Think my site is small, this does not concern me? If you have a contact form, Google Analytics or a store — you collect personal data and the rules apply to you too. Here is the practical minimum. (Note: this is a general guide, not legal advice — for your specific case, consult a lawyer.)
1. A privacy policy
A page stating: which data you collect (name, email, phone…), why, how long you keep it, who you share it with (e.g. a courier for delivery), and how a user can request deletion. Plain language — not a copied 5,000-word foreign text nobody reads.
2. Cookie consent
If you use analytics or marketing pixels, the cookie banner should offer a real choice (accept / decline), not just OK. Strictly necessary cookies (cart, login) need no consent — but say they exist.
3. Forms
Next to every form: a short sentence on why you ask for the data, plus a consent checkbox for sensitive purposes (newsletter, marketing). Do not collect more than you need — less data, less liability.
4. Stores — double care
Order and billing data: keep only as long as required, and card data NEVER on your side — it goes straight to the bank or processor (which makes CaSys/cPay payments a legal shield too).
A quick self-check
Does the site have: a privacy page in the footer ☐ a cookie banner with choice ☐ consent on the newsletter form ☐ SSL ☐. Four ticks = a calm sleep.