Is your website GDPR-proof? Many sites still are not
28 September 2026 · 4 min read
In short: a GDPR-proof website has at least a correct cookie banner, a clear privacy policy, HTTPS, secure forms, and collects only the data it needs. Many sites are missing exactly that baseline.
GDPR has been around since 2018, and yet plenty of websites still do not have it fully in order. Usually not out of bad will, but because the basics were never set up properly, or because the site changed over time without anyone keeping an eye on the privacy side. The annoying part: you barely notice yourself, until a visitor trips over it or a complaint comes in.
The good news is that the baseline is limited and easy to grasp. Below I run through the points that most often go wrong, each with something you can check yourself. This is not legal advice, but the practical baseline that should be in place.
1. A correct cookie banner
Refusing must be as easy as accepting. A banner with a big "Accept all" and a hidden or hard-to-find "Reject" does not qualify. Just as important: tracking such as Google Analytics, the Meta Pixel or other scripts may only load after the visitor gives consent.
Many banners do ask for consent, but are already measuring in the background. That is exactly what is not allowed. Want to check it yourself? Open your site in an incognito window and see whether trackers or cookies load before you click anything. If they do, you are collecting data without valid consent.
2. A clear privacy policy
As soon as you process personal data, and you already do that with a contact form, you need a privacy policy. In it, explain clearly what data you collect, why, how long you keep it, who you share it with and what rights the visitor has.
Write it in plain language, not legal copy-paste no one reads. Make sure it is easy to find, usually at the bottom of every page, and link to it from your forms so people know where they stand before they submit anything.
3. HTTPS and a secure connection
An SSL certificate, the padlock in the address bar, is the absolute minimum today. Without HTTPS, data is sent unencrypted, your site looks less trustworthy to visitors and ranks lower in Google.
A certificate is free and easy to enable with almost every host. Make sure all traffic runs over https://: a visitor who lands on the old http:// version should be redirected automatically.
Not sure how your site scores on this? In the free website audit I check your cookie banner, privacy policy and security all at once. Request it here.
4. Forms and data minimisation
Only ask for the data you actually need. Every extra field is extra responsibility and extra risk. A phone number or date of birth you never use is better left unasked.
Also think about what happens to that data afterwards. Where do submissions end up, how long do they stay, and are they properly secured? The less you collect and the shorter you keep it, the less can go wrong.
5. Know where your data lives
Use EU hosting where possible, and sign a data processing agreement with the tools that process data on your behalf: your mail provider, your newsletter tool, your analytics package. That is not a formality, it sets out who is responsible for what.
Especially with services outside the EU, this is an important point of attention. If you use tools that process data in the US, check whether that is done compliantly and whether there is a more privacy-friendly alternative.
Frequently asked questions
Does every website need a cookie banner?
No, only when you use non-essential cookies, such as analytics or marketing. Purely functional cookies, needed to make the site work, are allowed without consent.
Is a privacy policy mandatory?
Yes, as soon as you process personal data. And you already do that with a simple contact form or a newsletter signup.
How do I know if my cookie banner is in order?
Check whether refusing is as easy as accepting, and whether no tracking loads before you give consent. Not sure? Then the free website audit checks it for you.
What do I risk if it is not in order?
In the worst case a fine, but at the very least a loss of trust from visitors who notice something is off.
Conclusion
GDPR does not have to be a headache. The baseline is limited, and once it is set up properly you are in order. Most sites that are not compliant are simply missing one or two of the points above.
Not sure everything is right? Request a free website audit: I check your GDPR baseline, along with speed, technology, SEO and your findability in AI, and tell you honestly what still needs doing. Would you rather we build it right from the start? See how we make a website that is technically and legally sound, or get in touch.