Skip to content
The Tech Genius

Web design · 9 min read

GDPR-compliant website: what an EU business should check before hiring a developer

Eight checks decide whether a website is GDPR-compliant: cookie consent with a real reject option, a lawful basis for every form, a privacy notice that matches what the site does, a data processing agreement, named sub-processors, hosting and transfer safeguards, security basics, and a plan for rights requests and breaches. Here is what each looks like, and what to ask a developer outside the EU.

Published

A GDPR-compliant website comes down to eight checks: non-essential cookies blocked until the visitor consents, with a genuine reject option; a lawful basis for every form and no pre-ticked boxes; a privacy notice that describes what the site actually does; a written data processing agreement with whoever builds and hosts it; named sub-processors; hosting and transfer safeguards for any data that leaves the EU; the security basics; and a plan for rights requests and breaches. Those are the checks, whether your developer is in Dublin or in India — and if they are outside the EU, two of them need a harder look, which is what this post is for.

The regulation applies to the processing of EU residents' personal data wherever the processor sits, so a developer's location changes nothing about your obligations as the controller. What it changes is the paperwork that has to exist for the arrangement to be lawful, and how confidently the developer can answer when you ask for it. We work for companies in Ireland, the Netherlands and Germany from India, and the honest way to earn that work is to put the answers in writing before anyone asks.

Why the developer's location changes the checklist

When a site collects personal data — enquiry forms, newsletter sign-ups, analytics, customer accounts — you are the controller and the developer or agency that builds, hosts or maintains it is usually a processor. GDPR requires a written contract between the two. If the processor is inside the EEA, that contract is the whole of the transfer question. If the processor is outside it, in a country without an adequacy decision, the data leaving the EEA needs its own legal mechanism, and you need to be able to show it. India has no adequacy decision. A developer there who says GDPR does not apply to them has told you something useful about whether to hire them.

The eight checks

GDPR website checklist — what to look for and what to ask
CheckWhat compliant looks likeWhat to ask the developer
Cookie consentNon-essential cookies and tags load only after consent; reject is as easy as acceptShow me the banner blocking analytics before I click
Forms and lawful basisEach form states why it collects data; marketing opt-in is unticked by defaultWhich basis does each form rely on, and where is consent recorded?
Privacy noticeDescribes the real data flows, retention periods and recipientsWill you list every tool that receives data so the notice matches?
Data processing agreementA signed DPA covering build, hosting and maintenanceSend me your DPA before the quote
Sub-processorsHosting, email, analytics and support tools named, with a change noticeWho else touches the data, and where are they?
Hosting and transfersEU hosting where practical; Standard Contractual Clauses for anything leaving the EEAWhere is the data stored, and what covers the transfer to you?
Security basicsHTTPS everywhere, hashed passwords, least-privilege access, offboardingWho has access, and how is it removed when the job ends?
Rights and breachesA way to export or delete a person's data; a written breach responseWhat happens in the first 24 hours after a breach?

None of these require a certification. They require the site to be built a certain way and the arrangement to be documented, and a competent developer can show you both in the first meeting. What you are testing with the questions in the third column is whether they have done this before.

The most common failure is a banner that looks compliant and does nothing: analytics, advertising pixels and embedded video load before the visitor has chosen, and the only prominent button says accept. Compliant behaviour is the reverse. Nothing non-essential loads until consent is given, reject is one click, and the choice is stored and honoured on every page. On a build we do, the consent state gates the tags in the code rather than in a plugin setting someone can switch off later, and we ask you to test it yourself before launch with the browser's network panel open — it is the one check a non-technical owner can run in two minutes.

Forms are the second failure. Marketing consent has to be a separate, unticked box; an enquiry form should collect only what answering the enquiry needs; and every submission should be stored somewhere you can find and delete it when a person asks. That last point is where sites silently break: the form posts to three tools, nobody remembers the third, and a deletion request cannot be fulfilled. The fix is a written list of every recipient, which is also what your privacy notice needs to say.

Transfers outside the EU: the question to ask an Indian developer

Here is how we answer it, so you can compare. Where we process personal data for you, we act as a processor under a written data processing agreement, with Standard Contractual Clauses covering the transfer to India and the UK addendum where UK data is involved. Our sub-processors — hosting, email, the tools that touch your data — are named publicly, and access is granted per person, per project, and removed at handover. We do not hold ISO 27001 or SOC 2 and say so rather than imply an audit that has not happened; what we do instead is set out on our security and data handling page, and the agreement itself is published as our data processing terms.

Two practical points sit underneath. First, most of what a developer touches during a build is not personal data at all — layouts, code, copy — and a well-scoped engagement keeps it that way, with production data staying on EU hosting in your name. Second, where a transfer is needed, your legal adviser may ask for a transfer impact assessment alongside the clauses; ask the developer whether they have supported one before. A yes with a document attached is worth more than any badge.

What it should cost, and the VAT

Compliance is part of a competent build rather than a line item, so the price to hold a quote against is the ordinary market price. A small-business website in 2026 runs €800 to €15,000 in Germany, €500 to €25,000 and up in the Netherlands and €699 to €6,000 and up in Ireland, with about €2,500 typical across the region. Our EU business websites land between €1,800 and €3,500 depending on page count and complexity, with the consent layer, privacy notice wiring and DPA included, and the full euro price list is on our pricing page. If search is part of the plan, German industry commentary treats SEO under €1,000 a month as too thin to work; our EU retainers run €1,000 to €3,500.

For a VAT-registered EU business buying services from a supplier outside the EU, the reverse charge applies: we do not add VAT, and you self-account for it on your return. Give us your VAT number and it goes on the invoice. Invoices are in euros as a zero-rated export of services from India, and payment goes to local EUR account details held through a licensed provider — a domestic transfer, no SWIFT fees. If you compare against UK quotes, we wrote up UK SEO agency pricing separately, and the same reverse-charge treatment applies there.

Germany, the Netherlands and Ireland are three different markets

The regulation is shared; the practice is not. In Germany, expect to need German-language legal pages — Impressum, Datenschutzerklärung — and a developer who understands that a large share of German business buyers will not engage seriously with English-only materials; payment runs on thirty-day terms with an explicit due date, and business-to-business e-invoicing is being phased in through 2026 to 2028. The Netherlands works comfortably in English for business and technology, on thirty-day terms. Ireland is the easiest of the three — native English, terms of around fourteen days, and a market whose small-business pricing sits close to the UK's.

On time zones, India is four and a half hours ahead of Central European Time in winter and three and a half in summer, and four and a half to five and a half ahead of Ireland, which keeps to UK time. In practice that is most of your working day: questions asked in your morning are answered the same day, and work finished in our afternoon is waiting when you arrive. If you already have a site and want to know where it stands before you brief anyone, run it through our free website grader — it checks speed, structure and search readiness in about a minute, and the result is yours whatever you decide.

The two-minute test

Open any developer's own website with the browser's network panel showing, decline the cookie banner, and watch what loads. A developer whose own site sets analytics before you have chosen is unlikely to build yours differently.

Related service

Web design & development

A web design company and website development company in one: custom sites that load fast, rank in Google and convert. Fixed price, and you own everything.

Questions this post gets asked

Can an EU business hire a web developer in India under GDPR?

Yes, provided the paperwork exists: a written data processing agreement, Standard Contractual Clauses covering the transfer to India (which has no adequacy decision), named sub-processors, and access that is granted per project and removed at handover. We provide all four in writing before a quote, and our data processing terms are published.

What makes a cookie banner GDPR-compliant?

Non-essential cookies and tags — analytics, advertising pixels, embedded media — load only after the visitor consents, rejecting is as easy as accepting, and the choice is stored and honoured on every page. You can test any site yourself: decline the banner with the browser's network panel open and watch whether analytics loads anyway.

Do you need ISO 27001 or SOC 2 to be GDPR-compliant?

No. GDPR requires appropriate security and documented processing, not a particular certification. We hold neither and say so plainly; what we do instead — access control, offboarding, named sub-processors, a breach response — is set out on our security page so your legal team can assess it directly.

Do you add VAT to invoices for EU businesses?

No. As a non-EU supplier of business-to-business services, the reverse charge applies — we invoice without VAT and you self-account for it. Provide your VAT number and we reference it. Invoices are in euros, with no Indian GST added, paid to local EUR account details.

Got a question this didn’t answer?

Ask it directly. We answer questions like these all day, and you won’t get a sales sequence for it.