Sandra Koelln Advocacia & Associados

Data protection in Germany: what your website must comply with

September 28, 2026 · By Dra. Sandra Koelln

Data protection in Germany: what your website must comply with

Running a business in Germany and putting a website online sounds simple: pick a nice template, publish it and start promoting. In practice, a website in Germany is also a legal document. Every form, cookie, font, embedded video or purchase button has legal consequences, and the rules became even stricter in 2026.

In this article we explain, in practical terms, what Brazilian entrepreneurs and professionals need to know about data protection in Germany, what changed for those who sell online, and why care begins as early as the build of the website and its systems.

DSGVO: the European law that applies to every website in Germany

The DSGVO (Datenschutz-Grundverordnung), known internationally as the GDPR, is the European data protection regulation. It applies to any company or professional processing personal data of people in the European Union, including those who only run a website with a contact form.

“Personal data” is any information that identifies someone directly or indirectly: name, e-mail, phone number, IP address, browsing data, purchase history.

Many people compare the DSGVO with Brazil’s LGPD. The principles are similar, but enforcement and the compliance culture in Germany are far more intense, and national laws complement the European regulation.

The laws every digital business in Germany needs to know

LawWhat it regulates in practice
DSGVOProcessing of personal data, data subject rights, privacy policy, contracts with suppliers
BDSGComplements the DSGVO under German law (e.g. employee data)
TDDDG (formerly TTDSG)Cookies and tracking technologies: require prior consent
DDG (formerly TMG)Mandatory Impressum, the legal notice (§ 5 DDG)
BGBDistance selling rules: order button, right of withdrawal and the new withdrawal button
UWGUnfair competition: the basis for the dreaded Abmahnungen

The website: where most mistakes happen

1. Impressum (legal notice)

Every website with a commercial purpose, including those of independent professionals, needs a complete Impressum reachable in no more than two clicks from any page: name, physical address (a P.O. box is not enough), quick means of contact (e-mail and phone) and, depending on the case, commercial register, VAT number (USt-IdNr.) and professional body details.

2. Privacy policy (Datenschutzerklärung)

It must genuinely describe what the website does: which tools it uses (Google Analytics, maps, videos, forms, scheduling, payments), for what purpose, on which legal basis and how long the data is kept. Copying a generic template that does not match the website is one of the most common mistakes.

3. Cookies and tracking

Under the TDDDG, analytics and marketing tools may only be activated after the visitor consents. The “Reject” button must be as easy as “Accept”. A banner that merely informs while already tracking is not compliant.

4. “Invisible” third-party services

Fonts, maps and videos loaded directly from external servers transmit the visitor’s IP address. In 2022 the Munich Regional Court I (LG München I, 3 O 17493/20) ordered a website owner to compensate a visitor precisely for loading Google Fonts without consent. The case triggered a wave of claims across the country.

5. Forms and security

Contact forms should collect only what is necessary, travel over HTTPS and deliver messages to a secure destination. Anyone processing data also needs data processing agreements (Auftragsverarbeitungsvertrag, art. 28 DSGVO) with hosting, e-mail tools and other suppliers.

Selling online in Germany: what changed on 19 June 2026

Those selling products or services online to consumers already had to follow strict rules, such as the final order button with unambiguous wording, for example “zahlungspflichtig bestellen” (order with obligation to pay, § 312j BGB). With a generic “Buy” or “Submit order”, the contract may not even come into existence.

Since 19 June 2026, a new obligation arising from Directive (EU) 2023/2673 has been in force: the withdrawal button (Widerrufsbutton, § 356a BGB). Anyone selling online to consumers must offer an easy-to-find function, in two steps, allowing the customer to withdraw within the statutory period. Sending a PDF or asking for an e-mail does not replace this function.

Without it, the consumer’s withdrawal period may extend to up to 12 months and 14 days — meaning the customer can return the product or cancel the service long after the purchase.

In practice: an online shop in Germany is not just a beautiful storefront, it is a checkout that follows the law and keeps following it when the law changes.

Systems and customer data: anonymisation and where data is stored

Data protection does not end with the website. CRMs, scheduling systems, client areas, spreadsheets and automations also process personal data and must be designed with this in mind from the outset (Privacy by Design, art. 25 DSGVO).

Anonymisation and pseudonymisation. Truly anonymised data, which no longer allows anyone to be identified, falls outside the DSGVO. Pseudonymised data (for example, with the name replaced by a code) remains personal data but greatly reduces the risk. Reports, tests and integrations should use as little identifiable data as possible.

Where data is stored. As a general rule, the DSGVO does not require data to stay in Germany. Within the EU and the European Economic Area it circulates freely. Transferring data outside the EU, however, requires a specific legal basis (arts. 44 et seq. DSGVO), such as an adequacy decision or standard contractual clauses.

And there are cases where keeping data on servers in Germany is the safer choice or even a requirement: professions bound by confidentiality (lawyers, doctors, psychologists and therapists, § 203 StGB), health data, contracts with public authorities or corporate clients that require national hosting. In those cases, choosing the “cheapest” cloud can become very expensive.

What mistakes cost

  • Fines of up to 20 million euros or 4% of global annual turnover, whichever is higher (art. 83 DSGVO).
  • Compensation to affected individuals, including for non-material damage (art. 82 DSGVO).
  • Abmahnungen: out-of-court warning letters from competitors or associations, with lawyer’s fees and an obligation to sign a declaration backed by a contractual penalty.
  • Invalid contracts or extended withdrawal periods in online shops.

For small businesses, a single warning letter can cost more than the entire website.

Law and technology have to work together

Legal compliance is not achieved through legal texts alone. It depends on how the website and the systems are built: which scripts load before consent, where the servers are, how the checkout works, what data a form actually stores.

That is why legal guidance works best alongside a technical team that understands the German rules. One example is RAMOA Digital, a digital media agency and software house based in Munich, specialised in businesses run by Brazilians in Europe. RAMOA develops websites, online shops and systems taking German legislation into account from the first line of code:

  • Impressum, privacy policy and cookie banner integrated and genuinely working (nothing loads before consent);
  • Fonts, maps and videos served in a DSGVO-compliant way;
  • Online shops with a compliant checkout, including the “zahlungspflichtig bestellen” button and the new withdrawal button;
  • Systems and automations with data minimisation and anonymisation, and hosting in Germany or the EU when the case requires it;
  • Ongoing support, because the law changes and the website has to change with it.
Transparency: RAMOA Digital is the technical partner of Sandra Koelln Advocacia & Associados and developed this website.

Quick checklist for your website

  • Complete Impressum, reachable in no more than two clicks
  • Privacy policy describing the tools actually in use
  • No analytics or marketing cookies before consent
  • Fonts, maps and videos with no data transmission without consent
  • HTTPS across the whole website
  • Data processing agreements (AVV) with suppliers
  • Online shop: “zahlungspflichtig bestellen” button and withdrawal button
  • Customer data minimised, protected and stored in the appropriate place

Do you have legal questions about your website, your online shop or your contracts in Germany? Talk to our firm.

Do you need to build or technically adapt your website or system? Get to know RAMOA Digital.

This article is for information purposes and does not replace individual legal advice.

Frequently Asked Questions

Yes. It applies to any person or company processing personal data for professional purposes, regardless of size.
Yes. The form collects personal data, and the visitor must be informed about the processing (art. 13 DSGVO).
You can, provided it is only activated after the visitor consents, it is described in the privacy policy and there is an adequate basis for the data transfer.
The obligation applies to contracts concluded online with consumers who have a right of withdrawal, which includes many services. Each case must be assessed individually.
Not always. Within the EU data can circulate freely, but professions bound by confidentiality, sensitive data and some contracts require additional care, and then hosting in Germany is often the best choice.