GDPR for Your Website – What You Need to Have

GDPR for Your Website – What You Need to Have

GDPR website requirements apply to every business that collects data from EU users – from a local service provider with a contact form to an international e-commerce store. The problem is that most website owners either don’t know what they actually need, or copy someone else’s privacy policy and hope for the best. That’s a mistake that can cost you anywhere from a regulatory warning to a fine worth a percentage of your annual turnover.

This article is a concrete checklist. No legal jargon, no scare tactics. Just what you need on your website and why.

What is GDPR and who does it apply to

GDPR (General Data Protection Regulation) is EU law that has been in force since May 2018. It applies to anyone processing personal data of EU citizens – and personal data means anything that can identify a person: email address, name, phone number, IP address, cookies.

If your website has a contact form, newsletter signup, Google Analytics, Facebook Pixel, or a shopping cart – you are processing personal data. It doesn’t matter whether you’re a sole trader based in Kraków or a limited company serving clients across Germany and France. GDPR applies.

It’s also worth remembering that a website that converts visitors into clients must also look credible from a legal standpoint. A missing privacy policy is one of the signals that turns potential clients away before they even read your offer.

GDPR website requirements – the complete list

Privacy policy

Mandatory. It must explain in plain language: who is the data controller, what data you collect, for what purpose, how long you store it, whether you share it with third parties (Google, Meta, payment processors), and what rights the user has (access, deletion, objection).

A minimum privacy policy covers 8-10 sections. A document copied from a competitor or generated by a random online tool may not account for your specific tools and processes – and that’s exactly what regulators check during an audit.

Data collection notice at forms

Every form where you collect data (contact, quote request, newsletter, account registration) must include a data collection notice. It doesn’t have to be long – a single sentence with a link to the full privacy policy and the name of the data controller is enough. But it must be there.

Missing a data notice at a form is one of the most common violations found during data protection audits. A website that loses clients through poor experience often loses them through lack of trust too – and missing legal notices are exactly that kind of trust-breaking signal.

Cookie consent

If you use cookies that are not technically necessary for the website to function – and almost every analytics and marketing tool does – you must obtain active consent from the user before they are activated.

“Active consent” is not a banner with a single “OK” button and pre-ticked boxes. It means giving the user a real choice: they must be able to reject analytics and marketing cookies just as easily as accepting them. The law is precise here: no option to decline = no valid consent.

Cookie banners also touch on UX and UI design – a poorly designed banner is both legally ineffective and irritating for users. The two problems reinforce each other.

Records of processing activities

This doesn’t need to be visible on your website, but you do need to maintain it internally. It’s a document describing what data you process and how – for each process: the purpose, legal basis, categories of data, retention period, and recipients. The obligation applies to most businesses (exception: companies with fewer than 250 employees that process data only occasionally and without high risk – but keeping it is good practice regardless).

Data processing agreements

If you share personal data with external parties – your hosting provider, marketing agency, email platform, CRM – you need signed data processing agreements (DPAs) with each of them. These documents define what they can do with your clients’ data.

Many business owners don’t realise this applies to their hosting provider. Popular hosting companies have DPA templates ready – but you need to consciously sign them, not assume they’re “somewhere in the terms and conditions”.

How to implement GDPR on your website – where to start

Map what you collect. Before writing any document, go through your website and list: every form, every external tool (Analytics, Pixel, Hotjar, Mailchimp), every login point. This is the foundation – you can’t accurately describe in a privacy policy what you don’t know you have.

Don’t copy someone else’s policy. Beyond the copyright issue, their policy was written for their processes. If you use different tools, store data differently, or have a different legal basis for your newsletter – the document will simply be incorrect.

Sort out your cookies properly. This is an area where data protection authorities are actively auditing. Make sure your cookie banner actually blocks scripts before consent is given, rather than just displaying a nice button.

If you’re unsure how to evaluate the external partners you share data with – hosting providers, agencies, mailing platforms – the questions worth asking before signing with anyone are similar to those you’d ask when choosing a web agency.

The most common GDPR mistakes on websites

No privacy policy at all. Less common than it used to be, but still found – particularly on older websites that haven’t been updated since 2017.

A privacy policy from 2018 that hasn’t been updated. Laws change, tools change, purposes of processing change. A privacy policy is a living document – it should be reviewed at minimum once a year.

One checkbox for everything. Consent must be granular – separate for analytics cookies, separate for marketing cookies. A single checkbox covering everything has been non-compliant since the European Data Protection Board’s decisions in 2020.

No data notice at the contact form. Described above, but worth repeating – it’s one of the most common and most visible violations.

Transferring data to the US without a legal basis. Tools like Google Analytics, Meta Pixel, and Mailchimp involve data transfers to the US. After the invalidation of Privacy Shield in 2020 (Schrems II ruling), this area is particularly sensitive. Most large providers have compliance mechanisms (Standard Contractual Clauses) – you need to make sure they are activated in your account settings.

Can a generator replace a lawyer?

It depends on the scale. For a small business without complex data processing – a good GDPR document generator provides a solid base that you can supplement with the specifics of your own operation. For a business processing sensitive data, running an e-commerce store with thousands of monthly transactions, or operating across multiple EU countries simultaneously – a lawyer is necessary.

The DotLineCode GDPR Generator lets you create documents online, manage them across your entire team, and generate data collection notices tailored to specific forms. You can try the GDPR generator with a free 30-day trial – no commitment, no credit card required to start.

How often should you update your GDPR documents

At minimum once a year – and always after any change that affects data processing: a new tool on your website, a new purpose for collecting emails, a change of processor, or changes in the law. This is not a one-time task. GDPR is a process, not a project.

Summary – what your website needs

Four things are the absolute minimum: a privacy policy accessible from every page, a data notice at every form that collects data, a cookie banner with a genuine option to decline, and data processing agreements with external parties. The records of processing activities is an internal obligation, but also a useful map of your own processes.

GDPR website compliance isn’t complicated – it’s systematic. It requires a one-time mapping exercise and regular maintenance. Businesses that do this properly don’t just avoid fines – they build trust with clients who know their data is handled responsibly.

DotLineCode builds websites that meet both technical and legal standards. Our GDPR Generator is a tool for businesses that want their documentation in order without involving a lawyer for every update.

Author
Katarzyna Hernik

Contact

Call us up - help us help you.

footerlogo

Contact us

DotLineCode Sp. z o. o. Plac Wolnica 13/10
Cracow 31-060
Poland