Disclaimer: This article is practical guidance for business owners, not legal advice. For specific legal questions about your obligations, consult a solicitor or data protection specialist. The information here is based on publicly available guidance from the Data Protection Commission (DPC) and the GDPR text as of early 2026.
GDPR has been in effect since May 2018. That's over seven years now, and a surprising number of Irish websites still aren't properly compliant. Not because business owners don't care - most do - but because the guidance out there is either written in dense legalese or comes from companies trying to sell you compliance software.
This is the guide I wish existed when we started helping our web design clients get their sites sorted. It leaves out the jargon and the scare tactics and sticks to what you actually need to do.
What GDPR actually requires (the plain English version)
The General Data Protection Regulation is an EU law that governs how organisations collect, store, use, and share personal data. In Ireland, it's enforced by the Data Protection Commission (DPC), and it works alongside the Irish Data Protection Act 2018 and the ePrivacy Regulations (SI 336 of 2011).
Personal data is any information that can identify a person - their name, email address, phone number, IP address, or even a cookie identifier. If your website collects any of this (and it almost certainly does), GDPR applies to you.
The core principles are straightforward:
- Lawfulness and transparency: You need a valid legal reason to collect data, and you must tell people what you're doing with it.
- Purpose limitation: Only collect data for specific, stated purposes. Don't collect email addresses for order confirmations and then use them for marketing without separate consent.
- Data minimisation: Only collect what you actually need. If you don't need a phone number, don't ask for one.
- Accuracy: Keep data up to date and correct.
- Storage limitation: Don't keep data forever. Define retention periods and stick to them.
- Security: Protect the data you hold with appropriate technical and organisational measures.
Under the GDPR, there are six lawful bases for processing personal data. For most small business websites, three are relevant. Consent means the person has clearly agreed, contractual necessity means you need the data to fulfil an order or service, and legitimate interest means you have a genuine business reason that doesn't override their rights. You can't just assume consent - silence, pre-ticked boxes, or continued browsing do not count.
Cookie consent: what the DPC actually says
This is the area where most Irish websites fall short, and where the DPC has published specific guidance.
The rules on cookies come from two sources: the GDPR and Ireland's ePrivacy Regulations. Under Regulation 5(3) of the ePrivacy Regulations, you need user consent before placing cookies or similar tracking technologies on their device. The one exception is cookies that are strictly necessary to provide a service the user has explicitly requested.
What does "strictly necessary" actually mean? Session cookies that keep a shopping cart working, login session cookies, and security cookies. That's about it. Google Analytics cookies, Facebook Pixel, advertising cookies, and even most "functionality" cookies like remembering preferences are not strictly necessary.
According to the DPC's guidance, valid cookie consent must be:
- Freely given: Users must have a genuine choice. You can't block access to the site until they accept cookies (no "cookie walls").
- Specific: Users must be able to consent to different categories of cookies separately - analytics, marketing, functional.
- Informed: You must clearly explain what cookies you use and why, in plain language.
- Unambiguous: Consent requires a clear affirmative action. Pre-ticked boxes, scrolling, or continued browsing do not count.
The DPC has also noted that cookie consent should be refreshed approximately every six months. And crucially, rejecting cookies must be as easy as accepting them. If your consent banner has a big green "Accept All" button and a tiny "Manage Settings" link that leads to three more screens, you're not compliant.
A compliant cookie banner should offer equally prominent "Accept" and "Reject" options, with a link to manage granular preferences. No cookies (other than strictly necessary ones) should load before the user makes their choice.
Your privacy policy: what it must include
Every website that collects personal data needs a privacy policy. But it's not just a legal box-ticking exercise - under GDPR Articles 13 and 14, you're required to provide specific information to users in clear, plain language.
Your privacy policy should cover:
- Who you are: Your business name, address, and contact details. If you have a Data Protection Officer (DPO), their contact details too.
- What data you collect: Be specific. Names, email addresses, phone numbers, IP addresses, cookies, analytics data - list it all.
- Why you collect it: The purpose for each type of data, and the legal basis you're relying on (consent, legitimate interest, contractual necessity, etc.).
- Who you share it with: If you use Google Analytics, email marketing platforms, payment processors, or any other third-party services that process user data, name them.
- International transfers: If data is transferred outside the EU/EEA (and it often is - most cloud services are US-based), explain this and what safeguards are in place.
- How long you keep it: Specify retention periods for each type of data.
- User rights: Explain that users have the right to access their data, correct it, delete it, restrict its processing, object to processing, and port their data. Include how they can exercise these rights.
- Right to complain: Users must be told they can lodge a complaint with the DPC (dataprotection.ie).
Skip the 15-page legal template you found online. Write something your customers can actually understand. We help our web design clients create privacy policies that are thorough but readable.
Contact forms and data collection
Contact forms are the most common way small business websites collect personal data. Here's what you need to get right:
- Only ask for what you need. A contact form that asks for name, email, and message is fine. One that also demands phone number, company name, address, date of birth, and job title when none of that is necessary for responding to an enquiry - that's a problem.
- State why you're collecting the data. A short line near the submit button: "We'll use your details to respond to your enquiry. See our Privacy Policy for full details."
- Don't auto-subscribe. If someone fills in a contact form, you cannot automatically add them to your marketing email list. That requires separate, explicit consent.
- Secure the data in transit. Your site must use HTTPS (SSL). If your forms are submitting data over HTTP, that's both a GDPR issue and a security risk.
- Know where form data goes. If you use a third-party form service or your submissions go to a cloud-based CRM, those are data processors. You should have data processing agreements in place with them.
Email marketing consent
Email marketing is governed by both GDPR and Ireland's ePrivacy Regulations. The rules are clear, and the DPC has published specific guidance on this topic.
The default rule: you need prior consent to send marketing emails. That consent must be freely given, specific, informed, and unambiguous - just like cookie consent.
There is one limited exception, often called the "soft opt-in". If someone is an existing customer who gave you their email address in the context of a sale or negotiation, you can email them about similar products or services. This only applies if you gave them a clear and easy way to opt out when you collected their address, and you give them one again in every subsequent email.
What counts as valid consent for email marketing:
- An unticked checkbox that the user actively ticks (never pre-ticked)
- Clear language about what they're signing up for ("Tick this box to receive monthly marketing emails from [Your Business]")
- Separate from other consents - don't bundle marketing consent with terms and conditions
- A record of when and how consent was given
Double opt-in (where users confirm their subscription via a confirmation email) isn't technically required by GDPR, but it's strongly recommended. It proves consent was genuine and avoids accidental sign-ups. Most reputable email platforms like Mailchimp and ActiveCampaign support this.
Every marketing email must include a clear, working unsubscribe link. And when someone unsubscribes, it must be processed promptly - not "within 30 days."
If you use an email marketing agency, check that its sign-up forms and automated emails follow these rules too. Your business is still the data controller, so it is your business that has to be able to show consent was given.
Google Analytics and GDPR compliance
Google Analytics is probably the most common third-party tool on Irish websites, and it's been a flashpoint for GDPR compliance across Europe.
The key issues:
- Google Analytics uses cookies that are not strictly necessary. This means you need user consent before GA loads. If your analytics script fires on page load before the user has interacted with your cookie banner, you're not compliant.
- Data transfers to the US. Google Analytics sends data to Google's servers, which are predominantly in the US. The EU-US Data Privacy Framework (adopted in 2023) currently provides a legal mechanism for these transfers, as Google LLC is a certified participant. However, this landscape has shifted before and could change again.
- IP anonymisation. Google Analytics 4 (GA4) anonymises IP addresses by default, which is an improvement over Universal Analytics. But IP anonymisation alone doesn't make GA compliant - you still need consent for the cookies.
Practical steps for GA4 compliance:
- Configure your cookie consent banner to prevent GA4 from loading until the user consents to analytics cookies.
- Enable Google's Consent Mode v2, which allows GA4 to respect user consent choices.
- Document your use of Google Analytics in your privacy policy, including the data transferred and the legal basis.
- Consider server-side tagging or privacy-focused alternatives like Plausible or Fathom if consent rates significantly impact your data.
This is one of those areas where getting your website technically configured properly matters as much as having the right policies in place.
What the DPC actually enforces
Ireland's Data Protection Commission is the lead supervisory authority for many of the world's largest tech companies (Meta, Google, Apple, TikTok, and others have their EU headquarters here). That means the DPC gets a lot of attention - and handles a lot of high-profile cases.
But what about smaller Irish businesses? Here's the reality:
The DPC handles thousands of complaints annually. Many relate to direct marketing (unsolicited emails and texts), data subject access requests (people asking for their data and being ignored), and data breaches. While the multi-million euro fines make headlines - Meta was fined EUR 1.2 billion in 2023 for data transfer violations - the DPC also takes action against smaller organisations.
Enforcement actions the DPC takes against smaller businesses typically include:
- Warnings and reprimands for first-time or minor violations
- Orders to comply - directions to change specific practices within a set timeframe
- Orders to communicate breaches to affected individuals
- Fines - while the maximum is EUR 20 million or 4% of global revenue, actual fines for SMEs are proportionate and much smaller. But they do happen.
The DPC also runs an active programme of audits and inspections. They've published guidance specifically aimed at SMEs, including a readiness checklist on their website at dataprotection.ie.
The practical takeaway: the DPC is not going to show up at your door because your cookie banner isn't perfect. But if a customer complains about receiving unsolicited marketing emails, or if you suffer a data breach and fail to report it within 72 hours, you will hear from them. Complaints are the most common trigger for enforcement.
Common mistakes Irish businesses make
These are the mistakes we see again and again when we build and audit websites for Irish businesses:
- Cookie banners that don't actually block cookies. Installing a cookie consent plugin but not configuring it to prevent scripts from loading before consent. The banner is cosmetic - analytics and tracking cookies fire regardless.
- "Accept Only" cookie banners. No reject option, or the reject option is deliberately hard to find. The DPC has been clear: rejecting must be as easy as accepting.
- Pre-ticked newsletter checkboxes. Still surprisingly common on checkout pages and contact forms. This has never been valid consent under GDPR.
- Copy-pasted privacy policies. Using a template from another business or country that doesn't reflect what your website actually does. Your privacy policy must be accurate to your data processing activities.
- No SSL certificate. Collecting personal data over an unencrypted connection is a security issue and a GDPR compliance issue. Every website should use HTTPS - full stop.
- Ignoring data subject requests. When someone asks for their data or asks you to delete it, you must respond within one month. Ignoring these requests is one of the most common reasons people complain to the DPC.
- No data processing agreements. If you use a CRM, email platform, analytics tool, or any other third-party service that handles your users' data, you need a data processing agreement. Most reputable platforms offer these - you just need to sign them.
- Keeping data forever. Never defining or implementing data retention periods. Old contact form submissions from three years ago sitting in your inbox? Old customer records you no longer need? Define how long you keep data and delete it when the time is up.
Practical steps to GDPR compliance for your website
Here's a straightforward action plan:
1. Audit what data your website collects
Go through your website and list every point where data is collected: contact forms, newsletter sign-ups, checkout processes, analytics tools, cookies, live chat widgets, embedded social media, and any third-party scripts. Know exactly what data flows through your site and where it goes.
2. Fix your cookie consent
Implement a proper cookie consent mechanism that blocks non-essential cookies until the user consents. Use a reputable consent management platform (CookieYes, Cookiebot, or similar) and configure it correctly - don't just install it and assume it works. Test it: disable consent and check whether analytics and marketing cookies still load.
3. Write (or rewrite) your privacy policy
Make it specific to your business. Cover every point listed in the privacy policy section above. Write it in clear, plain English. Put it in your footer navigation so it's accessible from every page.
4. Fix your forms
Remove unnecessary fields. Add privacy notices near submit buttons. Ensure marketing consent is a separate, unticked checkbox. Make sure all forms submit over HTTPS.
5. Sort your email marketing
Audit your email list. Can you demonstrate valid consent for every contact? If not, consider running a re-permission campaign. Set up double opt-in for new subscribers. Make sure every email includes a working unsubscribe link.
6. Set up data processing agreements
Review every third-party service that processes your users' data. Most major platforms (Google, Mailchimp, HubSpot, Stripe, etc.) have data processing addendums available - find them and accept them.
7. Prepare for data subject requests
Have a process in place for when someone asks to see their data, have it corrected, or have it deleted. Know where all your data is stored so you can respond within the one-month deadline.
8. Document everything
GDPR is big on accountability. Keep records of your processing activities, your consent mechanisms, your data processing agreements, and any data subject requests you receive. If the DPC ever comes knocking, documentation is your best defence.
Key takeaways
- GDPR applies to virtually every business website that collects any personal data - including through cookies and analytics.
- Cookie consent must be obtained before non-essential cookies load, and rejecting cookies must be as easy as accepting them.
- Your privacy policy needs to be specific, accurate, and written in plain language - not a copy-pasted template.
- Email marketing requires prior consent (or qualifies under the limited "existing customer" exception), and every email needs a working unsubscribe link.
- Google Analytics requires cookie consent before loading, and you should document data transfers in your privacy policy.
- The DPC focuses enforcement on complaints, particularly around unsolicited marketing and ignored data subject requests.
- Most compliance failures are practical, not intentional - the biggest issue is cookie banners that don't actually block cookies.
- Start with an audit of what data your site collects, then work through each area systematically.
Getting GDPR compliant isn't about perfection - it's about demonstrating that you take data protection seriously and have made genuine efforts to comply. If you're unsure where your website stands, or you're planning a new site and want to get it right from the start, book a free website audit. We'll look over your site before a free 20-minute call, then walk you through what we'd fix first.