Home / Guides / GDPR Requirements for Websites

GDPR Basics

GDPR Requirements for Websites

Core GDPR requirements every website owner should understand: lawful bases, transparency, consent, data subject rights, security, and vendor accountability.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

July 2026

Reading time

4 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

Introduction

GDPR applies to websites that offer goods or services to people in the EU—or monitor their behavior online—even if the company is based elsewhere. That includes SaaS signup pages, ecommerce stores, blogs with newsletters, and B2B sites with contact forms.

Website owners often focus on privacy policy templates while overlooking runtime behavior: cookies firing before consent, unclear forms, and vendors receiving more data than disclosed. Regulators evaluate both documents and what the browser network tab shows.

This guide summarizes the GDPR requirements most relevant to public websites and pairs each with practical actions you can implement without a full enterprise privacy program.

What it means

Lawfulness, fairness, transparency (Art. 5–6): identify a lawful basis for each processing activity—consent for most marketing cookies, contract for checkout, legitimate interest only where carefully assessed. Tell users what you do in plain language.

Consent (Art. 7 + ePrivacy): non-essential cookies and similar technologies need prior, informed, freely given, specific consent. Pre-ticked boxes, cookie walls on public content, and bundled unrelated purposes invalidate consent.

Privacy notices (Art. 13–14): publish a privacy policy covering controller identity, purposes, categories of data, recipients, retention, rights, and sources. Cookie policies or tables should match actual tags.

Data subject rights (Art. 15–22): provide a channel (email or form) to handle access, deletion, correction, and objection requests within statutory timelines.

Security & accountability (Art. 5(2), 32): use HTTPS, access controls, vendor reviews, and records appropriate to risk. Demonstrate compliance with scans, consent logs, and DPAs—not only policies.

Processors & transfers (Art. 28, 44+): SaaS tools processing personal data on your behalf need data processing agreements. Cross-border transfers require appropriate safeguards.

Data subject request handling: publishing rights in a policy is not the same as being able to honor them. You need a documented process that covers verification of the requester's identity, internal retrieval of their personal data across all systems (CRM, analytics, email platform, support tickets), response within the one-month deadline, and a way to confirm deletion or export was completed. For small teams, start with a shared inbox (privacy@yourdomain), a spreadsheet to track requests, and a checklist of systems to check per request type. This meets the operational bar without requiring a dedicated privacy operations team.

Why it matters

Complaints often start with a visible cookie issue or unanswered privacy email—not complex legal theory. Websites are the primary touchpoint where individuals exercise rights and form opinions about your brand.

B2B buyers increasingly require privacy assurances during security reviews. Missing website basics delay deals even when your product is sound.

Fixing website requirements first delivers the highest risk reduction per hour compared to internal HR or legacy system projects.

B2B procurement teams increasingly run automated compliance scans on vendor websites before approving contracts. A single pre-consent GA4 request can delay or block a deal regardless of your product's actual capabilities. Website compliance is now part of your company's commercial infrastructure — treat it with the same operational rigor as uptime monitoring.

Common mistakes

  • Publishing a policy that lists tools you removed years ago.
  • Using one blanket legitimate interest claim for all analytics and ads.
  • Collecting marketing emails without an optional, unbundled consent checkbox.
  • Ignoring subdomains, staging, and localized country sites.
  • No process for deletion requests—only a legal paragraph promising rights.
  • Loading US-hosted widgets before consent without transfer analysis.
  • Treating GDPR as legal-only while marketing owns tag manager access.

Practical checklist

  1. Map data flows: forms, cookies, embeds, server logs.
  2. Publish accurate privacy and cookie notices.
  3. Implement banner with Reject all and enforce blocking.
  4. Sign DPAs with email, analytics, CRM, hosting vendors.
  5. Create privacy@ inbox and DSAR response workflow.
  6. Set retention limits in analytics and CRM tools.
  7. Enable HTTPS and restrict admin access.
  8. Re-scan after site or campaign changes.

How GDPRChecker helps

GDPRChecker connects policy expectations to observable behavior: the scanner shows trackers, banner gaps, and pre-consent events on your live site.

Managed sites combine consent UI, runtime blocking, and legal page hosting so website requirements move in sync—not as disconnected documents.

Compliance scores and reports give non-lawyers a prioritized fix list aligned with what regulators and cookie audits actually test.

The platform's scheduled scanning feature is particularly valuable for website compliance: configure weekly scans on your production domain, and the system alerts you when a new third-party script appears, the consent UI detection status changes, or a previously clean check starts flagging pre-consent requests. This converts website compliance from a deploy-and-hope milestone into a continuously monitored operational state that catches regressions within days, not months.

GDPRChecker tools for website GDPR requirements

FAQ

Does GDPR apply to my website if I am not in the EU?
It can, if you target or monitor people in the EU. Many global sites apply one standard worldwide to simplify compliance.
What is the difference between GDPR and cookie law?
GDPR governs personal data processing broadly. The ePrivacy Directive (and national cookie laws) specifically regulate cookies and similar technologies, often requiring consent before non-essential storage.
Do I need both a privacy policy and a cookie policy?
Most sites need a privacy policy. A separate cookie policy—or a detailed cookie section—is strongly recommended when you use analytics, ads, or social embeds.
What should I fix first on my website?
Stop pre-consent tracking, publish honest notices, then handle vendor DPAs and DSAR processes. That order matches most enforcement priorities.

GDPRChecker guides are educational resources and do not constitute legal advice. Use them to understand technical and operational privacy requirements, and consult qualified counsel for legal interpretation.

Check Your Website in Under 60 Seconds

  • No signup required
  • GDPR-focused checks
  • Cookie banner detection
  • Privacy policy verification