LessTools
LESSCMSVisual page editor with a headless API LESSCOMMERCEStore, PIM and orders in one place LESSSEOGoogle visibility, measured daily — coming soon
One account and one invoice for all of them. Discover LessTools →
← Blog
Guides

GDPR and cookies on your website: the essentials

GDPR applies to almost every business website with a contact form, analytics or ad pixels. Here are the practical essentials: the cookie banner, privacy notice, forms and data processing agreements. This is not legal advice, just a clear list of obligations and common mistakes.

GDPR on your website affects almost every business, because a single contact form, analytics tool or advertising pixel is enough to process visitors' personal data. The GDPR is the EU's data protection regulation, in force since 25 May 2018, which sets out when and how you may collect data about individuals. This article covers the practical essentials: the privacy policy, the cookie banner, forms and agreements with vendors.

This is not legal advice. It outlines the basic obligations and common mistakes, but every business processes data differently. If you collect sensitive data or children's data, or run extensive marketing, have your setup reviewed by a lawyer or a data protection officer.

Key takeaways

  • The GDPR applies to your website as soon as it collects personal data, for example through a form, analytics, advertising pixels or IP addresses.
  • Cookies that are not strictly necessary for the site to work require the user's prior, freely given consent.
  • Rejecting cookies should be as easy as accepting them, and consent cannot be given through a pre-ticked box.
  • Every website that collects data needs a clear privacy notice containing the information required by Article 13 GDPR.
  • Vendors that process data on your behalf, such as your host or email tool, need a data processing agreement with you.

When GDPR applies to your website

Personal data is any information about an identifiable person – not just a name and email address, but often IP addresses, cookie identifiers and phone numbers too. If your site collects any of these, you are a data controller and you are responsible for GDPR compliance.

The most common places where a business website processes data:

  • contact forms, newsletter sign-ups and quote requests;
  • analytics tools such as Google Analytics;
  • advertising pixels and tags (Meta, Google Ads, LinkedIn);
  • embedded third-party content – maps, videos, chat widgets;
  • server logs and spam protection tools.

Serious GDPR infringements can be fined up to €20 million or 4% of worldwide annual turnover. In practice, small businesses are more likely to face user complaints and lost trust than maximum fines, but the obligations are the same.

Cookies: when you need consent

Cookies are the most visible part of GDPR on your website, although the rules for them come not only from the GDPR but mainly from the EU ePrivacy Directive, implemented in national law in each member state (in the UK, through PECR). The rule is simple: storing or reading information on a user's device requires consent, unless it is strictly necessary to provide a service the user asked for.

Cookie categoryExamplesConsent needed?
Strictly necessarysession, shopping cart, remembering consent choices, securityNo, but users must be informed
Functionalremembering preferences, embedded maps and videosUsually yes
AnalyticsGoogle Analytics, heatmapsYes
Marketingadvertising pixels, remarketingYes

How a GDPR-compliant cookie banner should work

  • analytics and marketing scripts load only after consent, not as soon as the page opens;
  • "Accept" and "Reject" buttons are equally prominent, as European supervisory authorities have made clear;
  • users can choose individual categories, and no boxes are pre-ticked (confirmed by the CJEU in the Planet49 ruling);
  • consent can be withdrawn at any time, for example through a "Cookie settings" link in the footer.

Privacy notice and the duty to inform

Article 13 GDPR requires you to give users specific information at the moment you collect their data. Your privacy policy is the core document for meeting this duty under GDPR on your website. It is usually linked from the footer and from every form. It should answer at least these questions:

  • who the data controller is and how to contact them;
  • for what purposes and on what legal basis you process data;
  • who you share it with, including any transfers outside the European Economic Area;
  • how long you keep it;
  • what rights users have, including the right to complain to a supervisory authority.

Avoid copying templates unchanged. A policy that lists tools you do not use, or leaves out ones you do, is misleading.

GDPR and contact forms

Forms are where GDPR on your website most often turns into concrete obligations. Contrary to common practice, you do not always need consent: to reply to an enquiry, another legal basis usually applies, such as legitimate interest or steps taken before entering into a contract. Consent is mainly needed when you want to use the data for something extra, such as a newsletter.

The minimum for a form:

  • collect only the fields you actually need;
  • place a short privacy notice with a link to your privacy policy below the form;
  • if you ask for marketing consent, use a separate, unticked checkbox;
  • decide how long you keep submissions and delete those you no longer need;
  • respond to user requests, such as access or erasure, without undue delay and generally within one month.

Data processing agreements and common mistakes

Your host, email tool, CRM or CMS provider processes data on your behalf. With each of them you need a data processing agreement under Article 28 GDPR – many vendors include one in their terms or make it available in their dashboard.

The mistakes we see most often when it comes to GDPR on a website:

  1. Google Analytics or an ad pixel loads before the visitor clicks the banner.
  2. The banner only has an "OK" button, or rejecting is buried in the settings.
  3. The privacy policy is outdated and does not list the tools actually in use.
  4. Form submissions are kept indefinitely.
  5. More people than necessary can access the inbox that receives submissions.

A quick GDPR test for your website

Open your site in a private browser window and do not click the banner. In the developer tools (Network and Application tabs), check whether any cookies or requests to analytics and advertising tools appear. Then reject consent and visit a few pages. If tracking scripts still load, the setup needs fixing. Repeat this test every time you add a new tool.

How LessCMS handles it

LessCMS does not replace legal analysis, but it simplifies the technical side of GDPR on your website:

  • A cookie consent banner with categories is one of the built-in widgets, so you do not need an external tool.
  • Google Analytics, GTM and custom scripts are added in the project settings. After setting them up, check in a private browser window that tracking scripts do not run before consent is given.
  • Forms come with a builder; submissions arrive in the panel and by email, can be exported, and are protected from spam by Cloudflare Turnstile. You add the privacy notice as text next to the form.
  • Roles and per-project access – Admin and Editor by default, plus custom roles – let you limit who can see submissions.

Configuration details are in our help center.

Frequently asked questions

Does a small business website need to comply with GDPR?

Yes, the GDPR applies to your website regardless of company size if it collects personal data. A contact form or analytics is enough. The scope of your obligations depends on what data you process and why.

Is a cookie banner mandatory?

You need a banner if your site uses cookies or similar technologies that are not strictly necessary, such as analytics or ad pixels. If you only use strictly necessary cookies, information in your privacy policy is enough. In practice, most business websites need a banner.

Does a contact form need a consent checkbox?

Not always – replying to an enquiry usually relies on a legal basis other than consent. You do need a privacy notice, though. A separate checkbox is used when the data will serve additional purposes, such as marketing.

Is an IP address personal data under GDPR?

In many situations yes, because combined with other information it can identify a person. That is why analytics tools and server logs also fall under the GDPR. Check what data the services you use actually collect.

How long do I have to respond to a data deletion request?

As a rule, you have one month from receiving the request. In justified cases this can be extended by two further months, provided you inform the user.

Want to manage your consent banner, forms and tracking scripts in one panel? Compare the plans on the LessCMS pricing page – the cookie banner and forms are available in every plan. And if you have legal questions, remember: this article is not a substitute for advice from a lawyer.

gdprcookiesprivacy policycookie banner

Build a site like this yourself

Visual editor, content via API and SEO built in — on every plan.