GDPR for business websites: the ten things that actually apply
The ten obligations from the General Data Protection Regulation that a normal business website has to meet, in plain terms, with the primary sources.
The short answer
A normal business website processes personal data: the contact form, the email address someone sends, the server logs, the analytics, the newsletter list. That means the General Data Protection Regulation applies. It does not mean a small business needs a compliance department. Ten obligations cover almost everything a typical site has to do: have a legal basis for each processing purpose, tell people clearly what you do with their data, collect only what you need, delete it when you no longer need it, keep it secure, have written agreements with the providers who process it for you, know where data goes outside the EU, keep a short internal record of your processing, obtain consent before non-essential cookies, and be able to handle a request from someone exercising their rights. Most of that work is documentation and configuration rather than legal drafting. This is general information rather than legal advice; anything unusual, high-risk processing, a breach or a regulator’s letter deserves a qualified adviser.
The ten that apply
| # | Obligation | What it means for a website | Typical evidence |
|---|---|---|---|
| 1 | Legal basis | Each purpose needs one: contract, legitimate interest, consent, legal obligation | A line per purpose in your records |
| 2 | Information | A privacy statement that is accurate, findable and understandable | The published page, matching reality |
| 3 | Minimisation | Ask only for what the purpose needs; no optional curiosity fields | Form fields justified one by one |
| 4 | Storage limitation | Delete or anonymise when the purpose ends | A retention schedule that is actually applied |
| 5 | Security | Appropriate technical and organisational measures | HTTPS, access control, backups, the security checklist |
| 6 | Processor agreements | A written agreement with every provider processing data for you | Signed agreements on file for host, email, CRM, analytics |
| 7 | Transfers | Know where data is processed; use a lawful transfer mechanism outside the EU | A list of providers and locations |
| 8 | Records of processing | A short internal register of what you process, why, where and for how long | One document, kept current |
| 9 | Cookie consent | Consent before non-essential cookies and similar identifiers | A banner that actually controls the scripts, or no non-essential cookies at all |
| 10 | Individual rights | Handle access, correction, deletion and objection requests within a month | A written procedure and a log |
Getting a typical site compliant
- List every place personal data enters: forms, email, chat, analytics, bookings, newsletter, logs, uploads.
- For each, write the purpose, the legal basis, what is collected, where it goes and how long it is kept. That document is your record of processing.
- Cut the fields you cannot justify against the purpose.
- Set retention and make it real: a schedule, an owner and a recurring task.
- Collect the processor agreements from every provider; most publish them.
- Check locations: where each provider processes data, and the transfer mechanism if outside the EU.
- Rewrite the privacy statement from the record, so it is true rather than generic.
- Fix cookies: remove non-essential ones or gate them behind genuine consent.
- Write the rights procedure: who receives a request, how you verify identity, how you respond within a month.
- Review annually and whenever the site or the tools change.
Where the real risk sits
Not in the wording of the privacy page but in three places: marketing without a proper basis or an easy way to unsubscribe, which generates complaints; data kept forever because nobody set retention, which turns any breach into a bigger one; and a breach handled badly, without a procedure or a record. Those three account for most of the trouble small businesses actually meet, and the fixes are on the list above.
What this means for you
Ten obligations cover a normal business website: legal basis, information, minimisation, retention, security, processor agreements, transfers, records, cookie consent and individual rights. Build them from one document, your record of processing, which makes the privacy statement true and the rest follow. This is general information rather than legal advice; for a breach, high-risk processing or a regulator’s question, get qualified help.
Frequently asked questions
Does the GDPR really apply to a small brochure website?
Yes, if the site collects any personal data, which a contact form, an email address, a server log with IP addresses or most analytics all do. The regulation applies to the processing, not to the size of the business. What changes with size is proportionality: a small business with a form and cookieless analytics has a short, manageable set of obligations, not a compliance department's worth.
Do we need a data protection officer?
Only if your core activities involve large-scale regular monitoring of people or large-scale processing of special category data, or you are a public authority. Almost no small business website triggers that. You still need someone responsible for privacy in practice, which can be the owner or a manager, and access to qualified advice when something unusual happens.
What happens if we get it wrong?
For a small business the realistic consequences are a complaint to the supervisory authority, an instruction to fix something, and reputational damage, rather than a headline fine. Fines exist and scale with seriousness. The practical risk that bites small businesses is a data breach they handled badly, or a complaint about marketing consent, both of which are prevented by the basics on this page.
Sources
- EUR-Lex: Regulation (EU) 2016/679 (General Data Protection Regulation) (accessed 2026-09-12)
- Autoriteit Persoonsgegevens: AVG basis (accessed 2026-09-12)