GDPR for business websites: the ten things that actually apply

The ten obligations from the General Data Protection Regulation that a normal business website has to meet, in plain terms, with the primary sources.

4 minread 934words last updated

The short answer

A normal business website processes personal data: the contact form, the email address someone sends, the server logs, the analytics, the newsletter list. That means the General Data Protection Regulation applies. It does not mean a small business needs a compliance department. Ten obligations cover almost everything a typical site has to do: have a legal basis for each processing purpose, tell people clearly what you do with their data, collect only what you need, delete it when you no longer need it, keep it secure, have written agreements with the providers who process it for you, know where data goes outside the EU, keep a short internal record of your processing, obtain consent before non-essential cookies, and be able to handle a request from someone exercising their rights. Most of that work is documentation and configuration rather than legal drafting. This is general information rather than legal advice; anything unusual, high-risk processing, a breach or a regulator’s letter deserves a qualified adviser.

The ten that apply

#ObligationWhat it means for a websiteTypical evidence
1Legal basisEach purpose needs one: contract, legitimate interest, consent, legal obligationA line per purpose in your records
2InformationA privacy statement that is accurate, findable and understandableThe published page, matching reality
3MinimisationAsk only for what the purpose needs; no optional curiosity fieldsForm fields justified one by one
4Storage limitationDelete or anonymise when the purpose endsA retention schedule that is actually applied
5SecurityAppropriate technical and organisational measuresHTTPS, access control, backups, the security checklist
6Processor agreementsA written agreement with every provider processing data for youSigned agreements on file for host, email, CRM, analytics
7TransfersKnow where data is processed; use a lawful transfer mechanism outside the EUA list of providers and locations
8Records of processingA short internal register of what you process, why, where and for how longOne document, kept current
9Cookie consentConsent before non-essential cookies and similar identifiersA banner that actually controls the scripts, or no non-essential cookies at all
10Individual rightsHandle access, correction, deletion and objection requests within a monthA written procedure and a log

Getting a typical site compliant

  1. List every place personal data enters: forms, email, chat, analytics, bookings, newsletter, logs, uploads.
  2. For each, write the purpose, the legal basis, what is collected, where it goes and how long it is kept. That document is your record of processing.
  3. Cut the fields you cannot justify against the purpose.
  4. Set retention and make it real: a schedule, an owner and a recurring task.
  5. Collect the processor agreements from every provider; most publish them.
  6. Check locations: where each provider processes data, and the transfer mechanism if outside the EU.
  7. Rewrite the privacy statement from the record, so it is true rather than generic.
  8. Fix cookies: remove non-essential ones or gate them behind genuine consent.
  9. Write the rights procedure: who receives a request, how you verify identity, how you respond within a month.
  10. Review annually and whenever the site or the tools change.

Where the real risk sits

Not in the wording of the privacy page but in three places: marketing without a proper basis or an easy way to unsubscribe, which generates complaints; data kept forever because nobody set retention, which turns any breach into a bigger one; and a breach handled badly, without a procedure or a record. Those three account for most of the trouble small businesses actually meet, and the fixes are on the list above.

What this means for you

Ten obligations cover a normal business website: legal basis, information, minimisation, retention, security, processor agreements, transfers, records, cookie consent and individual rights. Build them from one document, your record of processing, which makes the privacy statement true and the rest follow. This is general information rather than legal advice; for a breach, high-risk processing or a regulator’s question, get qualified help.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Does the GDPR really apply to a small brochure website?

Yes, if the site collects any personal data, which a contact form, an email address, a server log with IP addresses or most analytics all do. The regulation applies to the processing, not to the size of the business. What changes with size is proportionality: a small business with a form and cookieless analytics has a short, manageable set of obligations, not a compliance department's worth.

Do we need a data protection officer?

Only if your core activities involve large-scale regular monitoring of people or large-scale processing of special category data, or you are a public authority. Almost no small business website triggers that. You still need someone responsible for privacy in practice, which can be the owner or a manager, and access to qualified advice when something unusual happens.

What happens if we get it wrong?

For a small business the realistic consequences are a complaint to the supervisory authority, an instruction to fix something, and reputational damage, rather than a headline fine. Fines exist and scale with seriousness. The practical risk that bites small businesses is a data breach they handled badly, or a complaint about marketing consent, both of which are prevented by the basics on this page.

Sources

  1. EUR-Lex: Regulation (EU) 2016/679 (General Data Protection Regulation) (accessed 2026-09-12)
  2. Autoriteit Persoonsgegevens: AVG basis (accessed 2026-09-12)