A Greek website needs four things to be right with the GDPR: a privacy policy describing what you collect and why, a cookie banner offering a real choice, clear notice on your forms, and a way to respond when someone asks for their data.
You do not need a legal department. You need to get five or six things right and review them once a year.
Not sure where you stand today?
Request a free compliance check and you will get a list of what needs fixing.
What counts as personal data on a website
More than you would think. It is not only names.
- Email addresses and phone numbers from contact forms.
- The visitor’s IP address, even if you do not know who they are.
- Cookie identifiers that track behaviour.
- Order data in an e-shop: address, tax ID, purchase history.
- CVs submitted through a careers form.
The third catches most people out. A simple brochure site running Google Analytics is already processing personal data.
Which cookies need consent?
The rule is simple: all of them, except the technically necessary ones.
| Category | Examples | Consent needed? |
|---|---|---|
| Strictly necessary | Login, shopping basket, security, language | No |
| Statistics / analytics | Google Analytics, heatmaps | Yes |
| Advertising | Meta Pixel, Google Ads, retargeting | Yes |
| Embedded content | YouTube, maps, third-party fonts | Yes |
| Preferences | Saved settings that are not essential | Yes |
Consent must be given before the cookie loads, not after. A banner that appears while Analytics is already running covers nothing.
The six mistakes in cookie banners
- Only an “Accept” button. Rejection must be as easy as acceptance — one click, at the same level.
- Pre-ticked boxes. Consent is given actively, not by silence.
- Cookies loading before the choice is made. The most common technical error.
- A hidden reject option buried behind “Settings” and three clicks.
- No way to withdraw. The user must be able to change their mind later.
- No record kept. You must be able to show who consented, when, and to what.
The fifth is solved with a small “Cookie settings” link in the footer. The sixth is handled automatically by any serious consent tool.
In practice, refresh consent periodically — every six to twelve months is the usual approach.
What a privacy policy must say
Not ten pages of legalese. Answers to specific questions, in plain language.
- Who you are: company name, address, contact details.
- What data you collect and from where (forms, cookies, orders).
- Why you collect it — the lawful basis for each purpose.
- How long you keep it. A range is enough, e.g. “contact enquiries for 2 years”.
- Who you share it with: hosting provider, email marketing, courier, accountant.
- Whether it leaves the EU and under what safeguard.
- What rights users have and how to exercise them.
- How to complain to the data protection authority.
Do not copy another business’s policy. You will declare tools you do not use and omit the ones you do.
Do I need consent on a contact form?
To reply to an enquiry, no — the processing rests on the fact that the user approached you. What you do need is notice: one sentence beside the form linking to your privacy policy.
Consent is needed when you want to do something beyond replying:
| Purpose | What is required |
|---|---|
| Replying to the enquiry | Notice, no checkbox |
| Newsletter signup | A separate, unticked checkbox |
| Sending offers later | Separate consent |
| Passing details to a partner | Explicit notice and a basis |
The rule: one checkbox per purpose. “I accept the terms and want the newsletter” in a single box is not valid consent.
And do not forget deletion: closed enquiries do not need to live in your inbox forever.
Analytics, pixels and third-party tools
Every external tool you add to the site is a data processor and needs three things.
- To be named in your privacy policy.
- A data processing agreement with it — usually already in its terms.
- Not to load before consent, unless it is strictly necessary.
The same applies to AI tools you connect to forms or chat. The relevant limits are covered in our guide to AI automations.
What rights users have
You must be able to respond within one month to requests for:
- Access: what data you hold about them.
- Rectification: correcting inaccurate details.
- Erasure: where no other obligation applies, such as tax retention.
- Restriction or objection: particularly to marketing.
- Portability: handing over the data in a readable format.
Practically, you need one dedicated email address for these and a person who reads it.
Want us to review your site?
Send us the address and we will check banner, policy, forms and tools.
What actually gets checked
Investigations usually start from a user complaint rather than a random inspection. The most frequent triggers:
- Cookie banners with no way to reject.
- Cookies loading before consent.
- Newsletters sent to people who never signed up.
- No response to a deletion request.
GDPR fines reach very high figures for serious breaches, but for small businesses the usual outcome is a warning with a deadline to comply. The real cost is time and reputation.
Compliance checklist
- A privacy policy written for your actual business.
- A cookie policy listing the cookies you genuinely use.
- A banner with equally weighted accept and reject buttons.
- No non-essential cookie loading before consent.
- A “Cookie settings” link in the footer.
- A notice beside every form.
- A separate checkbox for the newsletter.
- SSL on every page.
- A contact address for data requests.
- An annual review of your third-party tool list.
If you run an e-shop, terms of sale and the right of withdrawal are added — see our guide to legal requirements for an e-shop.
Frequently asked questions
Do I need a Data Protection Officer?
Most small businesses do not. It is required mainly for public bodies and for businesses doing systematic monitoring or handling special categories of data at scale.
What does compliance cost?
Legal texts typically €150–€600. The technical side is a few hours if done alongside the build — see what to ask for in our guide on choosing a web developer.
Does it apply to a site with no forms?
Yes, if you use analytics, embedded video or third-party fonts.
Can I email newsletters to my customers?
To existing customers, for similar products, there is some room — but always with an unsubscribe option in every message. To purchased lists, no.
How often should I update my policies?
Once a year, and whenever you add a new tool or service.
This article is for information only and is not legal advice.
Next step
Book a free 30-minute call with the team at The Dev Alley. We will walk the ten-point list together and tell you what can be fixed in a day.
