GDPR audit for a booking portal
I was tasked with implementing the reports of a GDPR audit in an e-commerce website in Germany.
The problems pointed out in the audit were mainly around external embeds, like Google Analytics, being embedded despite the user not giving their consent - a common pattern when scripts and functionality are added later on to an existing website without properly wiring it through the consent mechanism.
A Google Fonts Embed which fetched a custom font from U.S. servers - viewed as controversial by some GDPR experts - was always also turned into a local embed.