Pick the right legal basis
Before any personal information is processed you must decide whether you rely on contract performance, legitimate interest or another Art. 6 ground, and record that decision in writing.
Each type of processing (e.g., newsletter sign‑up, analytics) needs its own documented basis, and you must be able to show it if asked.
Using consent as a fallback is risky because it must be informed, specific, unambiguous and freely withdrawable, making it fragile in practice (Privacycompany).
Write a truthful, up‑to‑date privacy policy
The policy should list what data you collect, why you collect it, how long you keep it, and any third‑party transfers, mirroring the mandatory disclosures set out in GDPR guidance.
Any mismatch between the notice and your actual practices creates legal exposure and can attract hefty fines (Cookieyes).
Use plain language that a typical visitor can understand quickly, following the clear‑communication principles first championed for mobile apps (Fpf).
Manage cookies and consent banners
If you place tracking or advertising cookies, you must obtain prior consent that is specific to each purpose and allow users to withdraw it as easily as they gave it.
A banner that merely informs without offering a true opt‑out does not satisfy the GDPR’s consent standards.
Document the consent logs and retain them for the period required by law.
Respect data‑subject rights
Visitors have the right to access, correct, erase, restrict or port their data, and you must provide simple mechanisms – such as a web form or email address – to handle these requests.
Responses must be given within one month and in a clear, machine‑readable format where appropriate.
Keep a register of all requests and actions taken to demonstrate compliance.
Secure transfers and retention periods
If you send data outside the European Economic Area, you need an adequacy decision, Standard Contractual Clauses or another approved safeguard, and you must disclose this in the privacy notice.
Define how long each data type is retained and delete it once the purpose is fulfilled, documenting the schedule for audit purposes.
Regularly review storage locations and purge outdated records to minimise risk.
Watch for extraterritorial reach
Even if your business is based outside the EU, offering goods or services to EU residents or monitoring their behaviour brings GDPR obligations into force (Termly).
Conduct a simple audit of your traffic sources and marketing tools to confirm whether EU users are involved.
If they are, apply all the steps above; if not, keep records showing why GDPR does not apply.