How to Make Your Business Website GDPR Compliant
Who is actually in scope, how to choose a lawful basis, why most cookie banners fail a thirty second test, and the two deadlines that decide whether a mistake becomes a fine.
GDPR applies to your website if you offer goods or services to people in the EU or EEA, or track their behavior, wherever your company is registered. Compliance then rests on five things: a lawful basis recorded for every purpose you collect data for, non essential scripts that stay unfired until someone consents, a privacy notice that meets the Article 13 list, an answer to any rights request within one month, and a reportable breach on the regulator's desk within 72 hours.

Quick answer
A lawful basis, a gate on your scripts, and two deadlines
Scope follows targeting, not your address. If you sell into the EU or EEA, or profile visitors from it, the regulation reaches you. Record a lawful basis for every purpose before you build the form. Hold every non essential script until the visitor chooses, and prove it in the network tab rather than in the banner settings. Publish a notice that answers the full Article 13 list, including retention periods and recipients. Then keep two clocks visible: one month to answer a rights request, and 72 hours to report a breach that puts people at risk.
Does GDPR Apply to Your Business Website?
Two conditions in Article 3(2) put a business outside the EU in scope: you offer goods or services to people in the EU or EEA, or you monitor their behavior. Nothing about your company address decides it.
Recital 23 spells out the signals a regulator reads as targeting. Prices in euros. A language you do not speak at home. Shipping options to European addresses. European phone formats in your contact block. Testimonials from customers in Madrid or Milan. Paid campaigns with European geography in the targeting. Any two of those together and the argument that you never meant to serve Europe stops working.
Behavior monitoring catches sites that never sell anything abroad. If you run retargeting pixels, session replay or profiling that follows a European visitor across pages and back again, that is monitoring, and it counts on its own.
What does not put you in scope is accessibility. A site that loads in Lisbon because the internet has no borders is not targeting Lisbon. This matters because the honest answer for a lot of small businesses is that GDPR does not apply yet, and the useful move is to decide deliberately rather than bolt a banner on out of nervousness. If you are building the store that will change the answer, our guide to building an ecommerce store is the point where currency, shipping zones and email flows get set, and those three settings are what pull you into scope.
One more thing worth knowing early: the UK left the EU but kept the regulation as UK GDPR, with the Information Commissioner as regulator. Selling into both means two supervisory authorities reading the same notice.
Pick the Lawful Basis Before You Build the Form
Every purpose you process data for needs one of the six lawful bases in Article 6, chosen before collection and written into your notice. You cannot switch later because the first choice became inconvenient.
| Lawful basis | What it fits on a business site | The catch |
|---|---|---|
| Contract | Taking an order, shipping it, handling the return, running the account someone opened. | Covers only what the contract genuinely needs. Marketing is not part of the contract. |
| Legal obligation | Invoice and tax records, VAT reporting, anything a statute makes you keep. | You must be able to name the law. Company policy is not a legal obligation. |
| Legitimate interests | Fraud checks, service messages, business to business outreach, postal marketing. | Requires a documented three part balancing test, and it loses to a valid objection. |
| Consent | Non essential cookies, newsletter sign up, anything the person genuinely opted into. | Withdrawable at any moment, and it must be as easy to take back as it was to give. |
| Vital interests | Life or death situations. Almost never a website. | Set it aside unless you are in healthcare or emergency response. |
| Public task | Public authorities and bodies exercising official authority. | Not available to an ordinary company. |
Read the third column, because that is where the real decision sits. Teams reach for consent by reflex, and consent is the most fragile basis you can pick. It has to be freely given, specific, informed and given by clear affirmative action, which means no pre ticked boxes, no bundling the newsletter into the terms checkbox, and no treating continued scrolling as agreement. The Court of Justice settled the pre ticked box question in the Planet49 ruling in 2019 and it has not moved since.
Consent also has a second cost that people discover a year in. When it is withdrawn you must stop, and you must stop everywhere, including the segments already built in your email tool. Legitimate interests behaves differently: it demands homework up front, a written balancing test that weighs your purpose against what the person would reasonably expect, and then it holds, subject to an objection you honour on request.
Map Every Place Data Comes In, Online and Off
You cannot write an accurate notice until you know every doorway. Sit down with the site and list them: the contact form, the newsletter box, the checkout, account registration, the support inbox, the live chat transcript, the review widget, the analytics identifiers, the ad pixels, the embedded video player that sets its own cookie, and the web server logs holding IP addresses. Almost every one of those is a separate purpose with its own basis and its own retention period.
Then walk out of the browser, because paper collects data too and it is the part audits usually find missing. A sign up sheet at a trade show, an intake form on a clipboard, the bowl of business cards by the till, a written competition entry, a delivery signature sheet. Each is personal data collected by you, and Article 13 says the notice has to be given at the moment of collection, not emailed a week later.
Handle it the way you would handle it online. Print the short form notice directly on the form: who you are, what you will use the details for, how long you keep them, and a short link or QR to the full notice. Custom printed notepads from $93.37 work well as tear off intake pads because the notice is on every sheet, and a printed pad cannot quietly drift out of sync with your policy the way a hand written sheet does. If you want the link scanned rather than typed, our guide to QR codes for small business covers pointing a code at a page you control instead of a third party redirect that logs the scan.
The business card bowl deserves its own decision. A card handed to you at an event is data you now hold, and dropping it into your CRM is processing. Decide in advance whether those cards become a legitimate interests business to business list with an opt out in the first message, or whether they stay in the bowl. Your own business cards from $17.57 are the other half of that exchange, and printing your privacy page address on the back costs nothing and settles the question of where the person can go to see what you did with theirs.
Cookie Banners Are Where Most Websites Actually Fail
Cookies sit under the ePrivacy Directive, which requires consent for anything stored on a device that is not strictly necessary for the service the user asked for, and it borrows GDPR's definition of consent. Session cookies, login state, load balancing and the consent tool itself are exempt. Analytics, advertising, heatmaps, session replay, chat widgets and embedded media are not.
The failure is almost never the wording on the banner. It is the firing order. A tag container that loads with the page has already dropped identifiers before anyone has clicked anything, so the banner is describing a decision that was made without the visitor. Load the container blocked, and release each category on the consent event. Then open the network tab in a fresh private window, load the page, and look at what fired before you touched anything. That thirty second test is the only proof that matters.
Three more rules that regulators have been consistent about. Reject must be one click on the first screen, presented as prominently as Accept, not buried two levels down under settings. Categories start unticked, because a pre ticked analytics box is not consent. And withdrawal has to be as easy as giving, which in practice means a permanent link in the footer that reopens the choices.
Cookie walls that make access conditional on accepting tracking are treated as consent that was not freely given, with narrow exceptions. If your business model needs that trade, take advice on it rather than copying a competitor's implementation, and note that your competitor being unchallenged is not evidence that they are compliant.
The Notice, the One Month Clock, and the 72 Hour Clock
Articles 13 and 14 set what the notice must contain, and the list is longer than most published policies. Include all of it:
- Who the controller is, with a real contact route, plus the DPO or EU representative if you have one.
- Every purpose you process for, each paired with its lawful basis, and the legitimate interest named where you rely on it.
- Recipients and categories of recipient. Your email platform, your CRM, your host and your payment processor are recipients.
- Transfers outside the EEA, with the safeguard you rely on: an adequacy decision, standard contractual clauses, or the EU to US Data Privacy Framework.
- Retention periods, stated as a period or as the criteria you use. "As long as necessary" on its own is not an answer.
- The rights: access, rectification, erasure, restriction, portability, objection, and no solely automated decisions with legal effect.
- The right to withdraw consent at any time, and the right to complain to a supervisory authority.
- Whether providing the data is a statutory or contractual requirement, and what happens if it is not provided.
Then the clocks. A rights request gets an answer within one month of receipt, free of charge, extendable by a further two months only where the request is genuinely complex and you tell the person why inside the first month. Verify identity proportionately: enough to be sure, not so much that you collect more data than the request itself. Requests arrive anywhere, so brief whoever reads the support inbox that a sentence like "send me everything you have on me" starts the clock even without the words data subject access request.
Where the exchange gets formal, and it does when a request turns into a complaint or a legal claim, a written response on printed letterheads from $99.95 is worth the paper. Post gives you a dated record, it survives a spam filter, and it avoids attaching a file full of someone's personal data to an email that may sit unencrypted in two mailboxes.
The second clock is shorter. Article 33 gives you 72 hours from becoming aware of a personal data breach to notify the supervisory authority, unless the breach is unlikely to result in a risk to people. If the risk is high, Article 34 says you tell the affected people too, without undue delay. Seventy two hours is not long enough to work out who to call, so write the contact list before you need it. Breach here means more than a hacker: a laptop left on a train, an export mailed to the wrong client, or a bulk email sent with every address in the To field.
Marketing After GDPR: Email, Post, and the Opt Out You Print
The channels are not governed by the same rulebook, and knowing which is which is worth real money. Electronic marketing, meaning email, SMS and automated calls, falls under ePrivacy and needs consent, with a narrow soft opt in for people who bought something similar from you and were given a refusal option at the point of sale and in every message since. Addressed postal mail is not an electronic message. It sits under GDPR alone, and legitimate interests is normally the right basis for it.
That is why a list that has gone quiet by email is often still reachable by post. It is not a loophole and it is not a free pass. You still document the balancing test, still say in your notice that you send addressed mail, still act on an objection at once, and still keep a suppression list so a stale export does not put someone back in the drop. What you avoid is needing a fresh tick box before you can put a printed piece in front of an existing customer.
Build the opt out into the artwork rather than treating it as fine print. On the address side of a mailer, one clear line naming a route out, a web address, a phone number or a reply address, does the job and takes almost no space. Standard postcards from $16.48 suit this because there is no envelope to open and the opt out sits in plain sight next to the address block. The mechanics of getting a drop out the door are in our five step guide to sending direct mail postcards, and the response rates by industry figures are a sober place to set expectations before you commit a budget.
For a longer story, a piece someone keeps, printed brochures from $57.11 carry the same obligation on the back panel. Put the controller name, the privacy page address and the opt out route there in readable type. The whole compliant marketing mix, printed pieces plus the digital channels that need consent, is laid out in our digital marketing guide for small business, and the printed side lives in the marketing materials range.
The Ten Step Compliance Checklist
Work through these in order. Steps one to three are the ones that make the rest possible, and they are also the ones teams skip because they produce no visible change on the site.
- Decide whether you are in scope and write down why, using the targeting signals from Recital 23. Date the note.
- Build the data map. Every doorway, online and on paper, with the purpose, the lawful basis, the retention period and the systems the data lands in.
- Write the Article 30 record. The exemption for organisations under 250 people is narrower than it reads, and the record is the document a regulator asks for first.
- Fix the tag firing order so nothing non essential runs before consent, then prove it in the network tab of a clean private window.
- Rewrite the notice against the Article 13 list above, replacing every generated placeholder with what your systems actually do.
- Get Article 28 terms in place with every processor: host, email platform, CRM, analytics, payment processor, backup provider.
- Check your transfers. Know which vendors move data outside the EEA and which safeguard covers each one.
- Write the rights request procedure, including who owns it, how identity gets verified, and where the one month clock is tracked.
- Write the breach plan with names and phone numbers, because 72 hours starts the moment somebody realises, not the moment the meeting is scheduled.
- Set a review date. Every new tool, form or campaign adds a doorway, and the map goes stale within a quarter.
What it costs to skip: Article 83 sets two tiers, up to €10 million or 2% of worldwide annual turnover for administrative failures such as missing records and inadequate processor contracts, and up to €20 million or 4% for breaches of the principles, the lawful basis rules, consent, transfers or data subject rights, whichever figure is higher in each case. Small businesses rarely see the headline numbers. What they see is an order to stop processing, which can mean switching off the marketing database in the middle of a campaign. More compliance context for business owners sits in the rules and regulations guides, and how we handle data on our own site is set out in the 4OVER4.COM privacy policy. Slot the checklist into your annual planning alongside the rest of your small business marketing plan.
This guide explains the regulation without the legalese. It is not legal advice, and a lawyer in your jurisdiction should review anything with real money or sensitive data behind it.
Wally explains consent
The gate goes in front of the scripts, not in front of the visitor

Wally lets the session cookie, the login state and the banner itself straight through, because the site cannot work without them. Everything else waits behind the gate: analytics, ad pixels, heatmaps, the embedded player. Nothing fires until the visitor picks. Say no and the gate stays shut, one click, same screen, no hunting through settings. Change your mind later and Wally shuts it again. A banner that asks after the tags have loaded is a sign on a door that is already open.
Shop marketing materials →Specs and pricing
Printed pieces that carry a notice and an opt out
The channels that still reach a suppressed email list, with live configuration choices and starting prices straight from the 4OVER4.COM configurator.



Print it
Print the opt out where people can see it
Explore more
Where to go next






By the numbers
Printing you can plan a campaign around
Common Questions
Your GDPR questions, answered
Does GDPR apply to a US company with no office in Europe?
It can. Article 3(2) extends the regulation to controllers outside the EU when they offer goods or services to people in the EU or EEA, or monitor their behavior. The test is whether you target them, not whether they can reach you. Recital 23 lists the signals regulators look at: a language or currency you do not use at home, EU delivery options, EU phone formats, references to European customers, and ad campaigns aimed at European countries. A local plumber in Ohio whose site happens to load in Lisbon is not in scope. An online store that prices in euros and ships to Lisbon is.
Do I need a cookie banner if I only run Google Analytics?
Yes, in the EU and UK. Analytics cookies are not strictly necessary for the service the visitor asked for, so the ePrivacy rules require consent before the script writes anything to the device. The part most sites get wrong is the order of operations rather than the banner itself: the tag manager loads on page load, sets its identifiers, and only then shows the banner. Load the container in a blocked state and release it on the consent event. Check it in the browser network tab before and after clicking, not by reading your own banner settings.
Is a generated privacy policy good enough?
As a skeleton, yes. As a finished document, no, because Articles 13 and 14 ask for facts a generator cannot know. It must name your retention periods, your actual recipients and processors, your legal basis for each purpose, whether data leaves the EEA and under what safeguard, and how someone withdraws consent or complains to a supervisory authority. Take the generated draft, then walk your own systems and replace every placeholder with what you really do. A notice that describes software you do not use is worse than a short honest one.
Do I need consent to send postal direct mail in Europe?
Usually not consent, but you do need a lawful basis and a working opt out. The ePrivacy rules that force consent for email, SMS and automated calls cover electronic messages, not addressed letters, so postal marketing to existing and prospective business contacts is normally run on legitimate interests under Article 6(1)(f). You have to document the balancing test, tell people in your notice that you post to them, honour any objection immediately and keep a suppression list. That difference is why a mailing list often stays reachable by post after it has gone quiet by email.
What do I do when someone asks me to delete their data?
Verify who is asking, then answer within one month, free of charge. Erasure is not absolute. You may keep what you need to meet a legal obligation such as tax records, what is required to perform a contract that is still running, and what you need to establish or defend a legal claim. Delete the rest, including the copies inside your email platform, your CRM and your backups on their normal rotation. Keep one thing on purpose: a minimal suppression record so the same address does not get loaded back in from an old file next quarter.
When does a small business need an EU representative or a DPO?
They are separate questions. An EU representative under Article 27 is needed by controllers outside the EU that are in scope, unless the processing is occasional, low risk and involves no large scale special category data. A data protection officer under Article 37 is only mandatory for public authorities, for core activities that require regular and systematic monitoring of people on a large scale, and for large scale processing of special category or criminal data. Most small websites need the representative sooner than they need a DPO.
Get Started
Reach the list your email tool no longer can
Postal marketing runs on legitimate interests, so an existing customer list stays reachable by post. Print the opt out on the piece and send something people keep.
Legal Disclaimer
Gold Standard guarantees apply to all standard orders placed through 4over4.com. Price match requires verifiable proof of a competitor's published price for an equivalent product with matching specifications and turnaround time. Satisfaction guarantee covers manufacturing defects and print quality issues. Contact support with order number and documentation. On-time delivery rate based on tracked orders 1999 to 2026. Individual results may vary based on shipping carrier performance.


