Back to blog
    Header image for the article "GDPR Website Compliance: A Checklist for Estonian Businesses"
    Security03/06/20268 min

    GDPR Website Compliance: A Checklist for Estonian Businesses

    Everything you need to know about GDPR for websites – cookies, data processing, forms, and legal texts. A practical guide for international compliance.

    Author: Meiko Neuman

    Founder and web strategist, Kodulehe Haldus

    Why is GDPR Important?

    GDPR violations can result in fines of up to €20 million or 4% of annual turnover. In Estonia, the Data Protection Inspectorate (AKI) has conducted 50+ audits on small businesses over the past year alone.

    Checklist

    Legal Documents - [ ] Privacy Policy (mandatory, accessible from every page) - [ ] Cookie Policy - [ ] Terms and Conditions (for e-commerce) - [ ] Data Processing Agreement (if using third-party services)

    Technical Measures - [ ] SSL Certificate (HTTPS) - [ ] Cookie banner (where "rejecting" is as easy as "accepting") - [ ] Google Analytics with anonymised IP or use of Plausible/Fathom - [ ] Encrypted storage of form data - [ ] Backups and encryption

    Forms and Data Collection - [ ] Clear purpose (why are we asking for data?) - [ ] Consent checkbox (not pre-selected) - [ ] Link to Privacy Policy - [ ] Data retention period

    User Rights - [ ] Right to access own data - [ ] Right to be forgotten (deletion) - [ ] Right to data portability (export) - [ ] Contact email address for inquiries

    Common Mistakes

    1. Automatic "I accept cookies" consent – illegal
    2. Google Analytics without anonymisation – problematic
    3. Form data sent via email – unencrypted
    4. Newsletter without double opt-in – risky
    5. Privacy Policy missing or only in one language – non-compliant

    Permitted Cookies Without Prior Consent

    • Session cookies (login)
    • Shopping cart cookies
    • Language preferences
    • Security cookies

    All others (analytics, advertising, social media) require explicit consent.

    Privacy Policy Minimum Requirements

    Must include: - Data controller details (company name, registry code) - Types of data processed - Purpose and legal basis - Retention periods - User rights - Contact information - Data Protection Inspectorate (AKI) contact details (for complaints)

    Summary

    GDPR compliance is not optional. The good news – once the initial setup is complete, maintenance is minimal. If you have doubts, request an audit – we will check your website's GDPR compliance for €49.

    Need help with your website?

    Our team maintains, optimises and protects your website. Pricing is agreed based on scope.

    Request a quote

    About the author

    Meiko Neuman Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.

    Related articles