By Mahope
Every agency that builds or maintains websites for European clients is already processing personal data — and already responsible for GDPR compliance, whether anyone has said so out loud or not. This guide turns that vague obligation into a concrete checklist you can complete in two weeks.
It is written for agencies of one to fifty people: no legal department, no DPO on payroll, no budget for outside counsel. Everything here can be done by a technically competent founder with a spreadsheet and an afternoon.
What this guide gives you:
- A plain-language map of which GDPR rules actually apply to an agency
- The three documents every client relationship needs (DPA, processor list, incident plan)
- A 14-day action plan that takes you from "nothing written down" to "defensible"
- Contract clauses you can paste into your next agreement
- Templates and checklists referenced throughout
This guide is practical, not exhaustive. Where the law leaves room for judgement, we tell you what most agencies do and what regulators expect. It is general information about compliance practice — not legal advice for your specific situation.
Chapter 1 — Why This Applies to You (Yes, You)
The most common misconception among small agencies is some version of: "We just build websites. Our clients own the data."
Under GDPR, that's only half true. When your client asks you to build a contact form, set up analytics, or configure email marketing, you are processing personal data on their behalf. That makes you a data processor under Article 28, with direct legal obligations of your own — obligations that exist regardless of what your contract says.
Regulators have been explicit about this. Processing without a written contract that meets Article 28 requirements is itself a violation — for both parties. If your client gets audited and cannot produce a compliant contract with you, that is their violation. If you process data without the right terms in place, it is yours.
Almost everything an agency does touches personal data. If you do any of these for EU-based clients (or their EU visitors), you're in scope. There is no size threshold for GDPR — unlike NIS2, a one-person shop is fully covered.
The dramatic fines make headlines, but they are not the realistic risk for a small agency. The realistic risks are: a client procurement review fails you, a data breach you can't document, a subject access request lands, or insurance won't cover you. None of these require a regulator to be involved. All of them cost real money and reputation. Compliance is cheaper than any of them.
For a small agency, GDPR is mostly documentation discipline, not technology. You almost certainly already do most of the right things technically — encrypted connections, access control, backups. What you lack is the paperwork that proves it. This guide fixes exactly that.
That was the beginning
The complete book continues with eight chapters and three appendices: controller vs processor roles, the three documents that matter, privacy infrastructure, security measures, data subject rights, and a 14-day action plan.
Download the full EPUB — free
The paperwork in this guide is yours to write. The technical scan behind it — cookies, trackers, missing policy pages — is what EUComply Pro runs for you, with a report you can hand to a client: $79 per website per year.
No account, no email, no payment. See all six free e-books.