The GDPR (General Data Protection Regulation) raises the same questions for website owners, agencies, and small businesses. Common questions include whether it applies to a given site, whether a cookie banner is required, and what happens after a violation.
Below are direct answers to the questions people search most, each linked to a deeper guide when you need the full detail.
GDPR Basics
Start here if you are new to the GDPR.
What is the GDPR?
The GDPR is the EU's General Data Protection Regulation (Regulation (EU) 2016/679). It has governed how organizations collect and handle the personal data of people in the EU since 25 May 2018. It sets rules for consent, transparency, security, and individual rights. For the full breakdown of principles, rights, and lawful bases, see our full guide to the GDPR.
What does GDPR stand for?
GDPR stands for General Data Protection Regulation, the EU regulation (2016/679) that protects the personal data of people in the EU and EEA. It covers any organization that collects, stores, or processes that data, regardless of where the organization is based. A common related question is whether Google Analytics is GDPR compliant, since analytics is where most sites first run into the GDPR.
When did the GDPR take effect?
The GDPR took effect on 25 May 2018, replacing the 1995 Data Protection Directive. It applied immediately across the EU and EEA, with no phase-in period for organizations to adjust. The GDPR sits alongside the EU cookie law, which governs consent for cookies and similar tracking technologies specifically.
Is the GDPR a law or a guideline?
The GDPR is binding law, not a voluntary guideline. As a regulation, it applies directly in every EU and EEA country without needing separate national legislation. Breaching it carries enforceable fines, not just a warning. It works alongside the ePrivacy rules that specifically cover cookies and electronic communications.
Why does the GDPR matter for my website?
Your website may collect personal data from EU or EEA visitors through contact forms, analytics, or cookies. When it does, the GDPR sets rules you must follow for consent, transparency, and security. Ignoring it exposes you to fines and complaints. Cookies are usually the first place a site runs into the GDPR cookie consent rules.
What are the 7 principles of the GDPR?
The GDPR sets seven data protection principles that govern how personal data must be handled:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Every processing activity must satisfy all seven. For how these principles translate into day-to-day obligations, see the core data protection principles.
Does the GDPR Apply to Me?
The most-asked GDPR question, especially for US and small businesses.
Who does the GDPR apply to?
The GDPR applies to any organization, anywhere in the world, that processes the personal data of people in the EU or EEA. This holds whether the organization offers them goods or services, or simply monitors their behavior (Article 3). Location of the business does not matter; location of the data subject does. See a simple test for who must comply to check your own site.
Does the GDPR apply to US companies?
Yes. A US company must comply with the GDPR if it offers goods or services to people in the EU or EEA, or monitors their behavior. The law follows where the data subject is located, not where the company is registered (Art. 3(2)). Read more on when US businesses must comply.
Does the GDPR apply if all my customers are in the US?
Usually not, if you neither target nor monitor anyone in the EU or EEA. Mere accessibility of your US site to EU visitors is not enough on its own (Recital 23). But EU visitors combined with analytics or ad cookies can still pull you into scope. Check whether your tech stack puts you in scope.
Does the GDPR apply to small businesses and sole traders?
Yes, the GDPR has no small-business exemption. A sole trader or tiny company handling EU personal data must comply like any other organization. The only relief is lighter record-keeping for organizations under 250 employees, not an exemption from the core rules. See GDPR for startups and small teams for the practical minimum.
Does a contact form on my website trigger the GDPR?
Yes, a contact form collects personal data (name, email, message), so the GDPR applies. You need a lawful basis for processing, a clear privacy notice, and secure storage. A form alone rarely triggers a cookie-banner requirement on its own. Learn what counts as personal data more broadly.
Are IP addresses personal data under the GDPR?
Yes. The GDPR and EU case law treat an IP address as personal data, since it can identify a device and, indirectly, the person using it. Logging or processing IP addresses, including through analytics tools, falls under the GDPR. See whether cookies count as personal data for the related cookie question.
Cookies and Cookie Banners Under the GDPR
Cookie banners are where the GDPR meets your website most directly.
Does the GDPR require a cookie banner?
Yes. The GDPR, combined with the ePrivacy Directive, requires informed, prior consent before setting non-essential cookies. In practice this means a cookie banner for any site running analytics or advertising cookies. Strictly necessary cookies are exempt from this consent requirement. See how a cookie banner works for the mechanics.
Do I need a cookie banner if I only use necessary cookies?
No. Sites using only strictly necessary cookies, such as those for login, security, or a shopping cart, do not need a consent banner under the GDPR. You should still disclose those cookies in a cookie policy for transparency. Compare essential vs non-essential cookies to check your own setup.
Is the GDPR the reason cookie banners exist?
Largely yes. The GDPR and the earlier ePrivacy Directive made prior consent for tracking cookies mandatory, which is why EU-facing sites display cookie banners. The banner is how a site collects and records that consent. See what cookie consent means for the full concept.
What makes a cookie banner GDPR compliant?
A GDPR-compliant banner blocks non-essential cookies until the user opts in, offers accept and reject choices with equal visual prominence, and uses no pre-ticked boxes. It also lets visitors withdraw consent as easily as they gave it and offers granular category choices. See GDPR cookie banner examples for what this looks like in practice.
Do I have to list every cookie by name?
No. The GDPR does not strictly require naming every individual cookie. You must clearly describe the categories of cookies, their purposes, and how long each one lasts. A categorized cookie list, usually built from a cookie scan, is the practical standard most sites follow. See automatic cookie scanning for how that categorization gets built.
What is the easiest way to add a compliant cookie banner?
A consent management platform adds a cookie banner, scans your site for non-essential cookies, auto-blocks them before consent, and keeps consent logs as records. Consently does this from one script with a GDPR opt-in template. A CMP provides the tooling; you remain responsible for overall legal compliance. See Consently's cookie consent banner for the setup.
Fines and Enforcement
What is actually at stake if you get the GDPR wrong.
What is the maximum GDPR fine?
The maximum GDPR fine is EUR 20 million or 4% of a company's total worldwide annual turnover, whichever is higher. A lower tier caps administrative violations at EUR 10 million or 2% (Art. 83, gdpr.eu). Regulators choose the tier based on the severity of the violation. See how GDPR fines work for how the tiers are applied.
What counts as a GDPR violation?
Common GDPR violations include:
- Processing personal data without a valid lawful basis
- Ignoring data subject rights requests
- Setting cookies without valid consent
- Failing to report a data breach in time
- Inadequate security around stored data
Different violations map to the lower or higher fine tier depending on severity. See GDPR privacy policy requirements to check a common gap.
Can a small business be fined under the GDPR?
Yes, regulators can fine any non-compliant organization regardless of size. Fines are meant to be proportionate. Small businesses typically face far smaller penalties than the headline maximums, but enforcement actions, warnings, and complaints still apply to them. See the biggest GDPR fines so far for real enforcement examples.
Can a US company actually be fined under the GDPR?
Yes, in principle. EU regulators have fined US companies before. Enforcement can reach them through EU establishments, representatives, or cross-border cooperation agreements. Collecting from a US firm with no EU presence is harder in practice. Ignoring the GDPR is still a real financial risk. See recent GDPR fines for current enforcement activity.
Can you be fined for not having a cookie banner?
Yes, several EU regulators have fined websites for setting tracking cookies without valid consent, whether that meant no banner at all or a non-compliant one. Cookie-consent enforcement is one of the most common GDPR and ePrivacy penalty triggers for ordinary websites. See a GDPR cookie consent solution to close this gap.
Your Data, Rights, and Roles
The GDPR vocabulary you will keep running into.
What is personal data under the GDPR?
Personal data is any information relating to an identified or identifiable person. Common examples include:
- Names
- Email addresses
- Phone numbers
- IP addresses
- Location data
- Online identifiers such as cookie IDs
A special category (health, biometrics, beliefs) gets extra protection under the GDPR. See the rights people have over their data for how these categories connect to individual rights.
What rights does the GDPR give people?
The GDPR gives individuals eight rights:
- The right to be informed
- The right of access
- The right to rectification
- The right to erasure (the right to be forgotten)
- The right to restrict processing
- The right to data portability
- The right to object
- Rights related to automated decision-making
Businesses must have a process to honor these requests when they come in. See what a DSAR is for how the access right works in practice.
What is the right to be forgotten?
The right to be forgotten, also called the right to erasure (Article 17), lets a person ask an organization to delete their personal data. Grounds include the data no longer being needed, consent being withdrawn, or unlawful processing. Some exceptions apply, such as legal retention obligations. See the right to be forgotten in full for how erasure requests are handled.
What is a data subject access request (DSAR)?
A DSAR is a request from an individual to see the personal data an organization holds about them. Under the GDPR, you must respond within one month, extendable by two further months for complex requests, and usually free of charge. See how to respond to a DSAR for the response process. Consently does not manage or fulfil DSARs on your behalf; it has no DSAR-management workflow.
What is the difference between a data controller and a data processor?
The data controller decides why and how personal data is processed, usually the website owner or business. The data processor handles data on the controller's behalf, usually a SaaS vendor or service provider. Each role carries different GDPR obligations. See controller vs processor, explained for the full comparison.
What is a Data Protection Officer, and do I need one?
A Data Protection Officer (DPO) oversees an organization's GDPR compliance. You only need one if you are a public body, or your core activities involve large-scale or sensitive-data processing. Most small websites do not require a DPO. See the steps to GDPR compliance for where DPO decisions fit into the wider process.
Getting GDPR Compliant
The practical "what do I actually do" cluster.
How do I make my website GDPR compliant?
Making a website GDPR compliant means working through a few core steps.
- Map the personal data you collect
- Set a lawful basis for each use
- Add a compliant privacy policy and cookie banner
- Block non-essential cookies until consent is given
- Keep consent records
- Build a process to honor data subject rights
- Secure the data you hold
WordPress sites have their own setup path. See make a WordPress site GDPR compliant for the platform-specific steps.
Where do I start with GDPR compliance?
Start by listing what personal data your website collects and why. Then fix the highest-risk basics first: a cookie banner that blocks trackers until consent, plus a clear privacy policy. Add a documented lawful basis for every use. See cookie compliance basics for the cookie-specific starting point.
How do I know if my website is GDPR compliant?
Check the essentials: a cookie banner that blocks non-essential cookies until consent, plus a current privacy and cookie policy. Also confirm a lawful basis for each data use, a way to handle rights requests, and consent records. Run a cookie audit to confirm what your site actually loads. See run a cookie audit to get started.
Is there a GDPR compliance checklist I can follow?
Yes. A website GDPR checklist covers data mapping, lawful basis, consent and cookies, privacy and cookie policies, data subject rights, and breach planning. Work through each item and keep records as evidence of compliance. See a free GDPR compliance checklist for the full list.
What is a lawful basis for processing?
A lawful basis is the legal justification the GDPR requires before you can use anyone's personal data. The GDPR recognizes six lawful bases:
- Consent
- Contract
- Legal obligation
- Vital interests
- Public task
- Legitimate interests
You must pick and document one basis before processing begins. See how valid consent works for the most common basis websites rely on.
How quickly must I report a data breach?
You must notify your supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach (Article 33). If the breach is high-risk to individuals, you must also tell the affected people directly. See the 72-hour breach rule for the full notification process.
How much does GDPR compliance cost?
It varies. A small website can get compliant cheaply with a cookie consent tool and a privacy policy. Large organizations spend far more on audits, staff, and dedicated systems. For most site owners, the core recurring cost is a consent management platform subscription. See what consent management platforms cost for a full pricing comparison.
GDPR vs Other Privacy Laws
How the GDPR relates to the other laws you have heard of.
What is the GDPR called in the USA?
There is no single US equivalent of the GDPR. The US regulates privacy by sector and by state instead of with one federal law. The closest broad analog is California's CCPA/CPRA, but it uses an opt-out model rather than the GDPR's opt-in approach. See US state privacy laws for how the state-by-state patchwork works.
What is the difference between the GDPR and the CCPA?
The GDPR is an EU-wide, opt-in law covering all personal data. The CCPA is a California opt-out law focused specifically on the sale and sharing of personal information. The GDPR is broader in scope and stricter on consent requirements. See GDPR vs CCPA in detail for a full side-by-side comparison.
What is the UK GDPR, and how is it different after Brexit?
After Brexit, the UK kept the GDPR as the UK GDPR, a near-identical version enforced by the UK's Information Commissioner's Office (ICO). The core rules are largely the same. The main differences are the regulator, fine figures stated in pounds, and separate UK data transfer rules. See the UK GDPR explained for the specifics.
How does the GDPR fit with other data privacy laws?
The GDPR is the model many privacy laws follow, but it is one of dozens worldwide. The US has state-level laws, Canada has PIPEDA, and Brazil has the LGPD, among others. If you serve visitors across regions, you may need to satisfy several laws at once. See data privacy laws around the world for the full landscape.
Still Have Cookie Questions?
The GDPR sets the rules; a consent management platform handles the day-to-day work of following them on your website. Consently gives your site a GDPR-ready cookie banner, automatic cookie scanning with auto-blocking, and consent logs. That covers the cookie side of the GDPR in minutes, instead of building it yourself. It runs on EU (Frankfurt) hosting and includes a 14-day free trial with no credit card required.
Try Consently free and cover the cookie side of the GDPR today.
