Why GDPR Applies to Your Website
The GDPR follows the visitor, not the company. If you offer goods or services to people in the European Union, or monitor their behaviour, then their data protection rights apply to you regardless of where your business is registered. A single contact form collecting an email address is already personal data processing.
Who Actually Has to Comply, in Practice
The threshold is lower than many non-European companies expect. You do not need a physical office in the EU; a website that takes orders, quotes or enquiries from EU buyers is enough. A B2B site is not exempt because the visitor is a business. Email addresses of named individuals, IP addresses stored in analytics, and cookie identifiers all count as personal data, and each carries its own obligations.
The Checklist
Consent must be collected before non-essential cookies are set, and it must be as easy to refuse as to accept. Your privacy policy has to name the data you collect, the legal basis for each category, how long you keep it, and who receives it. Every analytics and advertising tool on the page needs to be listed, including the ones added by a marketing colleague last month. Contact forms need a stated purpose and a retention period. And you need to be able to show, not merely claim, that all of this is in place.
Consent Before Non-Essential Cookies
No cookie or tracking script that is not strictly necessary for the service the user asked for may load before a clear opt-in. That means analytics, advertising pixels, embedded videos and social widgets stay dormant until the visitor consents. The reject option must be as visible and as easy as the accept button - hiding it in a settings screen is exactly the failure regulators target.
An Honest Privacy Policy
The privacy policy is not a formality you copy from a template in another country. It must tell the visitor, in plain language, what data you collect, why, on what legal basis, for how long, and who else sees it. Vague phrases like "we may use your data to improve our services" do not satisfy transparency; names and specifics do.
Every Tracker Listed and Justified
Audit the page as a visitor would see it in the browser developer tools. Every script that drops a cookie or sends data to a third party belongs in your records and in your policy. Marketing pixels, chat widgets, heatmap tools and embedded calendars are all trackers, and each needs a stated purpose. The common failure is the tool added quietly by someone in the team, which no one ever documents.
Contact Forms With Purpose and Retention
Every form field should collect only the data the purpose needs. A generic "message" box does not need a company registration number. Next to each form, state what the data is for and how long it will be kept before deletion. A checkbox pre-ticked to add the visitor to a mailing list is not valid consent; the action must be affirmative and separate.
Common Mistakes
The most frequent failures we see are cookie banners where the reject button is hidden in a second layer, privacy policies copied from an unrelated jurisdiction, third-party scripts firing before consent is given, and no record of when consent was obtained or withdrawn. Each of these is straightforward to correct, but only if someone has actually looked.
The Hidden Reject Button
The single most cited violation is a banner that offers a large "Accept all" button and buries "Reject all" behind a second screen or a settings menu. Regulators across Europe treat this as invalid consent by design. The fix is cheap: place both buttons side by side on the first screen, with equal visual weight.
Scripts That Fire Before Consent
A site can look compliant - the banner is there, the policy is written - and still send analytics and advertising data the moment the page loads, before the visitor has clicked anything. This happens when scripts are loaded in the page code rather than gated behind the consent management platform. It is one of the most common technical findings in audits, and one of the easiest to correct.
How to Prove Compliance, Not Just Claim It
GDPR is enforceable, and enforcement increasingly asks for evidence. Keep a record of when each visitor gave consent, which version of the banner they saw, and when they withdrew it. Maintain a simple list of processors you share data with - analytics vendors, CRM providers, hosting companies. If a regulator or a customer asks, you should be able to produce this in hours, not weeks.
Frequently Asked Questions
The questions we hear most often from B2B marketing and IT leads about website compliance.
We are registered outside the EU. Does GDPR still apply?
Very likely yes. The regulation applies to anyone who offers goods or services to, or monitors the behaviour of, people in the EU, regardless of where the company sits. A contact form that accepts enquiries from a German or French buyer already brings you into scope. Treat GDPR as the baseline for any site with European traffic, even if your office is on another continent.
Does a small B2B website really need all of this?
The obligations scale with your processing, but the basics do not disappear at any company size. If you have a contact form, an analytics tool and a cookie banner, you already fall under the rules. The good news is that for a simple site the full checklist is usually a few days of work, not a quarter-long project.
How often must we review website compliance?
At least once a year, and every time you add a new tool, change your privacy policy or launch a major redesign. The most common reason compliance drifts is a new marketing tool added in between reviews, which is why the tracker audit should be part of every release, not a one-off exercise.
Conclusion
This article is practical guidance, not legal advice, and your obligations depend on your specific processing. What we can do is make sure the technical side - consent management, script gating, data mapping - is implemented correctly, so your legal advisor has something solid to review.