GDPR and cookies are often treated as an annoying formality that can be solved by copying a legal text and adding a banner to the website. For many SMEs, the problem is that this apparent solution does not always comply. A generic policy, a notice that does not allow users to reject cookies or forms that collect data without proper information can become a real risk.

Not every website has the same level of exposure, but any business that captures leads, measures visits, uses advertising pixels, sends newsletters or allows bookings is processing personal data. The goal is not to panic, but to understand which points are most often reviewed and what should be corrected before a complaint appears.

What can really lead to a fine

Penalties usually do not arrive because one perfect sentence is missing from the footer. They arrive when a website collects data without a clear basis, installs non-essential cookies before consent, does not make rejection as easy as acceptance or fails to explain who processes the data and for what purpose.

Problems can also appear when forms do not include an acceptance checkbox where needed, when commercial messages are sent without valid consent or when data is shared with external tools without reviewing their conditions. Google Analytics, Meta Pixel, CRMs, email platforms and web chats can be useful, but they need to be configured with care.

The cookie banner is not decoration

A cookie banner must let the user decide. If the website loads analytics or advertising before the user accepts, the notice is not doing its job. If there is only a large accept button and the reject option is hidden, that is not good practice either.

  • Accept and reject should both be clearly available.
  • Non-essential cookies should not load before consent.
  • Settings should explain categories: technical, analytics, advertising or others.
  • The cookie policy should state which cookies are used, who installs them and how long they last.
  • Consent should be changeable afterwards.

Forms and lead capture

Contact, quote, booking and download forms are among the most important points. The person must know who will receive their data, what it will be used for, how long it will be kept and how they can exercise their rights. This can be handled with a first information layer next to the form and a link to the full privacy policy.

It is also better to ask only for the data that is necessary. If name, email and message are enough to answer a question, requesting date of birth, full address or sensitive information adds risk without adding value. Less data handled well is usually better than a lot of data handled poorly.

External tools and automations

A modern website rarely works alone. It may be connected to a CRM, calendar, email marketing platform, WhatsApp, analytics, chat, payment gateway or internal automation. Each integration should be reviewed: what data it receives, where it stores it, which provider is involved and whether it must be reflected in the legal texts.

Automation helps a lot, but it should not bypass compliance. For example, a form can create a lead in the CRM and send an internal alert, but if that person is later added to a commercial list without consent, the problem remains. Technology should follow the permission received, not invent it.

Where to start

A good first step is to audit the real website, not only the legal pages. Check which cookies load on entry, which scripts are installed, which forms exist, which data travels to third parties and whether the policies explain what actually happens. Many businesses discover old tools that nobody uses but that are still collecting data.

Then the basics can be corrected: a properly configured banner, policies adapted to the business, forms with clear information, consent for commercial communications and a review of providers. The website does not need to become an endless legal document. What it says needs to match what it does.

At Bertronit, we help SMEs review their websites, configure cookies, organise forms and connect digital tools without neglecting compliance. If you want to reduce risk and have a more serious website for customers and providers, contact Bertronit and we will review which points should be corrected first.