTTP Archive, Web Almanac 2025, "Third Parties" chapter. The count is of requests, not vendors: several requests may belong to the same service.

Every one of those services that processes personal data on your behalf, and an IP address already counts as personal data, needs a contract. This is not a formality but Art. 28 GDPR: processing by a processor is lawful only on the basis of a contract setting out subject matter, duration, nature and purpose. With the larger providers such a contract usually sits ready as a clause in the terms and needs only to be actively accepted. That is precisely what often does not happen, because nobody goes looking. Processing on behalf is the point least often checked and most easily fixed.

The practical route there is unglamorous: open the site in a browser, run the network panel, write down every third-party domain. What remains is your contract list. There are usually fewer vendors than requests, often somewhere between five and fifteen, and half of them were added years ago for a test nobody switched off.

What happens when a tool sits in the United States?

Then you need a basis for the transfer itself. Since 10 July 2023 there has again been an adequacy decision from the European Commission, the EU-US Data Privacy Framework. For providers certified under it, the transfer is covered without additional contracts of your own. The decision stands, but it stands less firmly than the quiet of recent years suggests.

Four-station timeline on the EU-US Data Privacy Framework: 10.07.2023 adequacy decision by the European Commission, 27.01.2025 three of five PCLOB members removed and the board loses its quorum, 03.09.2025 the General Court dismisses the Latombe annulment action in case T-553/23, an appeal remains open before the Court of Justice.
10.07.2023 adequacy decision; 27.01.2025 three of five PCLOB members removed, board without a quorum; 03.09.2025 Latombe action dismissed, case T-553/23; appeal pending before the Court of Justice. Sources: Commission Implementing Decision (EU) 2023/1795 and case T-553/23. Figures as at 30.08.2026.

This does not mean you have to avoid US tools. It means you should know which ones you use and how quickly you could replace them. Two questions are enough: which service currently holds which data, and how long the move would take if the basis fell away. Anyone who can answer that for their three most important tools has third-country transfers under control without having bought legal advice.

Why are the authorities reading privacy notices in 2026?

Because they agreed to. The European Data Protection Board picks one topic each year for the national supervisory authorities to examine together. In 2023 it was cloud services in the public sector, in 2024 the position of data protection officers, in 2025 the right of access. On 19 March 2026 this year's action began: transparency and information obligations under Art. 12 to 14 GDPR, with 25 participating authorities.

Art. 12 to 14 are the least glamorous part of the regulation and the part you can repair fastest on your own. They require it to say, in clear and plain language, who processes what, for what purpose, on which legal basis, for how long, who receives it, and what rights people have. The typical privacy notice satisfies that formally and fails on currency: it names services that left long ago and stays silent about the ones added last year. If somebody asks in 2026, that comparison is the audit. This is the cheapest of the three points, because it costs nothing but an hour of honesty.

What does a mistake cost, and where?

It varies, and in a direction most people find back to front. In Germany the banner hangs on the TDDDG, where section 28 TDDDG sets a ceiling of 300,000 euros. The processing behind it hangs on the GDPR, whose Art. 83(5) reaches 20 million euros or 4 per cent of worldwide annual turnover, whichever is higher.

Two ceilings compared: 20 million euros or 4 per cent of worldwide annual turnover under Art. 83(5) GDPR against 300,000 euros under section 28 TDDDG for storing on or reading from a device without consent.
Ceilings compared: up to 20,000,000 euros or 4 per cent of worldwide annual turnover under Art. 83(5) GDPR, up to 300,000 euros under section 28 TDDDG. Sources: Art. 83(5) GDPR and section 28 TDDDG. Both are ceilings, not standard penalties; small businesses operate in entirely different orders of magnitude.

These are maximums, not a forecast for a trades business with eight staff. What they do show is the ranking the legislator applied, and it runs exactly counter to the attention each part usually receives. The panel in the foreground carries the smaller number. What runs behind it carries the larger one. In daily life the trouble rarely arrives from a regulator anyway: it arrives from a customer, a competitor or a job applicant who reads the notice and asks a question.

What do you do with this?

Three steps, in this order, and none of them needs a law firm.

First, pull the list. Open the site, run the network panel, note every third-party domain. It takes twenty minutes and everything else builds on it. Without the list you are guessing.

Second, halve the list. One question per entry: what is this for? Anything customers never see and nobody ever reads goes. Every service you delete saves a consent, a contract, a line in the notice and a little load time. It is the only step that makes the site faster and more lawful at the same time.

Third, write down what is left. The remainder goes into the privacy notice, contracts get accepted where they sit ready, and the banner gets configured so that genuinely nothing loads before the click. After that, pull the list once a year and hold it against the notice.

Website privacy is not a legal project but a stocktake with three columns: what loads, who is allowed to, where it is written down. Do the stocktake once and an hour a year keeps it current. If you like, we will walk your site with you and hand the list back as a file, including the lines you can strike out yourself 🙂