Blog · Compliance
GDPR for websites: what small businesses need to know
The rules that matter for a typical business website: what personal data you collect, the privacy policy, cookies, contact forms, service providers and visitors’ rights. Practical, not legal advice.
The General Data Protection Regulation (Regulation (EU) 2016/679) has applied since 25 May 2018. It covers any organisation that processes personal data of people in the EU – including through a simple contact form or analytics on a website.
What counts as personal data on a website
- Names, email addresses and phone numbers sent through forms
- IP addresses and online identifiers, for example in server logs or analytics
- Cookies and similar identifiers used to track visitors
- Customer and order data in an online store
- Newsletter subscriber lists
The essentials for your website
- A clear privacy policy that explains what data you collect, why, on what legal basis, how long you keep it and who you share it with
- Consent for non-essential cookies – analytics and marketing cookies need consent before they are set; strictly necessary cookies do not
- Minimal forms – ask only for the data you need to answer the request
- A legal basis for each use – for example, answering an enquiry or a contract, and consent for newsletters
- Agreements with processors – hosting, email, analytics and form tools that process data on your behalf should have a data processing agreement
- Security – HTTPS, updated software, strong passwords and limited admin access
- A plan for breaches – some personal data breaches must be reported to the supervisory authority within 72 hours
Visitors’ rights
People can ask to access, correct or delete their data, object to some uses, or withdraw consent. Make it easy to contact you about this – an email address in the privacy policy is enough – and answer within the legal deadline, generally one month.
Do you need a Data Protection Officer?
Most small businesses do not. A DPO is mandatory for public authorities and for organisations whose core activities involve large-scale, regular monitoring of people or large-scale processing of special categories of data, such as health data.
Quick checklist
- Privacy policy and cookie policy published and linked in the footer
- Cookie banner that blocks analytics and marketing until consent
- Contact forms ask only for necessary data and link to the privacy policy
- Data processing agreements with hosting and other providers
- Backups, updates and HTTPS in place
- A way for people to exercise their rights
Frequently asked questions
Does GDPR apply to companies outside the EU?
It can – if they offer goods or services to people in the EU or monitor their behaviour. Check your situation with a lawyer.
Is a cookie banner enough for compliance?
No. It covers consent for cookies, but you also need a privacy policy, secure processing and agreements with your providers.
Is this legal advice?
No. This article explains common technical and practical requirements. For your specific obligations, consult a lawyer or data protection specialist.
Need help with your website?
We design, build and maintain WordPress websites and WooCommerce stores. Tell us what you need and get a fixed-price quote.

