Legal and compliance

GDPR on a business website, 6 things you must take care of

GDPR on a business website, 6 things you must take care of

GDPR sounds like a topic for lawyers and big corporations. In reality it applies to every site that collects any data, and a contact form, a newsletter or plain visit statistics are already collecting data. The good news: at the level of a typical business site it is not complicated. Here are six things worth having in order.

Note: this is a practical guide, not legal advice. If you process sensitive data or run a higher-risk business, consult a lawyer or a data protection specialist.

1. A privacy policy: mandatory

This is a document that tells visitors what data you collect, why, for how long and to whom you pass it (e.g. to a newsletter system or an analytics tool). It must be easily accessible, usually as a link in the footer, visible on every page. It is the absolute basis to start with.

2. Consent on forms

On every form where someone leaves data (contact, enquiry, newsletter), there should be clear information about why you collect this data and, if needed, a consent checkbox. The key rule: consent must be voluntary and not ticked by default. A pre-ticked checkbox is a common mistake.

3. A cookie banner that actually works

If your site uses cookies for more than essential operation (e.g. analytics, advertising pixels), you need a cookie consent banner. Importantly, it should do more than just display a message: the user should have a real choice, to accept, reject or pick categories. A "click anything, we collect anyway" banner does not do its job.

4. Collect only what is needed

One of GDPR's basic principles is data minimisation. If a name and email are enough to answer an enquiry, do not ask for an address, ID number or date of birth. Less data collected means fewer obligations, lower risk in the event of a leak and greater customer trust.

5. Secure the data you have

GDPR requires you to protect the data you collect. At the site level this is mainly:

  • HTTPS across the whole site, so form data travels encrypted,
  • up-to-date software and plugins (a leak through a vulnerable plugin is also a data protection breach),
  • strong passwords and restricted access to the panel where form data is visible,
  • sensible retention, do not keep emails and enquiries you no longer need forever.

6. Prepare for users' rights

Everyone whose data you hold has the right to, among other things, view, correct and delete it (the "right to be forgotten"). It is worth knowing where that data is with you (in the inbox? in the shop database? in the newsletter tool?), so that you can react quickly to such a request.

Site security is part of GDPR compliance

It is worth noting that many GDPR requirements come down to the same thing as good site care: up-to-date software, HTTPS, strong protections and order in the data. A leak of customer data through a neglected site is not only an image problem, it is also a data protection breach.

Want to check whether your site has the basics in order, a privacy policy, HTTPS, a cookie banner and secure forms? Get in touch, we will review it together.

Want to check your site right away? Run the free GDPR & cookies test, it will show tracking scripts loaded without consent, the cookie banner and the privacy policy.

Related articles

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.