
GDPR and Websites 2026: A Complete Guide for Estonian Businesses
Want to know how your own site is doing?
Get a free auditGDPR took effect in 2018, but e-privacy rules and Data Protection Inspectorate oversight have evolved by 2026. Here is what must be in order today.
Author: Meiko Neuman
Founder and web strategist, Kodulehe Haldus
What is GDPR and who does it affect?
GDPR (General Data Protection Regulation) came into force on 25 May 2018 and applies to every company that processes the personal data of EU residents – regardless of the firm's location.
In Estonia, oversight is conducted by the Data Protection Inspectorate (AKI). In 2024, fines in Estonia totalled €2.3 million (AKI Annual Report).
What is personal data?
Any information that can directly or indirectly identify a natural person: - Name, email, phone, address - IP address and cookie identifiers - Location data - Online behaviour (if linked to a profile) - Biometrics, health data (special category – stricter regime)
10 GDPR requirements for your website
1. Legal basis Every instance of data collection must have a basis under [GDPR Article 6](https://gdpr-info.eu/art-6-gdpr/): - **Consent** (cookies, newsletter) - **Contract** (e-shop order) - **Legal obligation** (accounting) - **Legitimate interest** (technical security)
2. Privacy Policy Published on the site, accessible with 1 click, containing [Article 13](https://gdpr-info.eu/art-13-gdpr/) information.
3. Cookie consent Non-essential cookies (Google Analytics, Facebook Pixel, ads) **require prior consent**. Read our [cookie guide](/en/blog/gdpr-cookie-banners-compliance-guide-2026).
4. Right of access and erasure Users must be able to download their data (data portability) and request erasure (right to be forgotten).
5. Data minimisation Collect only what is necessary. A contact form should not ask for a personal identification code.
6. Security - HTTPS mandatory - Encrypted database - Regular backups - Access restrictions - Read [10 steps for website security](/en/blog/website-security-10-steps-protect-attacks)
7. Data Processing Agreement (DPA) You must have a DPA with every third party (hosting, email, analytics). Usually based on [Standard Contractual Clauses](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en).
8. Data location EU/EEA preferred. USA – only within the [EU-US Data Privacy Framework](https://www.dataprivacyframework.gov/) (2023+).
9. Reporting data breaches To the AKI within 72 hours, and to users "without undue delay" ([Article 33](https://gdpr-info.eu/art-33-gdpr/)).
10. Data Protection Officer (DPO) Mandatory if: - You regularly engage in large-scale processing of special category data - You are in the public sector
Fines
- Up to €20 million or 4% of global turnover (whichever is greater)
- Lower-level infringements: up to €10M or 2%
Estonia's largest fine in 2024: €155,000 issued to a marketing company for illegal email campaigns.
Action Plan
- Audit existing data – what do you collect, why, and where is it stored?
- Update privacy policy – use our template
- Install a cookie banner – Cookiebot, Iubenda, or open-source
- DPAs with third parties – ensure these are in place retrospectively
- Staff training – at least once a year
- Data breach plan – what happens if a leak occurs?
Where Estonian companies most often slip
Auditing dozens of small-business sites, the same five mistakes repeat:
- Cookies fire before consent. The banner exists, but Google Analytics and the Meta Pixel already run on page load. Check DevTools -> Application -> Cookies before clicking anything – if
_gaor_fbpis already there, the consent is not valid. - "Accept" is a big green button and "Reject" a hidden link. Refusing must be as easy as accepting; unequal design makes the consent invalid under EDPB guidance.
- A pre-ticked newsletter checkbox in the contact form. Pre-ticked consent is not consent.
- The privacy policy is a generic template that never names the actual processors (host, email service, analytics) or any retention periods.
- A legacy database. Email addresses from a 2015 campaign are still on the newsletter list and nobody knows on what basis they were collected.
Retention periods – concrete numbers
GDPR does not hand you a table, but Estonian law does. A practical default:
| Data | Retention | Basis |
|---|---|---|
| Accounting source documents (invoices, orders) | 7 years | Accounting Act |
| Contact form enquiry that did not become a contract | 6–12 months | Legitimate interest |
| Newsletter subscriber data | Until unsubscribe + 1 year as proof | Consent |
| Web server logs and IP addresses | 3–6 months | Legitimate interest (security) |
| Job applicant CVs | 6 months (longer only with consent) | Consent |
Put these numbers in the privacy policy. "We keep data as long as necessary" is not an answer a supervisory authority accepts.
Handling a data subject request
Users can ask for a copy of their data, its correction or its deletion. The deadline is one month. A workable process:
- Log the request with its arrival date – you need proof you answered in time.
- Verify identity reasonably, but do not demand an ID card scan when confirming the email address is enough.
- Search every system: CMS, shop orders, newsletter tool, CRM, mailbox, backups.
- Answer in a structured format (CSV or PDF) and explain what each field means.
- For deletion, state what you are not deleting and why – accounting records cannot be erased just because consent was withdrawn.
A breach: the first 72 hours
The moment you suspect a breach, start the clock. Practical order: isolate the system, preserve logs (do not overwrite them by restoring), assess impact – which data categories, how many people, were passwords hashed. If a risk to people's rights is not unlikely, notify the supervisory authority within 72 hours; if the risk is high, notify the individuals directly too. Document the incidents you decide not to report, with reasoning – you may be asked for it.
Further reading
Need a GDPR audit? See website security and get in touch.
Need help with your website?
Our team maintains, optimises and protects your website. Pricing is agreed based on scope.
Request a quoteAbout the author
Meiko Neuman — Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.