Web Design

GDPR for Website Owners: What the EU Privacy Law Means for Your Business

GDPR requires your website to: display a compliant privacy policy explaining what data you collect and why; obtain explicit, affirmative consent before setting non-essential cookies (analytics, advertising); provide a cookie consent mechanism that allows users to accept or reject categories of cookies separately; include an unsubscribe mechanism in every marketing email; allow users to request access to, correction of, or deletion of their personal data; and ensure any third-party tools (Google Analytics, email marketing platforms, CRMs) that process EU user data have GDPR-compliant data processing agreements in place.

Published: 2018-04-12 | Last Updated: 2018-04-12 | 9 min read

Key Takeaways

  • GDPR applies globally — any website collecting data from EU residents must comply, regardless of where the website or business is based.
  • Personal data under GDPR includes email addresses, IP addresses, cookie identifiers, and any data that can directly or indirectly identify an individual.
  • Valid GDPR consent requires a clear, affirmative action — pre-ticked boxes, implied consent, and bundled consent are all invalid.
  • Cookie consent banners must allow users to reject non-essential cookies (analytics, advertising) — not just acknowledge that cookies exist.
  • Your privacy policy must be updated to explain, in plain language, what data you collect, why, how long you keep it, and how users can exercise their rights.

The General Data Protection Regulation — the most significant overhaul of EU data privacy law in 20 years — takes effect on May 25, 2018. Unlike its predecessor (the 1995 Data Protection Directive), GDPR has teeth: maximum fines of €20 million or 4% of global annual turnover, whichever is higher, for serious violations. And crucially, it applies to organisations worldwide — not just EU-based companies — if they collect or process personal data of EU residents. For website owners, this has concrete implications. If your website uses Google Analytics, has a contact form, runs a newsletter, or places any cookies that track user behaviour across sessions, you are processing personal data. Whether EU visitors make up 5% or 95% of your traffic, GDPR applies to that portion of your data processing. This guide covers what GDPR means specifically for your website: which requirements apply, what changes you need to make before May 25, and how to implement compliance in a practical, proportionate way.

Definition: Data Controller vs Data Processor under GDPR

A Data Controller is an organisation that determines the purposes and means of processing personal data — in practice, the business that decides what data to collect and why. A Data Processor is an organisation that processes data on behalf of a controller — typically a third-party service provider like a hosting company, email marketing platform, or analytics service. As a website owner, you are the Data Controller for data collected through your site. Your email marketing provider, CRM, and analytics platform are Data Processors. GDPR requires Data Controllers to have written Data Processing Agreements (DPAs) in place with each Data Processor — most major platforms (Mailchimp, Google, HubSpot) have standard DPAs available that can be accepted through their account settings.

Updating Your Privacy Policy for GDPR

GDPR requires your privacy policy to explain clearly what data you collect, the legal basis for each processing activity, how long you retain data, and how users can exercise their rights.

Your privacy policy must be updated to cover the GDPR-required information: what personal data you collect (by category — contact data, usage data, purchase data); why you collect each type of data and the legal basis for processing it (consent, legitimate interests, contract performance, legal obligation); who you share data with (list your key data processors — email platform, analytics, CRM, payment processor); how long you retain each type of data; and how users can exercise their rights (access, rectification, erasure, portability, restriction, objection, and the right to lodge a complaint with a supervisory authority).

Write the privacy policy in plain language — GDPR explicitly requires that information be provided 'in a concise, transparent, intelligible and easily accessible form, using clear and plain language'. Legal boilerplate that requires a law degree to interpret is not compliant. Structure it with clear headings for each data type, use tables where helpful to show data type / purpose / legal basis / retention period, and avoid industry jargon. The test is whether a typical user of your website can read it and understand what you're doing with their data.

Display a link to your privacy policy in your website footer, in any form that collects personal data (contact forms, newsletter sign-ups, checkout), and in every marketing email you send. The link should be easy to find — buried in a multi-page terms document is not 'easily accessible' under GDPR's standard.

Handling Data Subject Rights Requests

GDPR grants individuals eight rights regarding their personal data — your business must have a process to respond to requests within 30 days.

GDPR grants individuals the right to access their data (receive a copy of all personal data you hold about them), the right to rectification (correct inaccurate data), the right to erasure ('right to be forgotten' — delete their data where no legal basis for retention exists), the right to data portability (receive their data in a machine-readable format), the right to restriction of processing (limit how their data is used while a dispute is resolved), and the right to object to processing (particularly for direct marketing and legitimate interests processing). You must respond to requests within one calendar month, extending to three months for complex or numerous requests.

For most small and medium businesses, the most frequently received requests will be: access requests (someone wants to know what data you hold about them), erasure requests (former customers asking you to delete their details), and unsubscribe requests (email list opt-outs, which are also covered by anti-spam law). Build a simple internal process: a designated email address or web form for data rights requests, a procedure to search your CRM, email platform, and any other systems that hold personal data, and a template response that confirms receipt and sets the 30-day response expectation.

Document every request and your response — GDPR's accountability principle requires that you can demonstrate compliance. A simple spreadsheet logging request date, type, response date, and action taken is sufficient for most small businesses.

Experience Signal

The most common GDPR gap we find when auditing client websites is a cookie banner that fires Google Analytics and Facebook Pixel before consent is given. The banner is there — it says something about cookies — but the tracking scripts load on page load regardless. This is precisely what the GDPR cookie consent requirement is designed to prevent. Implementing a proper CMP that actually blocks non-essential scripts until consent is obtained is the single most important technical change for most websites. The second most common gap is a privacy policy that was generated by an online template tool and doesn't accurately reflect the actual data processing the website does. Generic templates are a starting point, not a solution.

Frequently Asked Questions

Yes. GDPR has extraterritorial scope: it applies to any organisation, anywhere in the world, that processes personal data of individuals in the EU — regardless of whether the organisation has a physical presence in the EU. If your website is accessible to EU residents and you collect any data from them (email addresses, contact form submissions, analytics data, cookie identifiers), GDPR applies to that data processing. This means North American businesses with EU website visitors, SaaS companies with EU customers, and e-commerce stores shipping to EU countries are all subject to GDPR requirements for their EU user data.

Sources

Need Help Making Your Website GDPR Compliant?

Webnixon audits website data collection practices, implements cookie consent management, and updates privacy documentation to meet GDPR requirements. We help businesses comply without disrupting their analytics and marketing tools.

Book a GDPR Compliance Review

About the author

Jai Paek

Jai Paek

Creative Director

Jai leads brand identity and UX design at Webnixon, bringing 20+ years of experience building digital design systems for agencies and enterprise teams. He has shipped design systems and visual identities for over 200 brands across Canada and the US, with deep expertise in conversion-focused UI, WCAG 2.1 accessibility compliance, and responsive web design for service businesses and ecommerce brands.

Related Articles

HTTPS and SSL: Why Every Business Website Needs to Make the Switch

Web Design

HTTPS and SSL: Why Every Business Website Needs to Make the Switch

Google began marking HTTP websites as 'Not Secure' in Chrome in 2017. For businesses, this is no longer a back-burner technical task — a browser security warning directly undermines visitor trust and conversion rates. Here is what HTTPS means, what it costs, and how to switch without breaking your site.

January 12, 2017Jai Paek7 min read
Website Accessibility Basics: What Ontario Businesses Need to Know About AODA

Web Design

Website Accessibility Basics: What Ontario Businesses Need to Know About AODA

Ontario's Accessibility for Ontarians with Disabilities Act has digital requirements that affect many Ontario businesses — and the compliance deadlines have either passed or are approaching. This practical guide explains what AODA requires for websites, what WCAG 2.0 Level AA actually means in practice, and where Ontario businesses should start.

December 08, 2016Jim Yang8 min read
What Is Schema Markup and Why Does Your Ontario Business Website Need It?

SEO

What Is Schema Markup and Why Does Your Ontario Business Website Need It?

Schema markup is one of the most misunderstood and underused SEO tools available to Ontario businesses. It doesn't directly change your rankings — but it changes how your website appears in Google results, often dramatically. Star ratings, FAQ dropdowns, review counts, and event information in search results are all powered by schema. Here's what it is and why it matters.

June 16, 2016Rutul Shah7 min read