Last updated: 15 June 2026
Data protection is often experienced as something large companies have to deal with, while small businesses can look the other way. That is not correct. If you collect personal data through your website — and most do, often without thinking about it — you are covered by the rules. The good news is that it is not as complicated as it sounds, as long as you take a few basic things deliberately.
What GDPR is really about
GDPR is not bureaucracy for its own sake. The core is simple: personal data belongs to the person it concerns, not to whoever collects it. As a business you are borrowing it for a clear purpose, and you have a responsibility to process it safely and openly. Think of it that way and most of the concrete requirements become logical.
The most common things on a website
You are probably collecting more than you think:
- Contact form — name, email, phone number, and whatever people write in the message field
- Analytics tools — IP address and behavioural data about visitors
- Cookies — which remember settings or track visits
- Newsletter — email addresses and consent to be contacted
Each of these is personal data in some form, and each requires that you have thought through why you are collecting it and what happens to it.
Consent and cookies
The main rule is that non-essential cookies and tracking — typically analytics and marketing — require active consent before they load. Not a pre-ticked box, not "by using the site you accept", but a real choice made by the visitor.
In practice that means analytics tools should not run at all before someone has said yes. A site that loads tracking before consent is not in line with the rules, however neat the consent banner is.
Data processing agreement
The moment you use a third party to process data on your behalf — hosting provider, email service, analytics tool — you need a data processing agreement with them. It is an agreement that governs what they are allowed to do with the data. Many forget this because the services "just work", but responsibility for the data stays with you.
Where the data is stored
This is the point most people overlook, and it is a real choice. Is the data stored within the EU/EEA, or is it sent to servers in other countries with weaker data protection? Transfer out of the EEA is not prohibited, but it comes with its own requirements. For many businesses the simplest and safest thing is to make sure data stays within the EEA from the start — that removes a whole category of questions you would otherwise have to be able to answer.
It is about trust, not just the law
It is easy to see data protection as a box to tick. But the way you handle people's data is a visible signal of trust. A business that is tidy about data protection tells its customers that it is tidy about the things they cannot see either. That is cheap marketing for something you have to do anyway.
One clarification at the end: this is a general overview, not legal advice. If you are in doubt about your specific situation, you should check with someone who knows the rules in detail. But if you have the five things above in place — a deliberate purpose, proper consent, data processing agreements, control of where data is stored, and openness about all of it — you are well ahead of most.