Chykalophia Docs
Compliance

GDPR basics for businesses

What the EU's General Data Protection Regulation means for your website, even if your business is based outside Europe.

Difficulty
Beginner

The General Data Protection Regulation — usually called GDPR — is a European privacy law that has applied since 25 May 2018. It sets rules about how businesses collect, store, and use personal data.

If your website collects information about people who are in the European Union, GDPR can apply to you — even if your business is based in the United States.

This is not legal advice

Chykalophia is a design and web agency, not a law firm. This article explains GDPR concepts and describes best practices we follow when building and maintaining websites. It is not a substitute for advice from a qualified attorney. Laws change, and your specific situation may have requirements not covered here. Please consult a lawyer for binding compliance decisions.

Quick summary

GDPR is an EU privacy law that protects how personal data is collected and used. It can reach a business anywhere in the world if that business offers goods or services to people in the EU, or tracks their behaviour there. Key requirements include: telling people what data you collect, getting consent before using tracking cookies, honoring data deletion requests, and keeping personal data secure. We build GDPR-aligned practices into every site we deliver.

What GDPR actually is

GDPR stands for General Data Protection Regulation. It is a law passed by the European Union that protects the privacy of people who are in the EU. Note that it turns on where the person is, not on their nationality or citizenship.

"Personal data" means any information that can identify a person. This includes names, email addresses, IP addresses, and even cookie identifiers.

The law gives those people specific rights. They can ask what data you hold about them. They can ask you to delete it. They can object to how you use it.

Does GDPR apply to my business?

If your business is not established in the EU, GDPR reaches you through one of two doors. Either you are offering goods or services to people in the EU (whether or not they pay), or you are monitoring their behaviour while they are there. Where your business is registered does not decide it.

Your situationDoes GDPR likely apply?
You serve customers only in the US, with no EU marketingProbably not
You sell products or services to people in EU countriesYes — that is the "offering goods or services" door
You run paid ads targeting EU audiencesYes
You have a contact form that people in the EU might usePossibly — a site simply being reachable from the EU is not on its own enough, so it depends on whether you are aiming at that market
You use Google Analytics or Meta Pixel on your siteLikely — tracking what visitors do is the "monitoring their behaviour" door

When in doubt, treating your site as GDPR-aware is the safer path — and it tends to be good practice for all visitors, not just EU ones.

What GDPR requires in plain English

GDPR has many provisions, but for most small and mid-size business websites, the practical requirements come down to these:

Be transparent about data collection

You must have a privacy policy that clearly explains:

  • What personal data you collect (e.g., name, email, IP address)
  • Why you collect it (contact forms, analytics, marketing)
  • Who you share it with (email platforms, analytics services, hosting providers)
  • How long you keep it
  • How people can request access or deletion

If your site uses tracking tools — such as Google Analytics, Meta Pixel, or advertising trackers — you must ask visitors for consent before those tools activate for EU users. Strictly speaking, that permission rule comes from the EU's separate ePrivacy Directive, and GDPR is what sets the standard the permission has to meet. In practice the two work as one requirement.

This is where a cookie consent banner comes in. See our guide on cookie consent law for how this works in practice.

Honor data subject rights

If someone asks you to:

  • See what data you hold about them
  • Correct inaccurate information
  • Delete their data ("the right to be forgotten")

You must act without undue delay, and in any event within one month of receiving the request. That month can be extended by a further two months where the request is complex or you have received a lot of them, but you have to tell the person about the extension, and why, inside the first month. Most small business websites receive very few such requests, but you should know the process.

Keep data secure

You must take reasonable steps to protect personal data from unauthorized access, loss, or breach. This includes things like keeping your website software updated, using SSL (the padlock in the browser), and not storing sensitive data unnecessarily.

Report data breaches

If personal data is compromised — for example, through a site hack — you must notify the relevant supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it. The one exception is a breach that is unlikely to put anyone's rights or freedoms at risk. Separately, where the breach is likely to put people at high risk, you must also tell the affected individuals, without undue delay.

Who is responsible for what

GDPR uses two key terms:

  • Data controller — the organization that decides why and how personal data is processed. As the business owner, this is usually you.
  • Data processor — a third party that processes data on your behalf (your email platform, analytics provider, hosting company, etc.).

You are responsible for ensuring your data processors also meet GDPR standards. Reputable services like Google, Mailchimp, and major hosting providers publish their own GDPR compliance documentation.

What we do to help

When we build or maintain your website, we follow these practices to support GDPR alignment:

  • We configure cookie consent tools to block tracking scripts until the visitor gives consent
  • We help you publish a clear, accurate privacy policy
  • We implement SSL on every site we manage
  • We keep software updated to close security vulnerabilities
  • We can advise on which third-party tools collect data and how to disclose them

We help, but you are the data controller

Even when we build and maintain your site, you — the business owner — remain responsible as the data controller under GDPR. Our technical work supports compliance, but the legal obligations are yours. Work with a lawyer to confirm your obligations and document your processes.

Common pitfalls

  • Using pre-ticked cookie consent boxes. GDPR requires active, unambiguous consent. Pre-ticked boxes do not count.
  • Ignoring analytics tools. Google Analytics and Meta Pixel collect personal data. They need to be behind a consent gate for EU visitors.
  • An out-of-date privacy policy. If you add a new tool (say, a CRM or live chat), update your privacy policy to reflect it.
  • No process for deletion requests. Even if you never receive one, you should know how you would handle it.
  • Thinking GDPR doesn't apply because you're in the US. What matters is whether you offer goods or services to people in the EU, or track their behaviour there, not where your business is registered.

Common questions

If you use tracking tools (Google Analytics, Meta Pixel, advertising pixels) and you are doing anything to reach people in the EU — selling to them, marketing to them, or tracking what they do there — then yes, plan on a compliant cookie consent banner. Your site simply being reachable from the EU is not on its own enough to bring the rules in, so if that is genuinely all that connects you to the EU, ask your lawyer. Many businesses implement a banner for all visitors to keep things consistent, which also helps with other privacy laws like the CCPA.

What counts as personal data under GDPR?

Personal data is any information that can identify a living person, directly or indirectly. This includes names, email addresses, phone numbers, IP addresses, cookie identifiers, and even behavioral data like purchase history tied to a profile.

Does GDPR require me to appoint a Data Protection Officer (DPO)?

Most small businesses do not need a formal DPO. The regulation requires one in three situations: you are a public authority or body; regular and systematic monitoring of people on a large scale is a core activity of yours; or processing special categories of data (such as health or biometric data), or criminal conviction data, on a large scale is a core activity. A national law can add to that list, so check with a lawyer if you are unsure.

What happens if I ignore GDPR?

The regulation sets two tiers. For the most serious breaches, including breaking the rules on consent and on people's rights, fines can reach €20 million or 4% of total worldwide annual turnover for the preceding financial year, whichever is higher. A lower tier, covering things like failing to notify a breach, caps out at €10 million or 2% on the same basis. For small businesses, enforcement is less common, but it does happen — and the reputational damage from a data breach can be significant regardless of fines.

Is my privacy policy good enough?

We cannot evaluate your privacy policy for legal sufficiency — that is a job for a lawyer. What we can tell you is that it should be easy to find (linked from every page footer), written in plain English, and kept up to date whenever you add new tools or change your data practices.

Need a hand?

If you're stuck, email support@chykalophia.com and we'll help. Include your website address and a screenshot if you can.

Learn more

Last updated

On this page