Skip to content
July 11, 2026·4 min read

GDPR privacy policy for your website: what it must contain in 2026 (the correct model)

A concrete guide to the mandatory sections of a GDPR-compliant privacy policy for a small-business website — no wrong generic templates.

Almost every small-business website collects personal data: a contact form, a newsletter signup, online orders, or just Google Analytics. The moment you do that, you need a real privacy policy — not a text copied from another site, with someone else's company name still sitting in paragraph three.

The trouble is that most free templates are either generic and empty of anything useful, or translations of American models that don't actually follow GDPR. And a wrong page is sometimes riskier than no page at all, because it gives you false confidence. Below, section by section, is exactly what a correct policy must contain in 2026 and how to adapt it to your business, not the other way around.

Who you are — the data controller

The first section identifies, without ambiguity, the company that decides what happens to the data — the controller, in GDPR terms. A brand name alone isn't enough.

It must show:

  • the full legal name and legal form of the entity
  • the tax/company registration numbers
  • the registered office or a correspondence address
  • a real, monitored email for data-related requests

If you've appointed a Data Protection Officer (DPO), put their details here. Most small businesses aren't required to have a DPO, so don't invent one just to look serious. What matters is that a visitor knows who they're dealing with and who is accountable for their data.

What data you collect and where it comes from

This is where people rush and stay vague. GDPR demands transparency, so be concrete and tie it to what your site actually does.

List the real categories:

  • form data (name, email, phone, the message the visitor writes)
  • order and billing data, if you sell
  • technical data collected automatically (IP, browser type, pages visited) via analytics
  • cookies and similar technologies

Also state the source: directly from the visitor (a form) or automatically (browsing). The golden rule: if a field or a tool isn't listed here, you shouldn't have it on the site. Many policies list data the business doesn't even collect — a sure sign the text was copied. Do the reverse: start from what you actually run on the site and describe only that.

Why you collect it (purpose) and on what legal basis

This is the section templates get wrong most often, even though it's the heart of GDPR. Every kind of processing has a purpose and a legal basis. Without a basis, the processing is unlawful, no matter how nice the rest of the page reads.

Tie each purpose to a basis:

  • replying to a form message — legitimate interest or pre-contractual steps
  • sending a newsletter — consent, which you must be able to prove
  • issuing invoices and bookkeeping — legal obligation
  • fulfilling an order — the contract

Don't slap "consent" on everything out of reflex. If you issue an invoice, the basis is a legal obligation, not the customer's agreement — and a customer can't withdraw a consent that never really existed. Getting this right prevents most real problems.

How long you keep data and who you share it with

Two things a visitor has the right to know: how long you keep their data, and who else touches it besides you.

For retention, don't just write "as long as necessary." Give concrete anchors: form messages can be kept for a reasonable period after the request is resolved, billing data follows the legal accounting archival terms, and newsletter data — until unsubscribe.

For recipients, list the categories of third parties that process data on your behalf (processors):

  • your hosting provider / site infrastructure
  • the email marketing service
  • the payment processor
  • your accountant or accounting firm

If any provider stores data outside the EU, mention it and the basis for the transfer. You don't have to name brands, but the categories must be clear and true.

Visitor rights and cookies

The policy must clearly state what rights the person has and how they exercise them in practice — not just list them as decoration.

Mention the rights: access, rectification, erasure, restriction, portability, objection and withdrawal of consent, plus the right to complain to the supervisory authority (in Romania, ANSPDCP). Most importantly, give a real channel: an email you actually answer and a rough response time.

Cookies deserve their own section, with the categories you use (strictly necessary, analytics, marketing) and how to refuse what isn't essential. The cookie banner must let people refuse as easily as they accept — not just a big "Accept all" button.

If you're not sure your page really covers all of this, message us on WhatsApp at MPO Web Studio. We build websites for small businesses across the country, remotely, and we deliver a ready-made demo before you pay anything — with the privacy structure set up correctly from the start.

Frequently asked questions

Can I use a free privacy policy template?+

Yes, as a starting point, but never as-is. Almost every template has to be adapted to what your site actually collects, to the real legal bases, and to your providers. An unchanged template usually lists data you don't have and wrong bases — which is riskier than helpful. Start from what your site does and cut everything that doesn't apply.

Do I need a privacy policy if I only have a contact form?+

Yes. The moment you gather a name, email, or phone number, you're processing personal data and you fall under GDPR. Even a single form triggers the duty to inform. It doesn't matter that the business is small or that you don't sell online — the collection itself is what counts.

Is a cookie banner and a DPO mandatory?+

A banner is needed if you use non-essential cookies (analytics, marketing), and it must let people refuse as easily as accept. A DPO, on the other hand, isn't mandatory for most small businesses — it becomes a requirement mainly for large-scale processing or sensitive data. Don't appoint a DPO just for show.

What's the risk if my privacy page is wrong or missing?+

You can face complaints and, in serious cases, penalties from the supervisory authority, but the most common practical risk is losing trust: an attentive visitor immediately spots a copied text with someone else's company name in it. A wrong page gives you false confidence, which is sometimes more dangerous than knowing you don't have one.

Who should write the policy — a lawyer or the web agency?+

It depends on complexity. For a simple presentation site, a correct structure adapted by the agency covers most needs. If you process sensitive data, do profiling, or operate at scale, it's worth consulting a data-protection specialist. Honestly: nobody can promise you perfect compliance from a page alone — how you handle data in practice matters just as much.

Free guide

7 mistakes that drive clients away from your website

Leave your email and get the guide right here, instantly. No spam.

By submitting, you agree to the Privacy Policy.
MThe MPO teamWe reply personally

Want to see what your business's website could look like?

Message us on WhatsApp and we'll build you a free demo website with your business name on it. See it first, then decide — no strings attached.

Ask for a free demo websiteWe usually reply within a few minutes