GDPR advice tends to arrive in two unhelpful forms. Either a warning about enormous fines, or a cookie banner sold as though it settles the matter.
Neither is accurate. GDPR website compliance for a typical small business is a manageable set of practical obligations. This is not legal advice — for anything unusual, take proper counsel — but it covers what actually applies to most sites.
When it applies to you
GDPR applies if you offer goods or services to people in the EU or UK, or if you monitor their behaviour — which includes analytics.
Being based elsewhere does not exempt you. If EU or UK residents can fill in your contact form and you track visitors, you are in scope. Similar principles now apply in many other jurisdictions, so this is increasingly the baseline rather than a regional quirk.
Personal data is broader than you think
People assume it means names and addresses. It means anything that can identify someone, directly or in combination:
- Names, email addresses, phone numbers, postal addresses
- IP addresses
- Cookie and device identifiers
- Order history and account details
- Anything in a form submission, including the free-text message
That last one catches people out. Contact form submissions sitting in a website database for years are personal data you are responsible for.
What you actually have to do
Have a lawful basis
You need a defensible reason for processing. For most small business sites that is consent for marketing, or legitimate interests for responding to an enquiry.
Practically: someone filling in a contact form has clearly asked you to reply. That does not mean you can add them to a newsletter. Those are different purposes requiring different bases.
Write a real privacy policy
Not a template with someone else's company name still in it. It should say what you collect, why, how long you keep it, who else sees it, and how someone exercises their rights.
Third parties matter here. Analytics providers, email platforms, payment processors, hosting and chat widgets all process data on your behalf and should be named.
Handle cookies properly
The part most sites get wrong. Non-essential cookies require consent before they are set — not after, and not on the assumption that continued browsing implies agreement.
A compliant banner rejects as easily as it accepts, does not pre-tick consent boxes, blocks non-essential scripts until consent is given, and lets people change their mind later.
A banner that says "by using this site you accept cookies" while analytics has already loaded is not compliance. It is decoration.
Design forms honestly
Collect only what you need — every extra field is data you must protect and justify. Keep marketing opt-in separate from the form's purpose, unticked by default. Explain briefly what happens to the data.
Be able to answer rights requests
People can ask what data you hold, request corrections, ask for deletion, or ask for a copy. Generally you have one month.
You do not need a sophisticated system. You do need to know where the data lives — website database, email inbox, CRM, email platform — so you can answer without a panic.
Keep it only as long as you need it
Indefinite retention is a common failing. Contact form entries from six years ago serve no purpose and are pure liability. Set a retention period and actually delete.
Where security comes in
This is the part usually left out of GDPR checklists, and it is explicit in the regulation. You must protect personal data with appropriate technical measures.
In practice that means keeping software patched, controlling who has access, encrypting data in transit, and being able to detect a breach. A site running a plugin with a known vulnerability is not meeting that standard, regardless of how good the privacy policy is.
There is also a hard deadline. A personal data breach must generally be reported to the regulator within 72 hours of becoming aware of it.
Consider what that requires. If your site is compromised and you find out three weeks later because a customer noticed, you have already missed the window — and "we did not know" is not a defence when nothing was monitoring.
This is why our security monitoring service is a compliance measure as much as a technical one. Detection time is a regulatory concern.
The realistic checklist
- Audit what personal data the site actually collects and where it ends up
- Write an accurate privacy policy naming your third parties
- Install a consent tool that genuinely blocks scripts before consent
- Separate marketing opt-in from enquiry forms
- Set retention periods and delete old submissions
- Serve everything over HTTPS
- Keep software patched and access controlled
- Restrict who can export customer data
- Know how you would detect and report a breach in 72 hours
- Review annually
Common mistakes
The recurring ones are worth naming: a cookie banner that loads analytics anyway, a privacy policy naming a different company, no way to withdraw consent, marketing consent bundled into a contact form, keeping every submission forever, and no plan at all for detecting a breach.
None are difficult to fix. They persist because nobody owns them.
Proportionality
Enforcement against small businesses is generally proportionate and focused on genuine carelessness — ignoring complaints, marketing without consent, or losing data through obvious negligence.
The realistic risk for most small businesses is not a headline fine. It is a complaint that becomes a time-consuming correspondence, or a breach handled badly in public.
Doing the basics properly removes most of that exposure.
If you sell into the Gulf
The UAE and Saudi Arabia have their own regimes with meaningful differences, particularly around data residency. Our PDPL compliance page covers what applies there.
Where we can help
We are not lawyers and will not pretend otherwise. What we handle is the technical side: securing personal data properly, implementing consent tooling that genuinely blocks scripts, tightening access, and monitoring so a breach is detected in hours rather than weeks.
Get in touch and tell us what your site collects. We will tell you plainly where the technical gaps are.
Get Shielded
We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.