Aloha Pixel

Book a call
English,
WordPress and maintenance

GDPR and your website: compliance without the headache

Cookies, legal pages, forms: GDPR compliance for your website without sailing blind. The essentials to put in place to stay on the right side of the rules.

By Justin Deboves5 min read

The open door of an old bank vault, its heavy brass bolts and gears caught in amber light

GDPR has something of a bad name among the people who run small and medium-sized businesses. It gets pictured as a legal maze built for large corporations, when in fact it applies to any website that collects so much as a single piece of personal data. The good news: GDPR compliance calls for neither a law firm nor an outsized budget. It is enough to understand a few principles and to put the right elements in the right places. Here is a clear course for keeping your site on the right side of the rules, without sailing blind.

What GDPR actually requires

The General Data Protection Regulation applies the moment a site processes the personal data of a visitor living in the European Union. Personal data means anything that can identify a person: a name, an email address, an IP address, a phone number. In other words, a simple contact form is enough to bring you within the scope of the regulation.

Keeping data also means being able to restore it: our guide to WordPress backups sets out the steps to follow.

GDPR rests on a few foundations. Transparency first: you must tell your visitors clearly what you collect and why. Purpose next: you gather only the data needed for a specific aim, never “just in case”. Limited retention last: data is not kept indefinitely. These principles steer every decision you will make for your site.

You also need to name a legal basis for each processing operation. Consent is the best known, but legitimate interest and the performance of a contract are among them too. For a typical brochure site, consent and legitimate interest cover most everyday situations.

The cookie banner has become the public face of compliance, and it is often where sites fall short. The rule laid down by the CNIL, France’s data protection authority, is clear-cut: no non-essential tracker may be set before the visitor has given explicit consent. That rules out pre-ticked boxes, and banners that treat simply carrying on browsing as acceptance.

A compliant banner offers a balanced choice. The “Accept all” button and the “Refuse all” button must be equally visible, on the same visual footing. A third level lets people fine-tune their choices by category: audience measurement, advertising, social networks. Cookies that are strictly necessary for the site to work need no consent and stay active at all times.

On WordPress, several plugins handle this machinery cleanly and hold the scripts back until the visitor has decided. Setting up that upstream blocking is the trickiest technical part, because a third-party script that loads in spite of a refusal cancels out the whole of your compliance.

Two legal pages form the bare minimum for any professional site. The legal notice identifies the site’s publisher: company name, contact details, hosting provider, publishing director. Under French law it is mandatory for any professional activity online, quite apart from GDPR.

The privacy policy, for its part, flows directly from the regulation. It spells out the data collected, the purposes it serves, how long it is kept and the rights visitors have: access, rectification, erasure, objection. It also says how to exercise those rights, usually through a dedicated contact address. This page must stay reachable from every page of the site, most often in the footer.

Writing these documents takes rigor, but they protect your visitors and your business in equal measure. A clear privacy policy sends a signal of seriousness that reassures people and feeds their trust.

Every form that collects data deserves particular attention. A contact form, a newsletter sign-up, a quote request: each one triggers a processing operation. The opt-in principle applies to any use that goes beyond simply answering the original request.

In practice, if a visitor fills in a form to ask you a question, their address is used to reply to them, with no extra box to tick. If, on the other hand, you then want to add them to a commercial mailing list, a dedicated box, not pre-ticked, must gather their explicit agreement. A short line next to the send button points to the privacy policy and states what the data entered will be used for.

Common mistakes to avoid

The same few reefs catch site after site. The first: a decorative cookie banner, which informs without actually blocking the trackers. The second: pre-ticked boxes on forms, formally banned for several years now. The third: a privacy policy copied from another site, which does not match the processing your own site really carries out.

Forgotten third-party tools are another thing we come across. An interactive map, an embedded video or a social network widget will often set trackers without the publisher being aware of it. Taking stock of everything that loads on your pages is the first step of any serious compliance effort. Once that inventory is down on paper, the rest follows in orderly sequence.

Frequently asked questions

Does every website have to comply with GDPR?

Yes, as soon as it collects personal data, even through a simple contact form.

It is, as soon as a site sets non-essential trackers, and it must gather consent.

At the very least a legal notice and a privacy policy, both clear and easy to reach.

What do you risk if you are not compliant?

Sanctions from the CNIL, and a loss of visitors’ trust in how you handle their data.

Also worth reading: WordPress maintenance in Paris

Have your compliance checkedOne hour to get compliantAsk a GDPR question

All articles