Eray MenekşeSoftware Developer
esmnnks@gmail.com

Privacy · November 20, 2025 · 8 min

Privacy compliance for your website: a ten-point checklist

Privacy notice, cookie consent, form consent, retention and data requests — practical steps for a small site.

Laptop with a security lock

Privacy compliance is usually presented as something only large companies deal with. In reality, every site with a contact form processes personal data. The ten points below are a practical checklist for a small site.

A ten-point checklist

  • The privacy notice must be published and written in plain language
  • Cookie consent must not run measurement cookies before consent is given
  • Forms need an explicit consent box, and it must not be pre-ticked
  • Collect only as much data as the purpose requires (don’t ask for unnecessary fields)
  • The retention period must be decided and written down
  • There must be a channel (an e-mail address) for deletion and information requests
  • Form data must travel over an encrypted connection
  • If servers abroad are used, the text must say so
  • Third-party tools (analytics, chat) must be listed in the text
  • Requests must be answered within thirty days

The most common mistake

Copying a template text and putting it in the footer. If the tools listed in the text aren’t on the site, or the tools on the site aren’t in the text, you have appearance rather than compliance.

The first step towards compliance is not writing a legal text; it is knowing which data you collect and why.

Was this useful?

Rate it — you can change your vote later.

4.5· 191 ratings

Notes

All notes