Prices dated and sourced
CNCodeNexon

Hosting, WordPress and Software Guides

GDPR and CCPA for Small Websites: What You Actually Need to Do

By

Founder and Tech Writer, CodeNexon

Updated • 11 min read

Key Takeaways

  • ▪GDPR maximum fines are €20 million or 4% of worldwide turnover, whichever is higher.
  • ▪The CCPA revenue threshold was $26,625,000 from January 1, 2025.
  • ▪Non-essential cookies such as analytics need consent before they load for EU and UK visitors.
  • ▪Your privacy policy must name the real tools that handle visitor data.
In this guide
  1. What counts as personal data
  2. The GDPR
  3. Cookie consent
  4. The CCPA and US state laws
  5. What a typical small website needs
  6. What a privacy policy should cover
  7. Data security basics
  8. An afternoon privacy checklist
  9. Frequently asked questions
  10. Sources

If your website collects any personal information, such as email addresses, analytics data or contact form messages, privacy law probably applies to you, even as a small business. The GDPR covers you if you offer goods or services to people in the EU or monitor their behavior online, with maximum fines of €20 million or 4% of worldwide annual turnover, whichever is higher. California's CCPA covers for-profit businesses that meet a threshold such as annual gross revenue above $26,625,000 in 2025, with administrative fines of up to $2,663 per violation or $7,988 per intentional violation. For most small sites, the practical steps are the same: collect only what you need, ask consent before setting non-essential cookies, publish an honest privacy policy, and make it easy for people to see, correct or delete their data.

This guide explains who each law applies to, what a typical small website needs to do, and a checklist you can work through in an afternoon.

What counts as personal data

Both laws define personal information broadly. It is any information about an identifiable person, not just names and addresses.

Data your website might collectPersonal data?
Name and email from a contact form or newsletter signupYes
IP addresses in server logsGenerally yes
Analytics cookies and identifiersYes
Order details and delivery addressesYes
Comments with a name and emailYes
Aggregate totals, such as "3,200 visits in September"No, if no one can be identified

Most small websites therefore process personal data, often without thinking of it that way. Analytics, a newsletter form and server logs are enough.

The GDPR

Who it applies to

The General Data Protection Regulation is European Union law. Its territorial scope reaches beyond Europe. It applies to organizations outside the EU when they offer goods or services to people in the EU, or monitor their behavior, for example through tracking and analytics. The United Kingdom has its own near-identical version, usually called the UK GDPR.

A US small business selling only to local customers, with no EU marketing and no EU-targeted offering, may fall outside it. A US online store that ships to Europe, or a site that tracks European visitors' behavior, may fall inside it. If you are unsure, assume it may apply and follow the basics below, which are good practice anyway.

Fines

Article 83 sets two tiers of maximum fines:

TierMaximum fine
Lower tierUp to €10,000,000, or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher
Upper tierUp to €20,000,000, or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher

These are maximums. Regulators consider the nature and severity of the infringement, and small businesses that make good-faith efforts rarely face anything close to these figures. The point is that the law has real enforcement behind it.

The key principles

The GDPR is built on a few principles that translate directly into website decisions:

  • Lawfulness and transparency. Have a legal reason to process data and tell people what you do with it.
  • Purpose limitation. Use data only for the purpose you collected it for.
  • Data minimization. Collect only what you need. If you do not need a phone number, do not ask for it.
  • Accuracy. Keep data correct and let people fix it.
  • Storage limitation. Do not keep data longer than needed.
  • Security. Protect it.

Lawful bases

You need one of six lawful bases for each use of personal data. For a small website, three cover most situations:

Lawful basisTypical website example
ConsentNewsletter signups, non-essential cookies such as analytics and advertising
ContractProcessing an order and delivering it
Legitimate interestsBasic security logs, fraud prevention

The other three are legal obligation, vital interests and public task, which rarely apply to a small business website.

Rights people have

Under the GDPR, people can ask to see the data you hold about them, correct it, delete it, restrict or object to its use, and receive it in a portable format. Respond within one month in most cases. A simple process, an email address and a way to find someone's data in each tool you use, is usually enough for a small site.

Cookie consent rules in Europe come mainly from the ePrivacy Directive, alongside the GDPR. The core rule: non-essential cookies and similar tracking need consent before they are set.

Cookie or storageNeeds consent?
Strictly necessary, such as a shopping cart or login sessionNo
Remembering a visitor's own preference, such as dark modeGenerally no, when it serves a feature the visitor requested
Analytics, such as Google AnalyticsYes, in the EU and UK
Advertising and retargeting pixelsYes
Social media embeds that trackYes

A consent banner that works properly:

  • Blocks non-essential cookies until the visitor accepts.
  • Makes "Decline" as easy as "Accept". A banner with a large Accept button and a hidden decline option is not valid consent under European guidance.
  • Lets visitors change their mind later, for example with a "Cookie settings" link in the footer.
  • Does not use pre-ticked boxes.

CodeNexon follows this pattern: Google Analytics loads only after a visitor chooses Accept, Decline is the same size as Accept, and a Cookie settings link in the footer reopens the choice. Theme and saved-post preferences are stored in the browser because the visitor asked for those features.

Expect your analytics numbers to drop once consent is required, since visitors who decline are not counted. How to Set Up Google Analytics 4 covers consent mode and what to expect.

The CCPA and US state laws

Who the CCPA applies to

The California Consumer Privacy Act, as amended by the CPRA, applies to for-profit businesses that do business in California and meet at least one threshold. According to the California Privacy Protection Agency's published figures, effective January 1, 2025, the annual gross revenue threshold is $26,625,000. The law also covers businesses that buy, sell or share the personal information of 100,000 or more California consumers or households, or that derive 50% or more of annual revenue from selling or sharing personal information.

Most small businesses fall below these thresholds. Check them each year, since the revenue figure is adjusted for inflation.

Fines

The agency's published figures for administrative fines and civil penalties, effective January 1, 2025, are up to $2,663 for each violation or $7,988 for each intentional violation. Because penalties apply per violation, they can add up quickly across many affected people.

What it requires

For businesses it covers, the CCPA gives California residents rights to know what personal information is collected, to delete it, to correct it, and to opt out of its sale or sharing for targeted advertising. Covered businesses must provide a clear privacy notice and, where they sell or share data, a "Do Not Sell or Share My Personal Information" link or equivalent.

Other US states

A growing number of states have passed their own comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas and others. Thresholds and details differ. If you serve customers across the US and are approaching any of these thresholds, take legal advice on which apply.

What a typical small website needs

Here is how the rules map onto the features most small sites have.

FeatureWhat to do
Contact formAsk only for what you need. Say how you will use the message. Do not add people to a mailing list without separate consent
Newsletter signupUse an unticked consent checkbox or a clear signup form, confirm by email where possible, and include unsubscribe links
AnalyticsAsk consent first for EU and UK visitors, or use a consent banner for everyone. Do not send personal data to analytics
Advertising pixelsLoad only after consent
Online storeProcess orders under contract. Keep order data only as long as needed for legal and accounting purposes
CommentsExplain what is stored and publish a way to request removal
Server logsKeep them for a limited time for security, and say so in your policy
Third-party toolsList every service that receives visitor data in your privacy policy

That last row covers more than people expect: email marketing tools, form builders, payment processors, analytics, chat widgets, automation tools and your hosting provider. Zapier vs Make and MailerLite vs Mailchimp cover two common categories.

What a privacy policy should cover

A privacy policy is required in practice by almost every privacy law, and by many services you will connect, such as analytics and payment providers. Write it in plain language and make it match what your site actually does.

  1. Who you are and how to contact you about privacy.
  2. What data you collect, grouped by source: forms, analytics, orders, cookies, logs.
  3. Why you collect it and your legal basis.
  4. Who you share it with, naming the services that process it.
  5. How long you keep it.
  6. People's rights and how to exercise them.
  7. Cookies, what they do and how to change consent.
  8. Children, if relevant. Most small business sites are not aimed at children under 13 and should say so.
  9. When it was last updated.

A privacy policy copied from a template that lists services you do not use, or misses ones you do, is worse than useless, because it is inaccurate. Update it whenever you add a tool that touches visitor data.

Data security basics

Both laws require reasonable security. For a small website, that means:

If you suffer a breach involving personal data, the GDPR generally requires notifying the relevant regulator within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people. US states have their own breach notification laws. Write down who you would call before you need to.

An afternoon privacy checklist

StepDone when
List every tool that collects visitor dataYou have a written list of forms, analytics, pixels, email, payments and hosting
Remove what you do not useOld pixels and plugins are gone
Minimize form fieldsEach form asks only for what you need
Add a working consent bannerNon-essential cookies wait for consent, and Decline is as easy as Accept
Add a cookie settings linkVisitors can change their choice later
Update the privacy policyIt names your real tools and the date it was updated
Set up a request processA contact address and steps to find and delete someone's data
Turn on two-factor authenticationOn every account holding customer data
Set retention rulesOld form entries, logs and backups are deleted on a schedule
Check thresholds yearlyYou know whether laws such as the CCPA apply to you

Frequently asked questions

Does GDPR apply to a US small business website?

It can. The GDPR applies to organizations outside the EU when they offer goods or services to people in the EU or monitor their behavior online, for example through analytics. A business with no EU customers or EU-targeted activity may fall outside it. Take legal advice if unsure.

What are the maximum GDPR fines?

Article 83 sets two tiers: up to €10 million or 2% of worldwide annual turnover, and up to €20 million or 4% of worldwide annual turnover, whichever is higher in each case. These are maximums, and regulators consider the severity of the infringement.

Does the CCPA apply to small businesses?

Usually not. It applies to for-profit businesses doing business in California that meet a threshold, such as annual gross revenue above $26,625,000 as adjusted for 2025, handling personal information of 100,000 or more California consumers or households, or earning half their revenue from selling or sharing it.

If you use non-essential cookies such as analytics or advertising and have visitors from the EU or UK, yes. Consent must be obtained before those cookies are set, declining must be as easy as accepting, and visitors must be able to change their choice later.

Is Google Analytics allowed under GDPR?

It can be used with valid consent and an accurate privacy policy. In the EU and UK, analytics cookies generally need consent before they load. Configure analytics to load only after a visitor accepts, and never send personal information such as email addresses to it.

What should a privacy policy include?

Who you are and how to contact you, what data you collect and from where, why you collect it, which services you share it with, how long you keep it, people's rights and how to use them, how cookies work on your site, and when the policy was last updated.

What should I do if my website has a data breach?

Contain the breach, change affected passwords and work out what data was exposed. Under the GDPR, notify the relevant regulator within 72 hours of becoming aware of a breach that risks people's rights, and tell affected people where required. US state laws have their own notification rules.

Sources

Figures were read on October 10, 2026.

Update history

  • First published.

About the author

Shubham Handore founded CodeNexon in 2024 and writes its guides on hosting, WordPress and the software small teams use to run a business online.

View author profile
PrivacyGDPRCCPACookie consent