Complete GDPR guide
for websites

Find out what GDPR requires, how to properly handle Cookies and how to avoid hefty fines. Updated for 2025.

What is GDPR and why does it concern you?

GDPR (General Data Protection Regulation) is an EU regulation on the protection of Personal data, which came into effect on 25 May 2018.

Before GDPR came into effect in May 2018, personal data protection in the EU was governed by the outdated Directive 95/46/EC from 1995. The internet had changed fundamentally since then: from social networks to e-commerce to cloud computing. GDPR was the EU's response to the need for modern regulation that protects citizens' rights in the digital age.

GDPR applies to any processing of personal data of EU citizens, regardless of where the operator is based. This means that even a small e-shop must comply with the same rules as a large multinational corporation. The key date is 25 May 2018, when GDPR became effective across all EU member states.

Global reach

GDPR applies to all websites that process data of EU citizens -- regardless of where they are based.

Hefty fines

Violations can result in fines of up to EUR 20 million or 4% of global annual turnover.

User rights

Users have the right to access, rectify, erase and port their personal data. Every Data subject can exercise these rights.

6 Key GDPR Principles

Every processing of personal data must respect these six fundamental principles.

Lawfulness, fairness, transparency

Data must be processed lawfully, fairly and transparently in relation to the data subject.

Purpose limitation

Data may only be collected for specified, explicitly stated and legitimate purposes.

Data minimisation

Processed data must be adequate, relevant and limited to what is necessary.

Accuracy

Personal data must be accurate and, where necessary, kept up to date.

Storage limitation

Data may only be stored for as long as necessary for the given processing purpose.

Integrity and confidentiality

Data must be secured against unauthorised access, loss or destruction.

Cookie Categories under ePrivacy

The ePrivacy Directive, known as the "cookie law", distinguishes cookies by purpose. Each category has different consent requirements.

Strictly Necessary Cookies

Required for basic website operation: login, shopping cart, security. Do not require consent.

Consent: Not required

Functional Cookies

Store user preferences such as language, currency or font size.

Consent: Required

Analytical Cookies

Measure traffic and user behaviour (Google Analytics, Hotjar, Clarity).

Consent: Required

Marketing Cookies

Track users across websites for targeted advertising (Facebook Pixel, Google Ads).

Consent: Always required

GDPR checklist for your website

Check whether your website meets all GDPR requirements.

  • Cookie banner with the option to reject all cookies
  • Information about cookie types and their purposes
  • Ability to change preferences at any time
  • Record of consent (proof of consent)
  • Blocking cookies before consent is granted
  • Google Consent Mode v2 support
  • Regular cookie list updates
  • Privacy policy
Start with Consentio for free
GDPR Compliant

GDPR Fines & Real-World Cases

GDPR introduces two tiers of fines based on the severity of the violation.

Lower tier

Up to EUR 10 million or 2% of global annual turnover for violations of controller, processor or certification body obligations.

Higher tier

Up to EUR 20 million or 4% of global annual turnover for violations of fundamental processing principles, data subject rights or data transfers to third countries.

Amazon (Luxembourg): EUR 746 million for personal data processing violations (2021)
Google (France, CNIL): EUR 50 million for lack of transparency and consent (2019)
H&M (Germany): EUR 35 million for unauthorised employee surveillance (2020)
British Airways (UK, ICO): GBP 22 million for a data breach affecting 400,000 customers (2020)
UOOU (Czech Republic): over 100 fines per year, most commonly for unsolicited marketing and inadequate security

Your Rights Under GDPR

GDPR guarantees eight fundamental rights to everyone whose personal data is processed.

Right to information

The controller must inform about processing, purpose and rights (Art. 13-14).

Right of access

The right to obtain a copy of your processed data (Art. 15).

Right to rectification

The right to correction of inaccurate personal data (Art. 16).

Right to erasure

The right to have data deleted under certain conditions: the "right to be forgotten" (Art. 17).

Right to restrict processing

The right to restrict processing, e.g. when contesting data accuracy (Art. 18).

Right to data portability

The right to receive data in a machine-readable format and transfer it (Art. 20).

Right to object

The right to object to processing based on legitimate interest (Art. 21).

Right regarding automated decisions

The right not to be subject to a decision based solely on automated processing (Art. 22).

Frequently asked questions

What is GDPR and why is it important?

GDPR (General Data Protection Regulation) is a European Union regulation on the protection of personal data. In effect since 2018, it applies to all websites that process data of EU citizens. Violations can result in fines of up to EUR 20 million or 4% of global turnover.

Do I need a cookie banner on my website?

Yes, if you use cookies for analytical, marketing or other purposes beyond those strictly necessary. GDPR requires informed consent before storing these cookies.

How to obtain valid cookie consent?

Valid consent must be: 1) Freely given -- the user must be able to refuse, 2) Specific -- for each purpose separately, 3) Informed -- the user must know what they are consenting to, 4) Unambiguous -- an active action, not pre-ticked checkboxes.

What is the ePrivacy Directive?

The ePrivacy Directive complements GDPR and specifically regulates the use of cookies and similar technologies. It requires consent before storing any cookies except those essential for the website to function.

How long should I keep consent records?

GDPR requires demonstrability of consent, so we recommend keeping records for at least the duration of data processing, ideally 3--5 years. Consentio automatically stores all records.

What is the ePrivacy Directive and how does it relate to cookies?

The ePrivacy Directive (2002/58/EC), known as the "cookie law", complements GDPR and specifically regulates the use of cookies and similar technologies. Article 5(3) requires consent before storing any cookies except strictly necessary ones. The proposed ePrivacy Regulation is expected to replace this directive and further tighten the rules.

What are the forbidden cookie consent patterns?

GDPR and the Planet49 ruling prohibit: 1) Pre-ticked checkboxes (consent must be actively given), 2) Cookie walls (making content access conditional on consent), 3) Scrolling = consent (scrolling the page is not valid consent), 4) Storing cookies before consent (cookies must not be stored before consent is given).

How does GDPR apply to Czech websites specifically?

GDPR applies directly in the Czech Republic as an EU regulation. The supervisory authority is the Office for Personal Data Protection (UOOU). UOOU can impose fines and conducts GDPR compliance audits. In 2023 it issued over 100 fines, most commonly for unsolicited marketing and inadequate data security.

Solve cookies today.
Sleep peacefully tomorrow.

Try for free
  • No card required
  • 5 minutes to implementation
  • Made in EU