Your website collects personal data the moment it has a contact form. Under GDPR, that makes you a data controller — and most websites delivered by web agencies are not compliant. Here's what you absolutely must demand.
What GDPR concretely requires for your website
The General Data Protection Regulation applies to any organisation that collects data from EU residents — regardless of size. For your website, this translates into concrete, verifiable obligations:
- Mandatory privacy policy: a document accessible from every page explaining what data you collect, why, how long you keep it, and how users can exercise their rights. Not optional — a legal requirement.
- Compliant cookie banner: not just an "OK" button. Regulators require that rejecting cookies be as easy as accepting them. An "Accept all" button with no equivalent "Reject all" = non-compliant.
- Up-to-date legal notices: name of the data controller, contact details, hosting provider. These must be accurate — a closed office address from 2022 is a red flag.
- EU hosting for health and sensitive data: if you work in healthcare, law or HR, your data is classified as sensitive. It must be hosted within the European Union on contracted servers.
- Forms with unchecked consent boxes: consent must be an active choice. A pre-checked box has no legal value — this is one of the most frequently sanctioned infractions.
- Defined data retention periods: you cannot keep data "indefinitely". State how long you retain contact requests (e.g. 3 years), client data (legal duration) and analytics data.
The 5 most common mistakes on websites
These aren't rare edge cases. They appear on the majority of sites created by generalist web agencies without a GDPR culture:
- ❌ Non-compliant cookie banner: a simple "Close" or "OK" with no rejection option. Regulators have sanctioned FTSE 100 companies for this. Your SME is not immune.
- ❌ Form with no consent checkbox: a contact form that submits directly without asking if the user agrees to be contacted. Each submission = data collected without a valid legal basis.
- ❌ Uncontracted US hosting: AWS, Google Cloud or Azure without signed Standard Contractual Clauses (SCCs) = non-compliant data transfer outside the EU. Common when developers use default server settings.
- ❌ No privacy policy: or a copy-pasted generic template that doesn't match your actual activities. Regulators can verify consistency between what you declare and what you actually do.
- ❌ Google Analytics without proper configuration: GA4 with IP anonymisation disabled, without prior consent, transfers data to the USA. The CNIL has explicitly served enforcement notices on sites using GA without compensatory measures.
Medical practice, Bordeaux. CNIL enforcement notice following a patient complaint. Site built by a generalist web agency. Reason: online appointment form collected health data without explicit consent — no checkbox, and data was sent to an AWS server without a DPA.
Fine avoided thanks to rapid emergency compliance work. Cost of urgent compliance: €2,400 — three times the cost of building it compliant from the start.
The practice subsequently had its site fully rebuilt with a GDPR-by-design approach: OVH hosting, Axeptio configured, DPA signed, real privacy policy. Result: zero legal risk — and better form conversion (+18%, as patients trust the site more).
What you must demand from your web developer
Before signing a quote, ask these concrete questions. If the answers are vague or evasive, that's a warning sign:
- ✅ Signed DPA (Data Processing Agreement): if your developer accesses your data (which they inevitably do when building your site), they must sign a data processing agreement with you. This is a legal obligation under Article 28 of GDPR. Few developers offer this proactively.
- ✅ OVH / Scaleway / SiteGround EU hosting: European hosting providers with data centres on EU soil. Not AWS without SCCs, not GCP without explicit EU region configuration.
- ✅ Configured Complianz or Axeptio plugin: not just "installed" — configured with your actual cookies, your processing categories, and a banner that meets regulatory requirements (reject as easy as accept).
- ✅ Processing register provided: a document listing all data processing activities carried out via your site. You'll need it in the event of a regulatory inspection or a client request.
- ✅ No Google Fonts or external web fonts: every call to fonts.googleapis.com transfers the visitor's IP address to Google's US servers. Host fonts locally — it's also faster (better Core Web Vitals).
The most exposed sectors
All sectors are subject to GDPR, but some face heightened exposure due to the nature of the data they handle:
- 🏥 Healthcare (health data = special category): health data has reinforced protection under Article 9 of GDPR. An appointment form mentioning the medical specialty may constitute health data collection — with even stricter obligations.
- ⚖️ Legal (confidential client data): lawyers and notaries handle highly sensitive information. Professional secrecy intersects with GDPR. Hosting, encryption and access controls must be impeccable.
- 👥 HR and recruitment (CVs and personal data): applications contain sensitive data. Job boards, application forms and ATS systems must be carefully configured — particularly CV retention periods.
- 🧠 Coaching (sensitive personal data): coaching forms often touch on personal topics (mental health, finances, relationships). A clear legal basis and detailed privacy policy are essential.
GDPR compliance isn't just a legal obligation — it's a competitive advantage. 73% of European consumers say they trust businesses whose data practices are transparent (Eurobarometer 2024). Displaying genuine compliance converts better than an anonymous form.
FAQ — GDPR and professional websites
My site only has a contact form — does GDPR apply to me?
Yes, absolutely. As soon as a form collects a name, email or phone number, GDPR applies. You need an accessible privacy policy, a compliant cookie banner (if you use tracking cookies), and defined data retention periods. The size of your site or business makes no difference to this obligation.
What fines can you actually face for GDPR non-compliance?
Supervisory authorities can impose fines up to €20 million or 4% of annual global turnover. In practice, for an SME, real sanctions range from €5,000 to €50,000 — but the enforcement notice itself, even without a fine, is public and can damage your reputation. Not to mention the cost of urgent compliance, always higher than building it right from the start.
Is a GDPR plugin enough to be compliant?
No. A cookie management plugin (Complianz, Axeptio, Cookiebot) is a necessary but insufficient component. You also need: a real privacy policy matching your actual activities, up-to-date legal notices, EU hosting or contracted hosting, forms with explicit consent, and a DPA signed with your developer. GDPR compliance is a holistic approach, not a plugin you install in 5 minutes.
How do I check if my website is GDPR compliant?
Quick test: 1) Visit your site in private browsing — does your cookie banner offer a "Reject" button as visible as "Accept"? 2) Does your contact form have an unchecked checkbox? 3) Do you have a real privacy policy (not a generic template)? 4) Can you say where your data is hosted? If you answer "no" or "I don't know" to any of these, your site is not compliant.
Is your website GDPR compliant?
I audit your website's GDPR compliance and provide a detailed report with priority corrections.
Request a free GDPR audit