
GDPR Website Compliance: A Checklist for Estonian Businesses
Everything you need to know about GDPR for websites – cookies, data processing, forms, and legal texts. A practical guide for international compliance.
Author: Meiko Neuman
Founder and web strategist, Kodulehe Haldus
Why is GDPR Important?
GDPR violations can result in fines of up to €20 million or 4% of annual turnover. In Estonia, the Data Protection Inspectorate (AKI) has conducted 50+ audits on small businesses over the past year alone.
Checklist
Legal Documents - [ ] Privacy Policy (mandatory, accessible from every page) - [ ] Cookie Policy - [ ] Terms and Conditions (for e-commerce) - [ ] Data Processing Agreement (if using third-party services)
Technical Measures - [ ] SSL Certificate (HTTPS) - [ ] Cookie banner (where "rejecting" is as easy as "accepting") - [ ] Google Analytics with anonymised IP or use of Plausible/Fathom - [ ] Encrypted storage of form data - [ ] Backups and encryption
Forms and Data Collection - [ ] Clear purpose (why are we asking for data?) - [ ] Consent checkbox (not pre-selected) - [ ] Link to Privacy Policy - [ ] Data retention period
User Rights - [ ] Right to access own data - [ ] Right to be forgotten (deletion) - [ ] Right to data portability (export) - [ ] Contact email address for inquiries
Common Mistakes
- Automatic "I accept cookies" consent – illegal
- Google Analytics without anonymisation – problematic
- Form data sent via email – unencrypted
- Newsletter without double opt-in – risky
- Privacy Policy missing or only in one language – non-compliant
Permitted Cookies Without Prior Consent
- Session cookies (login)
- Shopping cart cookies
- Language preferences
- Security cookies
All others (analytics, advertising, social media) require explicit consent.
Privacy Policy Minimum Requirements
Must include: - Data controller details (company name, registry code) - Types of data processed - Purpose and legal basis - Retention periods - User rights - Contact information - Data Protection Inspectorate (AKI) contact details (for complaints)
Summary
GDPR compliance is not optional. The good news – once the initial setup is complete, maintenance is minimal. If you have doubts, request an audit – we will check your website's GDPR compliance for €49.
Need help with your website?
Our team maintains, optimises and protects your website. Pricing is agreed based on scope.
Request a quoteAbout the author
Meiko Neuman — Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.