html How do you make your website GDPR-proof? Checklist | AgentsLabs
Directly to content
Agents Labs

Your website GDPR-proof to make.

No legal treaty, but the points that apply to almost every business website.

You make a website GDPR-proof by only asking for data that you really need, explaining in plain language what you do with it, asking permission before placing analytics or marketing cookies, concluding processing agreements with your suppliers and agreeing on and adhering to retention periods.

STEP BY STEP

Check these points

  1. Delete fields you don't needEvery field is responsibility. Do you only email back? Then you do not have to make a telephone number mandatory. This is the cheapest measure and it also increases your conversion.
  2. Write a readable privacy statementWhat do you collect, why, how long do you keep it, who do you share it with, and how can someone request it or have it deleted. In plain language: a boarded-up text that no one reads does not serve the purpose.
  3. Turn off analytics by defaultConsent must be given in advance, and refusal must be as easy as acceptance. A bar with only 'agreement' is not sufficient.
  4. Conclude processing agreementsWith every party that processes data on your behalf: hosting, email platform, form service, CRM. This is most often forgotten and is mandatory.
  5. Agree on retention periods and stick to themForm submissions from five years ago no longer serve any purpose. Get rid of them: setting a deadline and not adhering to it is worse than no deadline.
  6. Know what to do in the event of a data breachIf there is a risk to those involved, you must report it to the Dutch Data Protection Authority within 72 hours. Determine in advance who will do this; During an incident, figuring out the problem is the problem.

PITFALLS

Common mistakes

The most common is to show a cookie notification while nothing is placed that requires permission. That is unnecessary friction without legal gain.

The second is analytics that measures before a click is made. That happens more often than people think, because many scripts load immediately.

  • No notification without reason — purely functional cookies are allowed without.
  • Just as easy to refuse — like accept, in one click.
  • Don't measure anything before consent — check that the script is actually waiting.
  • Processing agreements complete — any supplier who sees data.
  • Also implement retention period — cleaning up is part of the deal.
  • We are not lawyers — have your statements tested.

FREQUENTLY ASKED QUESTIONS

More about privacy

Do I need a cookie notification?

Only for cookies that are not strictly necessary, such as analytics or advertising cookies. If you do not use it, no notification is required and your site will be more pleasant to use.

Can I use Google Analytics?

In practice, it is widely used with prior permission and the correct settings. If you want to avoid that discussion altogether, a self-hosted solution without personal data is an alternative.

Will you arrange this for me?

We build the technology in such a way that it is correct: prior consent, refusal just as easy, processing within the EU. We leave the legal test of your statements to a lawyer - that is not ducking but the correct division of roles.

CONTINUE READING

More on this topic

Of course, continue reading about this subject.

Technically in order?

We check your forms, cookies and analytics and send you what is technically missing.

Schedule a free consultation info@agentslabs.net