codexier.

Websites

GDPR Checklist for Your Company Website

By CodexierPublished 6 min read

A company website handles personal data from the moment someone fills in a form or a script loads from a third party. The rules are the GDPR, supervised in Sweden by IMY, plus the cookie rules in the Electronic Communications Act. This checklist takes the five places where a typical business site goes wrong and gives you a yes or no question for each, so you can fix what is actually broken rather than rewrite everything.

Contact forms and what you store

  • Does every field on the form have a reason you could explain to the person filling it in? If not, remove it.
  • Is there a short line under the form saying what happens with the data and linking to the policy? Consent is not needed for answering an enquiry, but information is.
  • Do you know where submissions end up: the CMS database, an email inbox, a CRM, a form vendor's servers? Each one is a place to secure and to empty.
  • Is there a deletion routine? Enquiries older than a set period should be removed from every one of those places.
  • Are you asking for personal ID numbers, health information or anything sensitive? If yes, the form needs a stronger legal basis and encryption at rest; consider not asking at all.

Fewer fields also mean more enquiries; our guide to contact forms that get filled in covers the conversion side of the same decision.

Embedded maps, videos and fonts

Embeds are the item most sites miss. A Google Map, a YouTube player or a font loaded from a third-party server sends the visitor's IP address to that company on page load, before any consent. Each is easy to fix once you know it is there.

Maps

Show a static image of the map with a link to open the real one, or load the interactive map only after a click. The address in plain text is what most visitors want anyway.

Videos

Use the privacy-enhanced embed option or a click-to-load placeholder. Self-hosting short videos avoids the issue completely.

Fonts

Host the font files on your own server. It is faster and removes a data flow you would otherwise have to explain.

Chat widgets and social feeds

Treat them like analytics: load after consent, or choose a vendor that runs in the EU and needs no cookies until the chat starts.

Privacy policy content

The policy is not a formality; it is the document IMY and your customers read to check whether you know what you are doing. A copied template that names no systems fails that test. Ours is at /privacy if you want a structure to compare against.

  1. Who is responsible: your legal name, organisation number and a contact address.
  2. What data you collect and where: forms, analytics, newsletter, customer accounts, each with its purpose.
  3. The legal basis for each purpose, in plain words: answering enquiries, fulfilling an order, consent for marketing.
  4. How long you keep each category, as a period rather than 'as long as necessary'.
  5. Which processors receive data: hosting, email, CRM, analytics, and whether any sit outside the EU.
  6. The rights people have and how to exercise them, plus that they can complain to IMY.

Processor agreements with vendors

Every vendor that stores or handles personal data on your behalf is a processor, and the GDPR requires a written agreement with each. Hosting, the form tool, the newsletter service, the CRM and the web agency that has admin access all count. Most large vendors publish a standard agreement you accept in the account settings; check that you actually did, and save a copy. For a web agency, the agreement should be part of the contract, and it should say what happens with backups and access when the engagement ends.

When you do not need to do more than this: a brochure site with a contact form, self-hosted fonts and no marketing pixels is compliant with the items above and a short policy, and does not need a consent platform or a consultant. When we build a site through our website launch package these checks are part of the launch, but if you already have a site and want it reviewed, book a free 15-minute call and we will go through this list against it together.

Frequently asked questions

Do I need a cookie banner if I only use a contact form?

No. A form does not set tracking cookies, and cookies strictly necessary to make the site work do not need consent. You need the banner as soon as you add analytics with cookies, marketing pixels or embeds that set cookies.

Can I keep enquiries in my email forever?

Not without a reason. An enquiry that became a customer relationship can be kept as part of that relationship; one that led nowhere should be deleted after a set period. Write the period into your policy and actually follow it.

Is Google Analytics allowed in Sweden?

IMY has ruled against specific setups that transferred data to the US without adequate safeguards. Current versions with consent, the EU data framework and a proper configuration are used by many Swedish companies, but a cookieless EU-hosted tool is the lower-risk choice and removes most of the paperwork.

Does a small company really need processor agreements?

Yes. Company size changes the fines, not the requirement. In practice it means accepting the vendor's standard agreement and keeping a list of which vendors you have one with.

Want your site checked against this list?

Send us the address. In fifteen minutes we tell you what loads before consent, what the policy is missing and which fixes matter first.

Book a free 15-minute call