Compliance basicsItaly Developers
GDPR, cookies and privacy basics every small-business website needs
A practical starting checklist for privacy-aware small-business websites in Italy—not a substitute for qualified legal advice.
Most small-business websites collect more personal data than their owners realise: contact forms, analytics, embedded maps, booking widgets. Getting the basics right is achievable without a legal department.
Start with what you actually collect
List every form, cookie, script and third-party embed on the site, and what personal data each one touches. You cannot write an honest privacy notice, or configure consent correctly, without this inventory.
Typical sources
Contact forms, analytics, maps, booking widgets, chat tools
First deliverable
A plain-language data inventory
Practical defaults we build in
- No non-essential cookies fire before consent is given
- A clear, specific privacy notice at the point of data collection
- Data minimisation—collect only what the process actually needs
- A defined retention period instead of storing enquiries indefinitely
- HTTPS everywhere and secure handling of stored submissions
Where a developer's job ends
We can implement consent management, minimise data collection and document what the site does with personal information. Whether that implementation satisfies your specific legal obligations is a question for a qualified privacy adviser, particularly if you handle sensitive data, operate across borders or work in a regulated sector.
Treat this as a foundation, not a certificate
A well-built site makes compliance achievable. It does not replace a proper legal review for a business with real regulatory exposure.