This is not legal advice. We build websites, not legal opinions. This article explains, in plain terms, what the rules require of a typical small business website and how that looks in practice, so you can have a shorter and cheaper conversation with your lawyer. The texts on your site should be approved by a lawyer who knows your business.
The good news: for a typical site of a clinic, a salon, an office or a guest house, the minimum is short. You need to tell visitors what you do with their data, collect only what you need, and ask before you track them. Most problems we see on small sites come from tools added without thinking, not from the business itself.
#Two sets of rules
Two different rules apply, and they are often confused:
- The GDPR (Regulation (EU) 2016/679) covers personal data: names, phone numbers, emails, IP addresses, booking details. It applies to everything your site collects, cookies or not.
- The cookie rule comes from Article 5(3) of the ePrivacy Directive (2002/58/EC), in Bulgaria Article 4a of the Electronic Communications Act. It covers storing or reading anything on the visitor's device: cookies, local storage and similar technologies. It applies even when no personal data is involved.
In Bulgaria, the supervisory authority for personal data is the Commission for Personal Data Protection (КЗЛД).
#The privacy notice
When you collect personal data, Article 13 of the GDPR requires you to tell people, at that moment, at least: who you are and how to contact you, why you process the data and on what legal basis, who receives it, how long you keep it, and what rights they have, including the right to complain to the supervisory authority. A privacy notice linked from the footer and from every form covers this.
Write it for your site, not for a generic one. A notice that lists newsletters, online payments and profiling on a site that has only a contact form is not more compliant, just less true.
#The contact form
- Ask only what you need. A name, a way to answer and the message are usually enough. Every extra field is data you have to protect and justify.
- Name the legal basis. Answering a request someone sent you is usually based on their request or on your legitimate interest, not on consent, so it may not need a consent checkbox at all. Your lawyer decides which basis your notice names.
- Keep newsletters separate. Signing up for marketing needs its own consent, with its own unticked checkbox.
- Decide how long you keep messages, and delete them after that.
Health data is a special category under the GDPR. A clinic's booking form should not ask for symptoms or diagnoses unless that is truly needed, and if it is, ask your lawyer first.
#Cookies: what needs consent
Cookies that are strictly necessary for something the visitor asked for do not need consent: the shopping cart, the login session, the language choice, the record of their cookie choice itself. Almost everything else does, set before the visitor agrees:
- analytics, such as Google Analytics;
- advertising and remarketing pixels, such as the Meta (Facebook) pixel;
- embedded content from other services, such as videos, maps and social media widgets, which often set cookies or contact other servers as soon as the page loads.
#What a valid consent looks like
- Before, not after. Nothing that needs consent loads until the visitor agrees.
- No pre-ticked boxes. The Court of Justice of the EU ruled in Planet49 (C-673/17, 1 October 2019) that a pre-ticked checkbox is not valid consent.
- A real choice. Refusing should be as easy as accepting, without hunting through settings.
- Easy to withdraw. The GDPR requires withdrawing consent to be as easy as giving it, so keep a link such as "Cookie settings" in the footer.
#The leanest option: fewer tools
The simplest cookie banner is the one you do not need. A small business site often uses Google Analytics only out of habit, embeds a map where a link would do, and loads a social widget nobody clicks. Remove what you do not use, replace embedded videos and maps with a click-to-load preview, and the cookie question gets much smaller. Fewer third-party scripts also make the site faster on a phone, as our slow website checklist shows.
#A short checklist
- List every form and every third-party tool on the site.
- Remove what you do not need.
- Write the privacy notice for what remains, and link it from the footer and each form.
- Load anything that needs consent only after consent, with refusal as easy as acceptance.
- Have a lawyer approve the texts, and review them when you add a tool.
#How we handle it
Every business website we build, from €590, includes privacy and cookie notice templates for your lawyer to approve, and a contact form with spam protection that asks only what you need. Our online shop package adds the order and GDPR consents a shop needs. If you want to know what your current site loads before consent, the free website check is a good start. And when you compare studios, ask who writes these texts: it is one of the 10 questions worth asking.
#Frequently asked questions
Is this article legal advice?
No. It explains the rules in general terms. The texts on your site should be approved by a lawyer who knows your business.
Do I need a cookie banner if I use no analytics?
If your site sets only strictly necessary cookies and embeds nothing from other services, you may not need a consent banner, though you should still explain the cookies you use. Check what the site really loads: embedded maps and videos are easy to forget.
Do I need a data protection officer?
Most small businesses do not. Article 37 of the GDPR requires one mainly for public bodies and for organisations whose core activity is large-scale monitoring or large-scale processing of special categories of data, such as health data. A medical practice should ask its lawyer.
Can I just copy a privacy policy from another site?
It will describe someone else's processing, not yours. Use a template as a structure, fill it with what your site really does, and have it approved.
Comments
Comments
Be the first to leave a comment.
Leave a comment