← Back to blog

GDPR checklist for small websites

21/07/2026

Most small site owners know two things about GDPR: that it exists and that the fines are large. What rarely gets said is that for a typical small business site — a brochure site, a contact form, some analytics — compliance is an afternoon of work.

Does GDPR apply to you

It applies if you process personal data of anyone in the EU. Personal data means names, emails and phone numbers, but also IP addresses and cookie identifiers. In practice: if you have a contact form or analytics and someone in the EU visits your site, it applies. The UK has its own near-identical version, so one set of measures covers both.

Six things your site must have

  • A privacy policy on its own page, linked from the footer. It must state what you collect, why, how long you keep it, who you share it with, and how someone requests deletion.
  • A lawful basis for each processing activity. For a contact form that is usually legitimate interest or pre-contract steps — you do not need consent. For a newsletter you do need explicit consent.
  • A cookie banner that actually blocks. This is the most common failure: the banner shows, but Analytics has already loaded before the visitor clicked anything. Analytics and marketing scripts may only fire after consent.
  • Rejecting must be as easy as accepting. A "Reject all" button needs the same prominence as "Accept all". Buried under "Settings" does not comply.
  • No pre-ticked boxes. A newsletter checkbox on a contact form must start empty, and that consent must be separate from sending the message.
  • HTTPS. Transmitting personal data unencrypted is a breach in itself. SSL is free today and included in every one of our plans.

Records of processing and processor agreements

Organisations under 250 employees are largely exempt from full records, but a one-page table is still worth keeping: what data, where it is stored, for how long. With every external service that touches your users' data — hosting, email provider, CRM — you need a data processing agreement. Serious providers have one ready to sign or accept in the control panel.

Where the data physically sits

Transferring data outside the EU is not forbidden, but it requires an additional legal mechanism. The simplest answer is to keep the server in the EU or an adequacy-decision country. If you are choosing a host and have EU customers, server location is worth asking about before you buy.

Deadlines to remember

  • 30 days to respond to a subject request (access, correction, deletion).
  • 72 hours to report a serious data breach to the supervisory authority.
  • Delete when the purpose ends — five-year-old contact form messages have no basis sitting in your inbox.

A quick check you can run today

Open your site in a private window with developer tools on the Network tab. Before clicking anything on the banner, look for google-analytics or a Facebook pixel loading. If they load, you have half an hour of work ahead. In practice this is the single most common and most visible violation.

100% GUARANTEE30-day money back

30-day money back

No questions asked. Full refund if you are not satisfied.