Is Your Website Compliant with Data Protection Laws?
22nd April 2025
Does your business or organisation have a website? If so, you should ensure that it is compliant with data protection laws, both in the UK and in Europe, if you process the data of EU residents. This includes the UK GDPR and EU GDPR, as well as the UK’s Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (ePrivacy Regulations in Europe).
What Data Does My Website Collect?
When an individual visits a website, their personal data is collected. This occurs whenever they click on a link or type in the URL – they don’t have to fill in a form or submit any information for data collection and processing to occur. Most websites have third-party tools such as Google Analytics or another way of collecting cookies, like a Facebook Pixel. This is just a small way of collecting a user’s data so that relevant ads can be served to them on Google, Facebook or other platforms.
What are Cookies?
You have probably had the experience of searching for a product online and then seeing adverts for similar products everywhere you go – this is tracking cookies in action; they are referred to as remarketing or retargeting cookies. They can collect information such as browsing history, what products or links you click on, language preferences, shopping cart contents, login details, location data and even device information such as your browser type and other technical details about your laptop or smartphone. Using these tracking cookies, advertisers can build up quite a detailed picture of an individual, including potentially sensitive data. This is why websites are subject to the GDPR and other data protection laws.
How to Make Sure Your Website is Compliant
Here are some things you can do to ensure your website is compliant with data protection laws.
Adding a Privacy Notice to Your Website
A privacy notice informs website visitors about how their data is collected, why it is being collected, with whom their data will be shared with and how long it will be retained. Keeping an up-to-date privacy notice on your website will ensure that all site visitors are informed about cookie collection and any other ways that your website collects their data, for example, in an online form. You can include details of the cookies you use in your privacy notice or create a separate cookie policy.
Add Cookie Consent
You have probably noticed that all websites have a notice or pop-up informing visitors that cookies are being collected, and asking for consent for this to occur. They may offer the option to agree to non-essential cookies or third-party or advertising cookies to be collected. This is because the collection of personal data for advertising requires explicit consent from data subjects, as per the Privacy and Electronic Communications Regulations, or PECR, and GDPR. Even cookies that do not relate to advertising purposes but can still identify an individual are subject to the GDPR, and as such, consent for data processing is still required.
Include a Consent Check Box in Online Forms
If someone is completing a form on your website, for example, to request further information or ask for a callback, it could be reasonably assumed that they know you will be processing their personal data. However, if this data is then used for marketing or advertising purposes, e.g. including them on a mailing list or contacting them about new products they might be interested in, this requires its own explicit consent. This is why you often see two check boxes on contact forms – one to consent to general data processing and one to consent to processing for marketing and advertising purposes. This box should be unchecked by default, requiring the user to take action to give their consent.
Just as an aside, you do not need to ask users to click on a consent box if they are just submitting an enquiry form; you can rely upon the GDPR lawful basis of legitimate interests.
Ensure Your Site is Secure
All websites should be encrypted using the HTTPS protocol, which is a form of encryption between the web browser and a website. This establishes a secure connection by scrambling the data transmitted between the website visitor’s browser and the website, so if any hackers or other malicious actors try to intercept it, it will be unreadable. This can help protect personal data, including names, postal addresses, and contact information, as well as login credentials and payment card information. Contact your web hosting service to add HTTPS security to your website, or do it yourself by purchasing and installing an SSL certificate.
If you are using your site as a CMS (content management system), you will need to add a whole different layer of security, including firewalls, malware protection, perform penetration testing and have a very robust backup regime.
If you would like more advice on ensuring that your website is fully compliant with the GDPR and other data protection laws, you can get in touch with us here at Griffin House Consultancy. Give us a call at 01673 885533, email us at [email protected], or visit the Contact Us page on our website.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.