HomeAbout
Services
GDPR Health CheckBusiness Privacy EssentialsWebsite Compliance ReviewEmployee Privacy PackAI GovernanceOngoing Privacy Support
InsightsCase studiesPricingContactBook Free 30-Minute Consultation
Article 01  •  Website Privacy

Is Your Website GDPR Compliant? 7 Things Every Business Should Check

Shiraz Rahhal
By Shiraz RahhalFounder & Director, S.R Legal Services
Website Privacy  •  5 minutes read
Is Your Website GDPR Compliant? 7 Things Every Business Should Check

Your website may collect more personal information than you realise. From contact forms and cookies to analytics and third-party tools, there are seven key areas every business should review to reduce privacy risk and build trust with your customers.

1. Check your privacy notice

Your privacy notice should be easy to find, up to date and written in clear language. It should explain what information you collect, why you collect it, the lawful basis you rely on, who you share information with, how long you keep it and how people can exercise their rights. A notice copied from another website is unlikely to accurately describe how your own business operates.

2. Review your cookies and tracking technologies

Check which cookies, analytics tools, advertising technologies and other trackers operate when someone visits your website. Non-essential cookies should not normally be placed before the visitor has given the appropriate consent. Your cookie information should also accurately describe the technologies in use.

3. Look at your cookie banner

A banner should give visitors a genuine choice. Accepting non-essential cookies should not be easier than refusing them, and consent should be freely given, specific and informed. The banner also needs to work technically: declining cookies should actually prevent the relevant technologies from loading.

4. Review your online forms

Contact, enquiry, booking and newsletter forms often collect personal information. Only ask for information you genuinely need, explain what will happen to it and avoid automatically adding people to marketing lists without an appropriate basis.

5. Check third-party services

Booking platforms, payment providers, chat tools, analytics services and embedded content can all involve personal data. Understand which providers receive information through your website and whether your privacy information reflects those arrangements.

6. Check website security

Your website should use appropriate security measures, including HTTPS and sensible access controls for administrative accounts. Security should reflect the nature of the information you collect and the risks involved.

7. Keep the website under review

Compliance is not a one-off exercise. Websites change, new plugins are installed and marketing tools are introduced. Review your privacy arrangements whenever there is a significant change and periodically even when there is not.

In summary

A compliant website is not simply about having a privacy policy in the footer. The notices, cookies, forms, technology and actual data flows all need to work together.

Related service

Website Privacy Review

Practical support from S.R Legal Services tailored to your organisation.

Speak directly with Shiraz

Book a free 30-minute consultation to discuss your privacy challenges and practical next steps.

Book Your Consultation