Complete GDPR guide
for websites
Find out what GDPR requires, how to properly handle Cookies and how to avoid hefty fines. Updated for 2025.
What is GDPR and why does it concern you?
GDPR (General Data Protection Regulation) is an EU regulation on the protection of Personal data, which came into effect on 25 May 2018.
Before GDPR came into effect in May 2018, personal data protection in the EU was governed by the outdated Directive 95/46/EC from 1995. The internet had changed fundamentally since then: from social networks to e-commerce to cloud computing. GDPR was the EU's response to the need for modern regulation that protects citizens' rights in the digital age.
GDPR applies to any processing of personal data of EU citizens, regardless of where the operator is based. This means that even a small e-shop must comply with the same rules as a large multinational corporation. The key date is 25 May 2018, when GDPR became effective across all EU member states.
Global reach
GDPR applies to all websites that process data of EU citizens -- regardless of where they are based.
Hefty fines
Violations can result in fines of up to EUR 20 million or 4% of global annual turnover.
User rights
Users have the right to access, rectify, erase and port their personal data. Every Data subject can exercise these rights.
6 Key GDPR Principles
Every processing of personal data must respect these six fundamental principles.
Lawfulness, fairness, transparency
Data must be processed lawfully, fairly and transparently in relation to the data subject.
Purpose limitation
Data may only be collected for specified, explicitly stated and legitimate purposes.
Data minimisation
Processed data must be adequate, relevant and limited to what is necessary.
Accuracy
Personal data must be accurate and, where necessary, kept up to date.
Storage limitation
Data may only be stored for as long as necessary for the given processing purpose.
Integrity and confidentiality
Data must be secured against unauthorised access, loss or destruction.
Cookie Categories under ePrivacy
The ePrivacy Directive, known as the "cookie law", distinguishes cookies by purpose. Each category has different consent requirements.
Strictly Necessary Cookies
Required for basic website operation: login, shopping cart, security. Do not require consent.
Functional Cookies
Store user preferences such as language, currency or font size.
Analytical Cookies
Measure traffic and user behaviour (Google Analytics, Hotjar, Clarity).
Marketing Cookies
Track users across websites for targeted advertising (Facebook Pixel, Google Ads).
GDPR checklist for your website
Check whether your website meets all GDPR requirements.
- Cookie banner with the option to reject all cookies
- Information about cookie types and their purposes
- Ability to change preferences at any time
- Record of consent (proof of consent)
- Blocking cookies before consent is granted
- Google Consent Mode v2 support
- Regular cookie list updates
- Privacy policy
GDPR Fines & Real-World Cases
GDPR introduces two tiers of fines based on the severity of the violation.
Lower tier
Up to EUR 10 million or 2% of global annual turnover for violations of controller, processor or certification body obligations.
Higher tier
Up to EUR 20 million or 4% of global annual turnover for violations of fundamental processing principles, data subject rights or data transfers to third countries.
Your Rights Under GDPR
GDPR guarantees eight fundamental rights to everyone whose personal data is processed.
Right to information
The controller must inform about processing, purpose and rights (Art. 13-14).
Right of access
The right to obtain a copy of your processed data (Art. 15).
Right to rectification
The right to correction of inaccurate personal data (Art. 16).
Right to erasure
The right to have data deleted under certain conditions: the "right to be forgotten" (Art. 17).
Right to restrict processing
The right to restrict processing, e.g. when contesting data accuracy (Art. 18).
Right to data portability
The right to receive data in a machine-readable format and transfer it (Art. 20).
Right to object
The right to object to processing based on legitimate interest (Art. 21).
Right regarding automated decisions
The right not to be subject to a decision based solely on automated processing (Art. 22).
Frequently asked questions
What is GDPR and why is it important?
GDPR (General Data Protection Regulation) is a European Union regulation on the protection of personal data. In effect since 2018, it applies to all websites that process data of EU citizens. Violations can result in fines of up to EUR 20 million or 4% of global turnover.
Do I need a cookie banner on my website?
Yes, if you use cookies for analytical, marketing or other purposes beyond those strictly necessary. GDPR requires informed consent before storing these cookies.
How to obtain valid cookie consent?
Valid consent must be: 1) Freely given -- the user must be able to refuse, 2) Specific -- for each purpose separately, 3) Informed -- the user must know what they are consenting to, 4) Unambiguous -- an active action, not pre-ticked checkboxes.
What is the ePrivacy Directive?
The ePrivacy Directive complements GDPR and specifically regulates the use of cookies and similar technologies. It requires consent before storing any cookies except those essential for the website to function.
How long should I keep consent records?
GDPR requires demonstrability of consent, so we recommend keeping records for at least the duration of data processing, ideally 3--5 years. Consentio automatically stores all records.
What is the ePrivacy Directive and how does it relate to cookies?
The ePrivacy Directive (2002/58/EC), known as the "cookie law", complements GDPR and specifically regulates the use of cookies and similar technologies. Article 5(3) requires consent before storing any cookies except strictly necessary ones. The proposed ePrivacy Regulation is expected to replace this directive and further tighten the rules.
What are the forbidden cookie consent patterns?
GDPR and the Planet49 ruling prohibit: 1) Pre-ticked checkboxes (consent must be actively given), 2) Cookie walls (making content access conditional on consent), 3) Scrolling = consent (scrolling the page is not valid consent), 4) Storing cookies before consent (cookies must not be stored before consent is given).
How does GDPR apply to Czech websites specifically?
GDPR applies directly in the Czech Republic as an EU regulation. The supervisory authority is the Office for Personal Data Protection (UOOU). UOOU can impose fines and conducts GDPR compliance audits. In 2023 it issued over 100 fines, most commonly for unsolicited marketing and inadequate data security.
Solve cookies today.
Sleep peacefully tomorrow.
Try for free - No card required
- 5 minutes to implementation
- Made in EU