GDPR Website Checklist for Small Businesses
The General Data Protection Regulation (GDPR) applies to any website that handles the personal data of people in the EU and EEA — even a one-person business with a contact form. The good news: the core obligations are manageable, and most of a small site’s compliance comes down to a handful of concrete steps.
The short version
Know your lawful basis for every piece of data you collect, publish a clear privacy policy, get real cookie consent before loading non-essential trackers, be ready to answer data requests, know your 72-hour breach duty, and have written agreements with your processors. This is general information, not legal advice.
1. Identify a lawful basis for every data use
GDPR requires a valid legal reason before you process personal data. The six lawful bases are consent, contract, legal obligation, vital interests, public task and legitimate interests. For a typical small site: fulfilling an order runs on contract, a newsletter signup runs on consent, and basic fraud prevention often runs on legitimate interests. Write down which basis covers each activity before you collect anything.
2. Publish a clear, honest privacy policy
Every site that collects data needs an accessible privacy policy that names what you collect, why, your lawful basis, who you share it with, how long you keep it, and how people can exercise their rights. Plain language beats legalese — regulators expect it to be genuinely understandable. Our privacy policy essentials guide breaks down each required section.
3. Handle cookies and trackers correctly
Non-essential cookies — analytics, advertising, embedded media that profiles users — require freely given consent before they load. No pre-ticked boxes, and rejecting must be as easy as accepting. Strictly necessary cookies (a login session, a shopping cart) do not need consent. See cookie consent done right for the details most banners get wrong.
4. Respect data subject rights
People whose data you hold can ask to access it, correct it, delete it, restrict its use, or receive a portable copy. You generally have one month to respond, usually free of charge. Practical prep: know where personal data lives across your systems (CRM, email tool, order database, backups) so you can actually find and act on it when a request arrives.
| Obligation | What it means for a small site |
|---|---|
| Lawful basis | A documented legal reason for each data use |
| Transparency | A readable privacy policy that is easy to find |
| Consent | Opt-in before non-essential cookies and marketing |
| Data subject rights | Answer access and deletion requests within a month |
| Breach notification | Report qualifying breaches within 72 hours |
| Processor agreements | Written contracts with your vendors |
5. Know your breach notification duty
If personal data is exposed, lost or stolen and it poses a risk to people, you must notify your supervisory authority within 72 hours of becoming aware. Where the risk is high, you must also tell the affected individuals. Reducing that risk in the first place is largely a technical job — strong encryption, patched software and sensible access control. You can start with a free security scan and our headers check to spot obvious gaps.
6. Get processor agreements in place
Any third party that handles data on your behalf — hosting, email marketing, payment gateways, analytics — is a “processor.” GDPR requires a written data processing agreement with each one. Most reputable vendors offer a standard DPA you can accept; collect and file them so you can show the chain of responsibility.
What non-compliance can cost
Serious GDPR infringements can carry administrative fines of up to €20 million or 4% of global annual turnover, whichever is higher. For a small business the practical risks are more often complaints, remediation orders and reputational damage — but the ceiling is real and worth respecting. For a wider view of overlapping EU rules, see our compliance overview.
This guide is general information to help you get oriented, not legal advice. For decisions specific to your business, consult a qualified data protection professional.
Frequently asked questions
Does GDPR apply to my small website?
If you offer goods or services to, or monitor the behaviour of, people in the EU or EEA, it applies regardless of where your business is based or how small it is.
Do I need a cookie banner?
You need consent before loading non-essential cookies such as analytics and advertising. If you only use strictly necessary cookies, you can inform users without asking for consent.
How fast must I respond to a data request?
Generally within one month of receiving it, and usually free of charge. Complex requests can be extended, but you must tell the person and explain why.
Related guides
The NIS2 Directive Explained for Website Owners
What the EU NIS2 directive is, who it applies to, and the baseline security it expects.
Read →Privacy & ComplianceCookie Consent Done Right
How consent banners are supposed to work under EU law and how to avoid the most common compliance mistakes.
Read →Privacy & ComplianceWhat Every Privacy Policy Needs
The core sections a website privacy policy should contain and the plain-language way to write them.
Read →Check your site against this guide
Run a free ScanOpsPro scan and see how your site handles the fundamentals.
Run a free scan