GDPR and cookies in 2026: what an SME website actually needs to do
What's mandatory, what's overkill, mistakes to avoid and how to set up a cookie banner that doesn't ruin UX
Reality past the paranoia
Lots of noise has built up around GDPR and cookies. We've seen companies pay €1,500/year for complex compliance services they don't even need.
This article separates what's mandatory from what's overkill, focused on SME websites (B2B or B2C) — not cross-border e-commerce with sensitive data.
Important disclaimer
I'm not a lawyer and this is not legal advice. It's a technical guide based on hands-on experience with dozens of SME sites. For legal certainty consult a privacy lawyer.
What's mandatory
1. Privacy policy
A page explaining what data you collect, why, how you store it, who you share it with, what rights the user has. Yes, even with just a contact form.
Reliable generators: Iubenda, Cookiebot. Cost: €50-200/year.
2. Cookie banner (if you use non-essential cookies)
If you have Google Analytics, Facebook Pixel, YouTube embeds or any tracker, a banner asking consent BEFORE activating them is required.
Required features:
- "Accept all" and "Reject all" buttons with equal visibility
- Per-category customisation (analytics, marketing, etc.)
- Cookies don't fire until the user chooses
- Consent must be recorded and editable
3. Cookie policy (linked from the banner)
Page listing all cookies used, purpose, duration, third party. Generators above create it automatically.
4. Processing register (internal)
A document (Word is fine) listing data processing activities: contacts from form, newsletter, customer management. Simplified for SMEs. Not published, but must exist.
5. Explicit consent on forms
Forms must have a non-pre-ticked checkbox: "I have read and accept the privacy policy". Without it, the request is collected in violation of GDPR.
What's NOT mandatory
DPO (Data Protection Officer)
Only if you're a public authority, do large-scale systematic monitoring, or process sensitive data at scale. An SME with contact form and newsletter does NOT need a DPO.
Paying €1,000+/year for compliance services
For most SMEs you only need:
- Generated privacy + cookie policy (€50-100/year)
- Integrated cookie banner (included in generators)
- Form with consent (free)
- Internal processing register (free, you do it)
Common mistakes
- Cookie banner that doesn't actually block cookies — "decorative" banner: appears but Google Analytics fires anyway. This violates GDPR.
- Form without privacy checkbox — adds 5 minutes, prevents violation
- Generic privacy policy copied from another site — services mentioned that you don't use = exposed
- Newsletter without double opt-in — every signup must have an email confirmation
- Undeclared trackers — chat, heatmap, funnel analytics must be in cookie policy
Minimum checklist
- ☐ Updated privacy policy, accessible from footer
- ☐ Cookie banner that actually blocks (not decorative)
- ☐ Cookie policy linked from the banner
- ☐ Privacy checkbox on all forms (not pre-ticked)
- ☐ Newsletter with double opt-in
- ☐ Internal processing register
- ☐ Technical security: HTTPS, backups, strong CMS passwords
Practical setup
Initial setup: 4-6 hours of technical work. Annual maintenance: minimal (policy review when services change).
Full technical management (cookie banner, privacy, security) is included in the Digital Presence Management package from €89/month.
For a check on current compliance: free audit includes privacy/cookie verification.
Want to apply this to your SME?
If you'd like a concrete analysis of your situation, request the free audit from Gamerbit. In 48 hours we tell you exactly where you're losing leads, time or budget — no sales pitch.
If you already know what you need and want a steady system, the Free audit package is the most direct starting point.
Want more clients from your website?
Get the free 48h Check-up: we show you where you are losing enquiries.
Free 48h Check-up