What is GDPR and why you need a privacy policy
GDPR is the European data protection law. If your website has visitors from the EU, it applies to you, wherever your business is based.
What GDPR actually asks of a website#
GDPR regulates personal data: anything that can identify a person, including names, emails, and often IP addresses and analytics identifiers. For a typical website the obligations boil down to three things: tell people what data you collect and why, get consent before non-essential tracking, and be able to prove you did both. Contact forms, analytics, embedded videos, and marketing pixels all count as collection.
Why you need a privacy policy#
The privacy policy is the "tell people" part, and it is a legal requirement, not a nice-to-have. It should say what you collect, why, who you share it with (your analytics provider, your form tool), how long you keep it, and how a visitor can ask for their data or have it deleted. Keep it in plain language and date its versions: consent is recorded against a specific policy version, so "which policy did they agree to" must have an answer.
How Weblooks helps#
The GDPR scan checks your site for consent and privacy basics and can block the launch readiness badge until they are fixed. Weblooks-hosted sites can turn on the built-in consent banner, which gates non-essential scripts until the visitor chooses and records every choice in a consent log. See the "GDPR and the consent banner" guide for how that works in practice.