GDPR Website Checklist for Small Businesses

The General Data Protection Regulation (GDPR) applies to any website that handles the personal data of people in the EU and EEA — even a one-person business with a contact form. The good news: the core obligations are manageable, and most of a small site’s compliance comes down to a handful of concrete steps.

The short version

Know your lawful basis for every piece of data you collect, publish a clear privacy policy, get real cookie consent before loading non-essential trackers, be ready to answer data requests, know your 72-hour breach duty, and have written agreements with your processors. This is general information, not legal advice.

1. Identify a lawful basis for every data use

GDPR requires a valid legal reason before you process personal data. The six lawful bases are consent, contract, legal obligation, vital interests, public task and legitimate interests. For a typical small site: fulfilling an order runs on contract, a newsletter signup runs on consent, and basic fraud prevention often runs on legitimate interests. Write down which basis covers each activity before you collect anything.

2. Publish a clear, honest privacy policy

Every site that collects data needs an accessible privacy policy that names what you collect, why, your lawful basis, who you share it with, how long you keep it, and how people can exercise their rights. Plain language beats legalese — regulators expect it to be genuinely understandable. Our privacy policy essentials guide breaks down each required section.

3. Handle cookies and trackers correctly

Non-essential cookies — analytics, advertising, embedded media that profiles users — require freely given consent before they load. No pre-ticked boxes, and rejecting must be as easy as accepting. Strictly necessary cookies (a login session, a shopping cart) do not need consent. See cookie consent done right for the details most banners get wrong.

4. Respect data subject rights

People whose data you hold can ask to access it, correct it, delete it, restrict its use, or receive a portable copy. You generally have one month to respond, usually free of charge. Practical prep: know where personal data lives across your systems (CRM, email tool, order database, backups) so you can actually find and act on it when a request arrives.

ObligationWhat it means for a small site
Lawful basisA documented legal reason for each data use
TransparencyA readable privacy policy that is easy to find
ConsentOpt-in before non-essential cookies and marketing
Data subject rightsAnswer access and deletion requests within a month
Breach notificationReport qualifying breaches within 72 hours
Processor agreementsWritten contracts with your vendors

5. Know your breach notification duty

If personal data is exposed, lost or stolen and it poses a risk to people, you must notify your supervisory authority within 72 hours of becoming aware. Where the risk is high, you must also tell the affected individuals. Reducing that risk in the first place is largely a technical job — strong encryption, patched software and sensible access control. You can start with a free security scan and our headers check to spot obvious gaps.

6. Get processor agreements in place

Any third party that handles data on your behalf — hosting, email marketing, payment gateways, analytics — is a “processor.” GDPR requires a written data processing agreement with each one. Most reputable vendors offer a standard DPA you can accept; collect and file them so you can show the chain of responsibility.

Tip. Data minimisation is your friend. Every field you don’t collect is data you don’t have to protect, disclose or delete. Trim your forms to what you genuinely need.

What non-compliance can cost

Serious GDPR infringements can carry administrative fines of up to €20 million or 4% of global annual turnover, whichever is higher. For a small business the practical risks are more often complaints, remediation orders and reputational damage — but the ceiling is real and worth respecting. For a wider view of overlapping EU rules, see our compliance overview.

This guide is general information to help you get oriented, not legal advice. For decisions specific to your business, consult a qualified data protection professional.

Frequently asked questions

Does GDPR apply to my small website?

If you offer goods or services to, or monitor the behaviour of, people in the EU or EEA, it applies regardless of where your business is based or how small it is.

Do I need a cookie banner?

You need consent before loading non-essential cookies such as analytics and advertising. If you only use strictly necessary cookies, you can inform users without asking for consent.

How fast must I respond to a data request?

Generally within one month of receiving it, and usually free of charge. Complex requests can be extended, but you must tell the person and explain why.

Related guides

Check your site against this guide

Run a free ScanOpsPro scan and see how your site handles the fundamentals.

Run a free scan