Skip to content
All articles
June 19, 2026·7 min read

GDPR for small websites: what you actually need (practical guide)

GDPR for small websites, explained in plain business-owner terms: a cookie banner that actually works, a real privacy policy, compliant forms, what you risk without them, and what we include in every package.

GDPR sounds like bureaucracy and massive fines, but for a small business website in Cluj or Cluj-Napoca it really comes down to a few concrete things. If you have a site that collects any data — even just a contact form — you need three things: a cookie banner that works correctly, a privacy policy that reflects what your business actually does, and forms that ask for data the right way. The rest is common sense. This GDPR guide for small websites explains, without the lawyer-speak, what you need to have and why.

One important thing up front: we're not lawyers, and this isn't legal advice — it's experience from building websites. For complicated contracts or sensitive data (medical, financial), a GDPR consultant is still the best choice. But for most small businesses — a practice, a shop, a services firm — what follows covers the essentials.

The cookie banner: the mistake almost everyone makes

Cookies are small files that a website places in a visitor's browser. Some are strictly necessary for the site to work (they hold the shopping cart, the login session) — for those you don't need consent. Others track behavior: Google Analytics, the Facebook pixel, heatmaps. That's where the GDPR obligation comes in.

A proper banner isn't a line of text saying "we use cookies, OK?" with a single button. It means:

  • Real, symmetrical consent: the visitor must be able to refuse just as easily as they accept. A visible "Reject all" right next to "Accept all", not buried in three submenus.
  • No tracking before consent: tracking scripts must not fire until the person actually clicks "Accept". This is called "prior consent" and it's exactly the part most people miss.
  • The option to change your mind: a discreet link (usually in the footer) where the visitor can withdraw or change their choice at any time.

The most common non-compliance we see at small firms: the banner looks nice, but Analytics fires from the very first second, no matter what the visitor clicks. In practice, the banner is just decoration. That doesn't cover you — it just slaps a compliance label over a real problem.

The privacy policy: the foundational document, not a copied text

The privacy policy is the page that explains, simply, what data you collect, why, how long you keep it, and who you share it with. It becomes mandatory the moment you have a contact form, a newsletter, or an online shop. It has to clearly answer:

  • What data you collect (name, email, phone, delivery address) and through which channels.
  • On what legal basis — for example, consent for the newsletter, contract for an order, legitimate interest for site security.
  • Who you share it with: the courier, the payment processor, the email marketing provider, the hosting. These are "data processors" and you should have an agreement with them.
  • How someone can exercise their rights: access to data, correction, deletion ("the right to be forgotten"), and where they complain if they're not satisfied (with you first, then with the ANSPDCP).

It doesn't need to be ten pages of text copied from another site. A borrowed text will mention things you don't do (card processing, transfers outside the EU) and leave out what you actually do — which is worse than having nothing, because it shows you never once looked at it. We prepare a model tailored to your activity, which you or your consultant can adjust as needed.

Compliant forms: the details that make the difference

This is where most websites go wrong, because these look like minor details. A contact form or a newsletter sign-up should follow a few rules:

  • An unticked checkbox for consent — it can't be pre-ticked; the visitor has to actively tick it.
  • A visible link to the privacy policy right next to the submit button.
  • Only the data you actually need: if you're answering a question, you need an email and a message. Don't ask for a personal ID number, date of birth, or address "just in case". This is the data minimization principle.
  • Separate consent for marketing: if you also want to send offers, not just reply, you need a distinct checkbox for that. You can't assume consent from the mere fact that someone wrote to you.

It's a few minutes of work to set up, but this is exactly what makes the difference between a form that covers you and one that can bring a complaint your way.

What you realistically risk if you don't have them

Let's be honest: the ANSPDCP (Romania's authority) doesn't proactively inspect every neighborhood website. The big fines you see in the press usually concern large companies processing huge volumes of data. For a small business, the risk is less spectacular but closer to home:

  • A complaint from an unhappy client or a competitor can trigger an inspection — and at that point what matters is what they find, not who you are.
  • You lose trust when a visitor sees you asking for data without explaining anything. More and more people notice this.
  • Serious partners — banks, payment processors, marketing platforms — increasingly ask for proof of compliance before working with you.

In short, compliance is more about credibility than fear of a fine. It's the same reason a website built in Cluj is worth doing right from the start, not patched up later, and the reason a domain on secure HTTPS and a site that inspires trust translate into clients who fill in your form without hesitation.

What we include in every package

When we build your site, the GDPR side comes included — not as a hidden cost discovered at the end:

ElementWhat you get
Cookie bannerSet up not to fire tracking before consent
Privacy policyModel tailored to your real activity
FormsUnticked checkbox, link, and data minimization

This applies to any package: a simple landing page (290–490 €), a presentation site (490–890 €), one with 7+ pages (890–1,500 €) or an online shop (from 690 €), where GDPR matters most because you process orders and payments. For the breakdown by package, see how much a website costs. And if you want things to stay up to date — new scripts, updated policies — we offer maintenance from 29 €/month, which includes periodic checks of these elements.

If this guide helped you understand what you need to have, let's take a concrete step together. We'll prepare a free site mockup with your business name, with a banner, policy, and forms designed correctly from the start — so you can see exactly how it would look, with no commitment. Drop us a line and we'll build your demo.

Frequently asked questions

Do I need GDPR if I only have a simple presentation site, with no shop?+

Yes. The moment you have a contact form or use Google Analytics, you're collecting personal data and you need a cookie banner and a privacy policy. Even a small, single-page site falls under GDPR rules if it processes any data from visitors.

How much does a GDPR-compliant site cost with you?+

The GDPR side comes included in any package, at no separate cost. A landing page starts from 290–490 €, a presentation site from 490–890 €, one with 7+ pages from 890–1,500 €, and an online shop from 690 €. A proper banner, a tailored policy, and compliant forms are part of the delivery in every option.

Does the cookie banner really have to block tracking before consent?+

Yes. Tracking scripts like Google Analytics or the Facebook pixel must not fire until the visitor clicks Accept. Many banners start tracking from the very first second and are just decoration — that isn't compliant, even if the banner looks good.

Can I copy the privacy policy from another site?+

It's not recommended. The policy has to reflect exactly what data you collect, why, and who you share it with. A copied text will mention things you don't do and leave out what you actually do, which is worse than nothing. We prepare a model tailored to your business, which you can then adjust with a consultant.

What real risk does a small business in Cluj face if it doesn't comply with GDPR?+

The big fines usually concern large companies, but a small firm risks an inspection triggered by a complaint from a client or competitor, the loss of visitors' trust, and problems with serious partners (banks, payment processors) who ask for proof of compliance. Compliance is more about credibility than fear of a fine.

Free guide

7 mistakes that drive clients away from your website

Leave your email and get the guide right here, instantly. No spam.

By submitting, you agree to the Privacy Policy.
Free · no obligation

Want to see what your business's website could look like?

Message us on WhatsApp and we'll prepare a FREE demo website with your business name. See it first — decide after.

Request a free demo websiteWe reply on WhatsApp within minutes