If a business website collects personal data, people must be clearly told who processes it, why it is collected, the legal basis for processing it, who it is shared with, how long it is kept and what rights they have. In practice, this information is often collected in a privacy notice.
The EU's GDPR (General Data Protection Regulation) does not require a page with the specific name "privacy notice". It requires people to receive the necessary information clearly when their personal data is collected.
This guide provides a checklist. It does not replace a legal assessment of your business's particular circumstances.
When does a website process personal data?
A website may receive personal data through, for example:
- a contact form
- a quote request
- appointment booking
- a newsletter subscription
- an online shop
- analytics
- a customer account
- a chat service
- server logs
Names and email addresses are obvious examples of personal data. Online identifiers can also relate to an identifiable person in certain circumstances.
So do not copy a notice from another business's website. First find out what your own website actually does.
Establish these things before writing the text
| Question | What do you need to know? |
|---|---|
| Who processes the data? | The controller's name and contact details |
| What data is collected? | For example, name, email, phone number and message contents |
| Why is it collected? | For example, replying to an enquiry or preparing a contract |
| What is the basis for processing it? | A legal basis under the GDPR |
| How long is the data kept? | A period or the way the retention period is determined |
| Who receives the data? | Service providers, staff or other necessary recipients |
| Is data transferred outside the EU/EEA? | The services used and the transfer mechanism |
| What rights does the person have? | Access, rectification, erasure and other applicable rights |
| Where can they complain? | The right to complain to a supervisory authority |
| Is the information mandatory? | What happens if it is not provided |
| Is automated decision-making used? | If it is actually used |
EEA stands for European Economic Area.
Not every point applies in the same way to every small website. The content must reflect the actual processing.
What should you consider about a contact form?
A typical form might ask for:
- name
- phone number
- company
- a free-text message
Ask within the business:
- who receives these messages
- where they are stored
- how long they are kept
- whether the data is used only to answer enquiries or also for marketing
- whether the form uses third-party services
- whether the site has spam protection that processes user data
If a user's message is later to be used for a purpose other than the one for which it was originally collected, this needs a separate assessment.
A privacy notice and a cookie banner are not the same thing
A privacy notice explains personal data processing.
A cookie banner requests consent, where necessary, for cookies or similar device technologies that are not essential to the service requested by the user.
One does not replace the other.
Traficom's guidance says essential technologies do not require the same consent as non-essential ones. If the site uses analytics or other tracking technologies, for example, assess their purpose and the need for consent separately.
Read also does your business website need a cookie banner.
Does the privacy notice have to name every service provider?
Article 13 of the GDPR requires information about recipients or categories of recipients of personal data, where applicable.
How this is implemented depends on the business's processing and the services it uses.
Do not list services just in case. Do not leave actual processors unidentified either.
The most important thing is that the business itself knows where personal data goes.
What about analytics?
If the site has analytics, establish at least:
- what data is collected
- for what purpose
- which service processes it
- where it is processed
- whether cookies or other device identifiers are used
- whether consent is required before the technology starts
Adding analytics changes the website's privacy situation. Update the notice to reflect the actual implementation.
An easy starting point: complete these sentences
Before writing the final text, the business should be able to complete:
The data controller is ______.
On the website, we collect ______.
We use the data for ______.
The legal basis for processing is ______.
We retain the data for ______.
The data is processed or received by ______.
Data is / is not transferred outside the EU and EEA ______.
Individuals can exercise their rights by contacting ______.
If you cannot answer a point, do not hide it behind ready-made legal text. Establish the actual process first.
How does this relate to GC's website service?
GC's website service includes one standard contact form. That does not mean every customer can have the same privacy notice.
A business is usually the controller of its own customer and enquiry data, and it needs to know why the data is processed and how long it is kept.
The website's privacy text must therefore reflect the customer's actual operations, rather than a generic template from the website provider.
If booking, analytics, a newsletter or another external service is added to the site, the privacy information is checked for those services too.
Sources: EU General Data Protection Regulation 2016/679, particularly Article 13. Traficom / National Cyber Security Centre Finland, Evästeet and the 2026 Supreme Administrative Court decisions on cookies. This guide provides general information, not individual legal advice.
