GDPR sounds intimidating, but for an ordinary business website the essentials are few and anyone can grasp them. You don't need to become a lawyer — you need to know what data your site touches, why, and what you've told the visitor. This guide lays that out in order, with a practical checklist you can run through yourself. One honest note up front: this is practical guidance, not legal advice — for the tricky edges, ask a lawyer or a data-protection officer.
What GDPR actually means for a small site
GDPR is the EU regulation on personal data, enforced in Greece by the Hellenic Data Protection Authority. “Personal data” is anything that identifies a person: a name, an email, a phone number, even an IP address. The single word that unlocks everything else is purpose. For every piece of data you collect there should be a clear reason (“to reply to your message”), you should say so openly, and you shouldn't keep anything longer than you need it. Think that way and about 90% of compliance follows on its own.
1. Privacy policy: the first thing you need
This is a page, usually reachable from the footer, that explains in plain language: what data you collect (say, from your contact form or your analytics), why, how long you keep it, who you share it with (Google, your email provider, and so on), and what rightsthe visitor has. Don't blindly copy someone else's text: if it names tools you don't use, your policy is already wrong on day one. It helps to include a contact point for data matters too — for most small businesses, a single email address is plenty.
2. Cookies: consent first, not after
This is where most sites slip up. The rule is simple: non-essential cookies — analytics, Meta advertising pixels, embedded videos, chat widgets — may only run after the visitor says yes. In practice that means a banner that:
- Has a real “Reject” button as visible as “Accept” — not buried three clicks deep.
- Isn't pre-ticked. Silence or scrolling is not consent.
- Actually blocks the scripts until consent is given. A banner that pops up while Google Analytics has already loaded is decoration, not compliance.
- Lets people change their mind — withdrawing consent should be as easy as giving it.
Strictly necessarycookies (the ones that keep a cart or a login working) are exempt and need no consent. A smart move: if you don't truly need analytics that identify individuals, use a privacy-friendly stats tool instead — you often skip the banner altogether.
Want a site that's GDPR-ready from day one?
We set up a privacy policy tailored to your business, a proper cookie banner that genuinely blocks scripts, and secure storage for your form data. No panic, no copy-pasted boilerplate. See what we build or explore Helix.
Talk to us →3. Contact forms: ask for little, keep it well
Every form is a data-collection point. Three rules keep it clean. First, only ask for what you need: a contact message needs a name, an email and the message — not a tax number and a date of birth “just in case”. Second, say what happens next: a short line beside the button — “We'll use your details only to reply” — with a link to the privacy policy. Third, keep the newsletter separate: if you want to send marketing email, you need a distinct, un-ticked checkbox. Someone submitting a contact form has not agreed to receive ads.
Just as important is where the data lands. If submissions go into an organised database or arrive in an encrypted inbox, you're fine. If they're scattered across dozens of old emails and a spreadsheet on someone's desktop, you'll never be able to honour a deletion request properly. Good data storage is also a matter of the way a site is built.
4. Analytics and third-party tools
Google Analytics, Meta and Google Ads, embedded YouTube videos and Google Maps all send data outside your site. Two things always hold: (a) they must only run after cookie consent, and (b) they must be named in your privacy policy. SEO and analytics are not the enemies of GDPR — they just need to be declared. Handled that way, you can measure your traffic and stay compliant at the same time.
5. Visitor rights
GDPR gives every person specific rights, and you generally need to be able to respond within a month:
- Access: to see what data you hold on them.
- Rectification: to have anything wrong corrected.
- Erasure: the “right to be forgotten” — deleting their data when there's no reason to keep it.
- Objection: to stop marketing emails, for example.
You don't need expensive software for this — you need to know where the data lives, so you can find it and delete it when asked.
Your checklist
- ☐ A privacy policy in the footer, written for your business.
- ☐ A cookie banner with equal “Accept” / “Reject” buttons that blocks scripts before consent.
- ☐ Forms that ask only for the essentials and explain the purpose.
- ☐ A separate, un-ticked consent box for the newsletter.
- ☐ Analytics and pixels declared and gated behind consent.
- ☐ Form data stored in an organised, secure way.
- ☐ A way to handle an access or deletion request.
Frequently asked questions
I'm a very small business — does GDPR apply to me? Yes. The regulation has no size threshold; it applies the moment you process personal data, even a single contact form.
Will I be fined if something slips through?For a small business, the Authority rarely opens with a fine; there is usually a warning and room to fix things. The bigger risk isn't the fine — it's your customer's trust.
Is a free cookie banner from a plugin enough?Only if it genuinely blocks scripts before consent. Many free banners simply appear while the cookies have already loaded — that's decoration, not compliance.
The bottom line: GDPR isn't an obstacle, it's good practice with a legal name. A customer who sees that you respect their data trusts you more — and that, in the end, is the best marketing there is.
Want us to build it for you?
Tell us what you need — we'll get back to you within 24 hours with a concrete proposal, cost and timeline.
Let's work together