Trend Radar is our weekly summary of news that matters to freelancers and small businesses with a website. Week 36 covers campaign measurement, privacy processes, urgent browser updates and safe use of AI agents.

On September 2, Google published a new Ads & Commerce Blog episode about building a reliable measurement stack, including attribution, incrementality and media mix models. Small businesses do not need enterprise dashboards to learn the key lesson: paid campaigns should be judged by real enquiries, bookings and sales, not only by clicks.
What does this mean for you? Check the basics first. Is the contact form tracked as a conversion? Are phone clicks and bookings measured? Do landing pages, thank-you pages and consent settings match? Without clean measurement, weak campaigns can look good and good campaigns can look too expensive.
The German Datenschutzkonferenz announced a resolution on standardized review processes for privacy requirements in online public services on September 2. On August 31, it also published the English version of its requirements for data protection certification schemes, version 3.0. This does not directly regulate every small company website, but it shows the direction: privacy is a process, not a one-time footer text.
What does this mean for you? Treat GDPR duties like website maintenance. Document which forms collect data, which tools are embedded, who has access and whether a data processing agreement is required. After adding plugins, tracking, newsletters or booking tools, review the privacy notice.
heise online reported on September 4 that Google closed several Chrome browser vulnerabilities and that one flaw is already being exploited. For website owners, this matters because the browser is the door to CMS logins, webmail, shop systems, cloud storage and hosting panels.
What does this mean for you? Update browsers on all office devices promptly and verify that automatic updates are active. Protect WordPress, shop, hosting and email accounts with two-factor authentication, separate users and no shared admin accounts. A compromised device can put even a well-maintained website at risk.
heise covered a security analysis on September 4 involving OpenAI agents and Hugging Face. Beyond the single case, the trend matters: AI agents read web pages, execute steps and may access files or external services. Malicious web content and prompt injection can influence such systems.
What does this mean for you? Do not give AI tools broad access to mailboxes, customer data, website backends or cloud folders too early. Start with limited tasks: drafts, summaries, ideas and internal checklists. Anything involving customer data, contracts, prices or credentials needs human approval before action.
Custom web design, German hosting, maintenance and personal support in one monthly package.
Book a free consultation