Skip to content

Blog · Compliance

GDPR for websites: what small businesses need to know

The rules that matter for a typical business website: what personal data you collect, the privacy policy, cookies, contact forms, service providers and visitors’ rights. Practical, not legal advice.

The General Data Protection Regulation (Regulation (EU) 2016/679) has applied since 25 May 2018. It covers any organisation that processes personal data of people in the EU – including through a simple contact form or analytics on a website.

What counts as personal data on a website

The essentials for your website

Visitors’ rights

People can ask to access, correct or delete their data, object to some uses, or withdraw consent. Make it easy to contact you about this – an email address in the privacy policy is enough – and answer within the legal deadline, generally one month.

Do you need a Data Protection Officer?

Most small businesses do not. A DPO is mandatory for public authorities and for organisations whose core activities involve large-scale, regular monitoring of people or large-scale processing of special categories of data, such as health data.

Quick checklist

Frequently asked questions

It can – if they offer goods or services to people in the EU or monitor their behaviour. Check your situation with a lawyer.

No. It covers consent for cookies, but you also need a privacy policy, secure processing and agreements with your providers.

No. This article explains common technical and practical requirements. For your specific obligations, consult a lawyer or data protection specialist.

Need help with your website?

We design, build and maintain WordPress websites and WooCommerce stores. Tell us what you need and get a fixed-price quote.