GDPR compliance is one of the most commonly misunderstood parts of running a website. Business owners either assume it only applies to huge corporations, or they overcorrect and add confusing cookie popups that hurt conversions. This guide covers what your website actually needs — nothing more, nothing less — if you have visitors from the UK or EU. This is general guidance, not legal advice; for anything contract or liability related, consult a qualified solicitor. For the broader legal landscape across regions, see our comparison of website accessibility laws by country.
Does GDPR Apply to My Website?
GDPR applies if your website collects any personal data — including through analytics cookies — from anyone located in the UK or EU, regardless of where your business is registered. This means a US-based Shopify store selling to UK customers is just as subject to GDPR as a company headquartered in Berlin. If you use Google Analytics, Facebook Pixel, or any contact form that stores an email address, GDPR applies to you.
What Your Website Actually Needs
Compliance comes down to four concrete pieces, not a vague sense of "being careful":
- A cookie consent banner that lets visitors accept or reject non-essential cookies before they load — not just a banner that says "we use cookies" with no real choice
- A published Privacy Policy explaining what data you collect, why, how long you keep it, and how visitors can request deletion
- Consent logging — a record of when and how each visitor gave consent, in case of an audit
- A data request process — a way for someone to email you and request their data be deleted or exported, which you must action within 30 days
Cookie Categories & When Consent Is Required
| Cookie Type | Example | Consent Required? |
|---|---|---|
| Strictly necessary | Shopping cart, login session | No — always allowed |
| Analytics | Google Analytics, Hotjar | Yes — must be opt-in |
| Marketing/Advertising | Facebook Pixel, Google Ads remarketing | Yes — must be opt-in |
| Functional | Language preference, chat widget | Usually yes, unless essential to the service requested |
Common Mistakes That Still Get Businesses Flagged
The most frequent compliance failures we see when auditing client websites are: analytics or ad-tracking scripts firing before the visitor makes a cookie choice, a cookie banner with no real "reject" option (only "accept"), a privacy policy that is missing entirely or hasn't been updated in years, and using a generic template privacy policy that doesn't actually match what the site collects.
Test your own site in an incognito browser window from a UK or EU IP (a free VPN works for testing). If Google Analytics starts recording before you click "accept," your site is not compliant.
A Simple Compliance Checklist
- Cookie banner blocks non-essential scripts until consent is given
- Reject option is as visible and easy to click as Accept
- Privacy Policy page is linked in the footer and up to date
- Consent choices are logged with a timestamp
- A visible contact method exists for data deletion requests
Conclusion: GDPR compliance for a small-to-medium business website is achievable in a single afternoon of development work — it does not require an enterprise legal team. Getting it right protects you from fines and, just as importantly, builds trust with UK and EU visitors who are increasingly cookie-consent aware.
Need your website audited and brought up to GDPR standard? AppsBrain builds compliant cookie consent, privacy policies, and consent logging into every project for our UK and EU-facing clients.
Tags