"GDPR is for big companies" is one of the most expensive assumptions an SME can make. In practice, any website with a contact form already processes personal data — name, email, phone number — and is subject to the same rules that apply to a multinational. The good news is that meeting the essentials doesn't require a legal department, just doing the right things from the start.

Note: this article is a practical, operational guide, not legal advice. For specific or higher-risk cases (sensitive data, large volumes, regulated sectors), it's worth consulting a data protection lawyer.

When GDPR Applies to Your Site (almost always)

Common situations that already involve personal data processing:

  • A contact form asking for name, email, or phone number
  • A WhatsApp button that opens a chat with the visitor's number
  • Google Analytics, which records IP address and browsing behaviour
  • A newsletter with a subscriber list

If your site does any of these — and the vast majority do — GDPR already applies.

The Bare Minimum Every Site Needs

A Real Privacy Policy

Not one copied from another site with the company name swapped in a hurry. It should explain, in plain language: what data the site collects, for what purpose, how long it's kept, who it might be shared with (e.g. email tool, hosting provider), and how a visitor can request deletion of their data.

A Clear Legal Basis for Each Type of Processing

Responding to a contact request has a different legal basis than sending a monthly newsletter. The first relies on legitimate interest — the visitor asked, it makes sense to reply. The second requires explicit consent, usually an unchecked checkbox.

A Cookie Consent Banner (when applicable)

Cookies strictly necessary for the site to function (e.g. keeping a shopping cart) don't require a banner. Tracking tools like Google Analytics or the Meta Pixel require prior consent in most contexts — tracking should only start after the visitor accepts.

Forms That Only Ask What's Necessary

Every extra field on a form is one more piece of data to justify and protect. If you don't need a tax ID to answer a simple question, don't ask for it.

A Defined Retention Period

Keeping form submissions indefinitely, for no reason, is one of the most common — and easiest to fix — practices. Defining a period, for example deleting unanswered contacts after 24 months, already resolves most of the risk.

The Most Common Mistakes on SME Websites

  • A generic privacy policy with no real company name or valid contact for data requests
  • Google Analytics firing before any consent is given
  • No defined process for when someone requests deletion of their data
  • Third-party tools (forms, chat, email marketing) chosen without checking where and how they store collected data

Tools That Help Without Adding Complexity

For the cookie banner, tools like Complianz or CookieYes (both with a free tier for WordPress) cover most SME cases. For anyone using GA4, Google Consent Mode v2 lets tracking automatically respect the visitor's banner choice, without complex manual setup.

A Starting Point, Not the Finish Line

Meeting the essentials of GDPR isn't a one-time project — it's a set of habits: revisiting the privacy policy whenever a new tool joins the site, checking that cookie consent still works correctly, and staying clear on where each piece of collected data actually lives.

You can see this applied in practice in this site's own privacy policy. Basic compliance setup — forms with consent, a tailored privacy policy, and correctly configured tracking tools — is already part of every project under the web development services at PC Data Insights. To review the current state of your site, get in touch via the form or WhatsApp.