Back to blog
    Header image for the article "GDPR and Websites 2026: A Complete Guide for Estonian Businesses"
    WCAG & GDPR compliance08/06/20269 min

    GDPR and Websites 2026: A Complete Guide for Estonian Businesses

    GDPR took effect in 2018, but e-privacy rules and Data Protection Inspectorate oversight have evolved by 2026. Here is what must be in order today.

    Author: Meiko Neuman

    Founder and web strategist, Kodulehe Haldus

    What is GDPR and who does it affect?

    GDPR (General Data Protection Regulation) came into force on 25 May 2018 and applies to every company that processes the personal data of EU residents – regardless of the firm's location.

    In Estonia, oversight is conducted by the Data Protection Inspectorate (AKI). In 2024, fines in Estonia totalled €2.3 million (AKI Annual Report).

    What is personal data?

    Any information that can directly or indirectly identify a natural person: - Name, email, phone, address - IP address and cookie identifiers - Location data - Online behaviour (if linked to a profile) - Biometrics, health data (special category – stricter regime)

    10 GDPR requirements for your website

    1. Legal basis Every instance of data collection must have a basis under [GDPR Article 6](https://gdpr-info.eu/art-6-gdpr/): - **Consent** (cookies, newsletter) - **Contract** (e-shop order) - **Legal obligation** (accounting) - **Legitimate interest** (technical security)

    2. Privacy Policy Published on the site, accessible with 1 click, containing [Article 13](https://gdpr-info.eu/art-13-gdpr/) information.

    3. Cookie consent Non-essential cookies (Google Analytics, Facebook Pixel, ads) **require prior consent**. Read our [cookie guide](/blogi/gdpr-kupsised-eesti-ettevotjale).

    4. Right of access and erasure Users must be able to download their data (data portability) and request erasure (right to be forgotten).

    5. Data minimisation Collect only what is necessary. A contact form should not ask for a personal identification code.

    6. Security - HTTPS mandatory - Encrypted database - Regular backups - Access restrictions - Read [10 steps for website security](/blogi/kodulehe-turvalisus-10-sammu)

    7. Data Processing Agreement (DPA) You must have a DPA with every third party (hosting, email, analytics). Usually based on [Standard Contractual Clauses](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en).

    8. Data location EU/EEA preferred. USA – only within the [EU-US Data Privacy Framework](https://www.dataprivacyframework.gov/) (2023+).

    9. Reporting data breaches To the AKI within 72 hours, and to users "without undue delay" ([Article 33](https://gdpr-info.eu/art-33-gdpr/)).

    10. Data Protection Officer (DPO) Mandatory if: - You regularly engage in large-scale processing of special category data - You are in the public sector

    Fines

    • Up to €20 million or 4% of global turnover (whichever is greater)
    • Lower-level infringements: up to €10M or 2%

    Estonia's largest fine in 2024: €155,000 issued to a marketing company for illegal email campaigns.

    Action Plan

    1. Audit existing data – what do you collect, why, and where is it stored?
    2. Update privacy policy – use our template
    3. Install a cookie banner – Cookiebot, Iubenda, or open-source
    4. DPAs with third parties – ensure these are in place retrospectively
    5. Staff training – at least once a year
    6. Data breach plan – what happens if a leak occurs?

    Further reading

    Need a GDPR audit? See website security and get in touch.

    Need help with your website?

    Our team maintains, optimises and protects your website. Pricing is agreed based on scope.

    Request a quote

    About the author

    Meiko Neuman Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.

    Related articles