Start a Project

Systems

GDPR for a small website, in practical terms

Not legal advice — the concrete list of what a small business site has to have, and the three things most sites get wrong.

The GDPR is treated as either terrifying or ignorable. For an ordinary small business website it is mostly a short checklist. This is the shape of it; the binding detail for your situation comes from a lawyer.

The minimum for an ordinary business site

  • A privacy policy naming who is responsible, what data is collected, why, on what legal basis, how long it is kept, who else sees it, and the visitor's rights. Reachable from every page.
  • A lawful basis for each processing activity. A contact form is generally covered by legitimate interest or pre-contractual steps; a newsletter needs consent; analytics needs consent in the EU.
  • Consent that is real where consent is the basis. Unticked, specific, withdrawable, and logged.
  • Data minimisation. Do not collect a phone number you never call.
  • Processor agreements with anyone handling data for you — your host, your email provider, your analytics tool. Usually a form on their site.
  • A record of processing activities. Even small businesses generally need one; it is a document, not a project.
  • Encryption in transit. HTTPS everywhere, which you have anyway.

Three things most sites get wrong

  1. Fonts loaded from Google. Loading a font from a third-party server transmits the visitor's IP address before any consent. German courts have awarded damages for exactly this. Self-host your fonts — it is faster anyway, and it removes the problem completely.
  2. Analytics that fires before consent. If the script loads as the banner appears, the banner is decoration. Either gate it properly or use a tool that does not require consent.
  3. Contact form data kept forever. Define a retention period and actually delete. "We keep everything" is not a policy.

Embeds are the quiet risk

A YouTube video, a Google Map, a social feed, a chat widget — each contacts a third party as the page loads. Use click-to-load for all of them. It solves the legal problem and improves page speed at the same time.

If something goes wrong

A personal data breach generally has to be reported to the supervisory authority within 72 hours of becoming aware, and to affected individuals if the risk is high. Know now who makes that call, because the clock is short and it starts without warning.

Working on something like this?

Tell us what you are building — we reply to every enquiry.

Start a Project