GDPR checklist for your website: what you actually need to have - Zephyra Studio
GDPR (General Data Protection Regulation) is an EU rule, but it affects any site with visitors from the EU/EEA, regardless of where the business is registered. This is NOT legal advice, for a final assessment of your specific situation always consult a lawyer, but here is a concrete, practical list of what most small sites actually need to have.
Cookie consent banner: consent BEFORE loading
Non-essential cookies (analytics, advertising, social media) must not load BEFORE a visitor gives consent, this is a common mistake, a banner that shows up while the scripts load in the background regardless of the choice made. Declining must be just as easy as accepting (one click for either), not hidden behind extra clicks or fine print.
Essential cookies (e.g. ones that remember cart items or a login session) do not require consent since they are necessary for the basic site function the visitor requested.
Privacy policy: must match what is actually collected
The privacy policy must accurately describe what data the site collects (email, name, IP address through analytics), why, how long it is kept, and who it is shared with (e.g. third parties like an email provider or analytics tool). A generic policy copied from another site that does not match actual collection is riskier than having none, since it actively states inaccurate things.
Forms: clear about what happens to the data
Every form that collects data (contact, newsletter signup, calculator) should have a clear note about what happens to the submitted data, in practice a short sentence or a link to the privacy policy right next to the form, not just buried somewhere deep on the site.
Newsletter signup specifically requires explicit opt-in (an active checkbox, never pre-checked) - this is one of the most commonly violated GDPR obligations on small sites.
Right to erasure and data access
Visitors have the right to request deletion of their data or insight into what is stored about them. For a small site this practically means a clear contact (an e-mail) where such a request can be sent, and an internal process (even a simple one) to actually fulfil the request within a reasonable time, not just a formal statement with no real mechanism behind it.
Source
Key takeaways
- Non-essential cookies load ONLY after consent, not before - a common technical mistake, not just a legal one.
- The privacy policy must accurately match actual data collection, not be a generic copy from another site.
- Newsletter signup requires an active opt-in, never a pre-checked box.
- The right to erasure/access requires a real mechanism to fulfil requests, not just a formal statement.
- This is a practical overview, not legal advice, consult a lawyer for a final assessment of your situation.
Conclusion
GDPR compliance is not a one-time task, it changes as you add new tools (a new analytics service, a new marketing channel) that collect data. Our GDPR and accessibility service includes baseline compliance as a standard part of building a site, with a recommendation for legal review before launch for any site targeting the EU market.
Frequently asked questions
GDPR (General Data Protection Regulation) is an EU rule, but it affects any site with visitors from the EU/EEA, regardless of where the business is registered. This is NOT legal advice, for a final assessment of your specific situation always consult a lawyer, but here is a concrete, practical list of what most small sites actually need to have.