Funny to speak about security and a GDPR fine for a website that hasn't HTTPS activated...
There are no input fields, no requests sent with personal information at all etc.
Everything that's questionable already comes over HTTPS on their site though, like Facebook content etc.