Back to blog
    Header image for the article "GDPR and Websites 2026: A Complete Guide for Estonian Businesses"
    WCAG & GDPR compliance08/06/20269 min

    GDPR and Websites 2026: A Complete Guide for Estonian Businesses

    Want to know how your own site is doing?

    Get a free audit

    GDPR took effect in 2018, but e-privacy rules and Data Protection Inspectorate oversight have evolved by 2026. Here is what must be in order today.

    Author: Meiko Neuman

    Founder and web strategist, Kodulehe Haldus

    What is GDPR and who does it affect?

    GDPR (General Data Protection Regulation) came into force on 25 May 2018 and applies to every company that processes the personal data of EU residents – regardless of the firm's location.

    In Estonia, oversight is conducted by the Data Protection Inspectorate (AKI). In 2024, fines in Estonia totalled €2.3 million (AKI Annual Report).

    What is personal data?

    Any information that can directly or indirectly identify a natural person: - Name, email, phone, address - IP address and cookie identifiers - Location data - Online behaviour (if linked to a profile) - Biometrics, health data (special category – stricter regime)

    10 GDPR requirements for your website

    1. Legal basis Every instance of data collection must have a basis under [GDPR Article 6](https://gdpr-info.eu/art-6-gdpr/): - **Consent** (cookies, newsletter) - **Contract** (e-shop order) - **Legal obligation** (accounting) - **Legitimate interest** (technical security)

    2. Privacy Policy Published on the site, accessible with 1 click, containing [Article 13](https://gdpr-info.eu/art-13-gdpr/) information.

    3. Cookie consent Non-essential cookies (Google Analytics, Facebook Pixel, ads) **require prior consent**. Read our [cookie guide](/en/blog/gdpr-cookie-banners-compliance-guide-2026).

    4. Right of access and erasure Users must be able to download their data (data portability) and request erasure (right to be forgotten).

    5. Data minimisation Collect only what is necessary. A contact form should not ask for a personal identification code.

    6. Security - HTTPS mandatory - Encrypted database - Regular backups - Access restrictions - Read [10 steps for website security](/en/blog/website-security-10-steps-protect-attacks)

    7. Data Processing Agreement (DPA) You must have a DPA with every third party (hosting, email, analytics). Usually based on [Standard Contractual Clauses](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en).

    8. Data location EU/EEA preferred. USA – only within the [EU-US Data Privacy Framework](https://www.dataprivacyframework.gov/) (2023+).

    9. Reporting data breaches To the AKI within 72 hours, and to users "without undue delay" ([Article 33](https://gdpr-info.eu/art-33-gdpr/)).

    10. Data Protection Officer (DPO) Mandatory if: - You regularly engage in large-scale processing of special category data - You are in the public sector

    Fines

    • Up to €20 million or 4% of global turnover (whichever is greater)
    • Lower-level infringements: up to €10M or 2%

    Estonia's largest fine in 2024: €155,000 issued to a marketing company for illegal email campaigns.

    Action Plan

    1. Audit existing data – what do you collect, why, and where is it stored?
    2. Update privacy policy – use our template
    3. Install a cookie banner – Cookiebot, Iubenda, or open-source
    4. DPAs with third parties – ensure these are in place retrospectively
    5. Staff training – at least once a year
    6. Data breach plan – what happens if a leak occurs?

    Where Estonian companies most often slip

    Auditing dozens of small-business sites, the same five mistakes repeat:

    • Cookies fire before consent. The banner exists, but Google Analytics and the Meta Pixel already run on page load. Check DevTools -> Application -> Cookies before clicking anything – if _ga or _fbp is already there, the consent is not valid.
    • "Accept" is a big green button and "Reject" a hidden link. Refusing must be as easy as accepting; unequal design makes the consent invalid under EDPB guidance.
    • A pre-ticked newsletter checkbox in the contact form. Pre-ticked consent is not consent.
    • The privacy policy is a generic template that never names the actual processors (host, email service, analytics) or any retention periods.
    • A legacy database. Email addresses from a 2015 campaign are still on the newsletter list and nobody knows on what basis they were collected.

    Retention periods – concrete numbers

    GDPR does not hand you a table, but Estonian law does. A practical default:

    DataRetentionBasis
    Accounting source documents (invoices, orders)7 yearsAccounting Act
    Contact form enquiry that did not become a contract6–12 monthsLegitimate interest
    Newsletter subscriber dataUntil unsubscribe + 1 year as proofConsent
    Web server logs and IP addresses3–6 monthsLegitimate interest (security)
    Job applicant CVs6 months (longer only with consent)Consent

    Put these numbers in the privacy policy. "We keep data as long as necessary" is not an answer a supervisory authority accepts.

    Handling a data subject request

    Users can ask for a copy of their data, its correction or its deletion. The deadline is one month. A workable process:

    1. Log the request with its arrival date – you need proof you answered in time.
    2. Verify identity reasonably, but do not demand an ID card scan when confirming the email address is enough.
    3. Search every system: CMS, shop orders, newsletter tool, CRM, mailbox, backups.
    4. Answer in a structured format (CSV or PDF) and explain what each field means.
    5. For deletion, state what you are not deleting and why – accounting records cannot be erased just because consent was withdrawn.

    A breach: the first 72 hours

    The moment you suspect a breach, start the clock. Practical order: isolate the system, preserve logs (do not overwrite them by restoring), assess impact – which data categories, how many people, were passwords hashed. If a risk to people's rights is not unlikely, notify the supervisory authority within 72 hours; if the risk is high, notify the individuals directly too. Document the incidents you decide not to report, with reasoning – you may be asked for it.

    Further reading

    Need a GDPR audit? See website security and get in touch.

    Need help with your website?

    Our team maintains, optimises and protects your website. Pricing is agreed based on scope.

    Request a quote

    About the author

    Meiko Neuman Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.

    Related articles