GDPR and CCPA for Small Websites: What You Actually Need to Do
Founder and Tech Writer, CodeNexon
Key Takeaways
- ▪GDPR maximum fines are €20 million or 4% of worldwide turnover, whichever is higher.
- ▪The CCPA revenue threshold was $26,625,000 from January 1, 2025.
- ▪Non-essential cookies such as analytics need consent before they load for EU and UK visitors.
- ▪Your privacy policy must name the real tools that handle visitor data.
In this guide
If your website collects any personal information, such as email addresses, analytics data or contact form messages, privacy law probably applies to you, even as a small business. The GDPR covers you if you offer goods or services to people in the EU or monitor their behavior online, with maximum fines of €20 million or 4% of worldwide annual turnover, whichever is higher. California's CCPA covers for-profit businesses that meet a threshold such as annual gross revenue above $26,625,000 in 2025, with administrative fines of up to $2,663 per violation or $7,988 per intentional violation. For most small sites, the practical steps are the same: collect only what you need, ask consent before setting non-essential cookies, publish an honest privacy policy, and make it easy for people to see, correct or delete their data.
This guide explains who each law applies to, what a typical small website needs to do, and a checklist you can work through in an afternoon.
What counts as personal data
Both laws define personal information broadly. It is any information about an identifiable person, not just names and addresses.
| Data your website might collect | Personal data? |
|---|---|
| Name and email from a contact form or newsletter signup | Yes |
| IP addresses in server logs | Generally yes |
| Analytics cookies and identifiers | Yes |
| Order details and delivery addresses | Yes |
| Comments with a name and email | Yes |
| Aggregate totals, such as "3,200 visits in September" | No, if no one can be identified |
Most small websites therefore process personal data, often without thinking of it that way. Analytics, a newsletter form and server logs are enough.
The GDPR
Who it applies to
The General Data Protection Regulation is European Union law. Its territorial scope reaches beyond Europe. It applies to organizations outside the EU when they offer goods or services to people in the EU, or monitor their behavior, for example through tracking and analytics. The United Kingdom has its own near-identical version, usually called the UK GDPR.
A US small business selling only to local customers, with no EU marketing and no EU-targeted offering, may fall outside it. A US online store that ships to Europe, or a site that tracks European visitors' behavior, may fall inside it. If you are unsure, assume it may apply and follow the basics below, which are good practice anyway.
Fines
Article 83 sets two tiers of maximum fines:
| Tier | Maximum fine |
|---|---|
| Lower tier | Up to €10,000,000, or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher |
| Upper tier | Up to €20,000,000, or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher |
These are maximums. Regulators consider the nature and severity of the infringement, and small businesses that make good-faith efforts rarely face anything close to these figures. The point is that the law has real enforcement behind it.
The key principles
The GDPR is built on a few principles that translate directly into website decisions:
- Lawfulness and transparency. Have a legal reason to process data and tell people what you do with it.
- Purpose limitation. Use data only for the purpose you collected it for.
- Data minimization. Collect only what you need. If you do not need a phone number, do not ask for it.
- Accuracy. Keep data correct and let people fix it.
- Storage limitation. Do not keep data longer than needed.
- Security. Protect it.
Lawful bases
You need one of six lawful bases for each use of personal data. For a small website, three cover most situations:
| Lawful basis | Typical website example |
|---|---|
| Consent | Newsletter signups, non-essential cookies such as analytics and advertising |
| Contract | Processing an order and delivering it |
| Legitimate interests | Basic security logs, fraud prevention |
The other three are legal obligation, vital interests and public task, which rarely apply to a small business website.
Rights people have
Under the GDPR, people can ask to see the data you hold about them, correct it, delete it, restrict or object to its use, and receive it in a portable format. Respond within one month in most cases. A simple process, an email address and a way to find someone's data in each tool you use, is usually enough for a small site.
Cookie consent
Cookie consent rules in Europe come mainly from the ePrivacy Directive, alongside the GDPR. The core rule: non-essential cookies and similar tracking need consent before they are set.
| Cookie or storage | Needs consent? |
|---|---|
| Strictly necessary, such as a shopping cart or login session | No |
| Remembering a visitor's own preference, such as dark mode | Generally no, when it serves a feature the visitor requested |
| Analytics, such as Google Analytics | Yes, in the EU and UK |
| Advertising and retargeting pixels | Yes |
| Social media embeds that track | Yes |
A consent banner that works properly:
- Blocks non-essential cookies until the visitor accepts.
- Makes "Decline" as easy as "Accept". A banner with a large Accept button and a hidden decline option is not valid consent under European guidance.
- Lets visitors change their mind later, for example with a "Cookie settings" link in the footer.
- Does not use pre-ticked boxes.
CodeNexon follows this pattern: Google Analytics loads only after a visitor chooses Accept, Decline is the same size as Accept, and a Cookie settings link in the footer reopens the choice. Theme and saved-post preferences are stored in the browser because the visitor asked for those features.
Expect your analytics numbers to drop once consent is required, since visitors who decline are not counted. How to Set Up Google Analytics 4 covers consent mode and what to expect.
The CCPA and US state laws
Who the CCPA applies to
The California Consumer Privacy Act, as amended by the CPRA, applies to for-profit businesses that do business in California and meet at least one threshold. According to the California Privacy Protection Agency's published figures, effective January 1, 2025, the annual gross revenue threshold is $26,625,000. The law also covers businesses that buy, sell or share the personal information of 100,000 or more California consumers or households, or that derive 50% or more of annual revenue from selling or sharing personal information.
Most small businesses fall below these thresholds. Check them each year, since the revenue figure is adjusted for inflation.
Fines
The agency's published figures for administrative fines and civil penalties, effective January 1, 2025, are up to $2,663 for each violation or $7,988 for each intentional violation. Because penalties apply per violation, they can add up quickly across many affected people.
What it requires
For businesses it covers, the CCPA gives California residents rights to know what personal information is collected, to delete it, to correct it, and to opt out of its sale or sharing for targeted advertising. Covered businesses must provide a clear privacy notice and, where they sell or share data, a "Do Not Sell or Share My Personal Information" link or equivalent.
Other US states
A growing number of states have passed their own comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas and others. Thresholds and details differ. If you serve customers across the US and are approaching any of these thresholds, take legal advice on which apply.
What a typical small website needs
Here is how the rules map onto the features most small sites have.
| Feature | What to do |
|---|---|
| Contact form | Ask only for what you need. Say how you will use the message. Do not add people to a mailing list without separate consent |
| Newsletter signup | Use an unticked consent checkbox or a clear signup form, confirm by email where possible, and include unsubscribe links |
| Analytics | Ask consent first for EU and UK visitors, or use a consent banner for everyone. Do not send personal data to analytics |
| Advertising pixels | Load only after consent |
| Online store | Process orders under contract. Keep order data only as long as needed for legal and accounting purposes |
| Comments | Explain what is stored and publish a way to request removal |
| Server logs | Keep them for a limited time for security, and say so in your policy |
| Third-party tools | List every service that receives visitor data in your privacy policy |
That last row covers more than people expect: email marketing tools, form builders, payment processors, analytics, chat widgets, automation tools and your hosting provider. Zapier vs Make and MailerLite vs Mailchimp cover two common categories.
What a privacy policy should cover
A privacy policy is required in practice by almost every privacy law, and by many services you will connect, such as analytics and payment providers. Write it in plain language and make it match what your site actually does.
- Who you are and how to contact you about privacy.
- What data you collect, grouped by source: forms, analytics, orders, cookies, logs.
- Why you collect it and your legal basis.
- Who you share it with, naming the services that process it.
- How long you keep it.
- People's rights and how to exercise them.
- Cookies, what they do and how to change consent.
- Children, if relevant. Most small business sites are not aimed at children under 13 and should say so.
- When it was last updated.
A privacy policy copied from a template that lists services you do not use, or misses ones you do, is worse than useless, because it is inaccurate. Update it whenever you add a tool that touches visitor data.
Data security basics
Both laws require reasonable security. For a small website, that means:
- HTTPS on every page. How to Get a Free SSL Certificate With Let's Encrypt covers it.
- Strong, unique passwords stored in a password manager. Password Managers for Small Business covers it.
- Two-factor authentication on email, hosting, your website admin and every tool holding customer data.
- Software kept up to date. WordPress Security Checklist covers WordPress sites.
- Backups encrypted and stored securely, and deleted on a schedule.
- Access limited to people who need it, and removed when they leave.
If you suffer a breach involving personal data, the GDPR generally requires notifying the relevant regulator within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people. US states have their own breach notification laws. Write down who you would call before you need to.
An afternoon privacy checklist
| Step | Done when |
|---|---|
| List every tool that collects visitor data | You have a written list of forms, analytics, pixels, email, payments and hosting |
| Remove what you do not use | Old pixels and plugins are gone |
| Minimize form fields | Each form asks only for what you need |
| Add a working consent banner | Non-essential cookies wait for consent, and Decline is as easy as Accept |
| Add a cookie settings link | Visitors can change their choice later |
| Update the privacy policy | It names your real tools and the date it was updated |
| Set up a request process | A contact address and steps to find and delete someone's data |
| Turn on two-factor authentication | On every account holding customer data |
| Set retention rules | Old form entries, logs and backups are deleted on a schedule |
| Check thresholds yearly | You know whether laws such as the CCPA apply to you |
Frequently asked questions
Does GDPR apply to a US small business website?
It can. The GDPR applies to organizations outside the EU when they offer goods or services to people in the EU or monitor their behavior online, for example through analytics. A business with no EU customers or EU-targeted activity may fall outside it. Take legal advice if unsure.
What are the maximum GDPR fines?
Article 83 sets two tiers: up to €10 million or 2% of worldwide annual turnover, and up to €20 million or 4% of worldwide annual turnover, whichever is higher in each case. These are maximums, and regulators consider the severity of the infringement.
Does the CCPA apply to small businesses?
Usually not. It applies to for-profit businesses doing business in California that meet a threshold, such as annual gross revenue above $26,625,000 as adjusted for 2025, handling personal information of 100,000 or more California consumers or households, or earning half their revenue from selling or sharing it.
Do I need a cookie banner?
If you use non-essential cookies such as analytics or advertising and have visitors from the EU or UK, yes. Consent must be obtained before those cookies are set, declining must be as easy as accepting, and visitors must be able to change their choice later.
Is Google Analytics allowed under GDPR?
It can be used with valid consent and an accurate privacy policy. In the EU and UK, analytics cookies generally need consent before they load. Configure analytics to load only after a visitor accepts, and never send personal information such as email addresses to it.
What should a privacy policy include?
Who you are and how to contact you, what data you collect and from where, why you collect it, which services you share it with, how long you keep it, people's rights and how to use them, how cookies work on your site, and when the policy was last updated.
What should I do if my website has a data breach?
Contain the breach, change affected passwords and work out what data was exposed. Under the GDPR, notify the relevant regulator within 72 hours of becoming aware of a breach that risks people's rights, and tell affected people where required. US state laws have their own notification rules.
Sources
Figures were read on October 10, 2026.
Update history
- First published.