{"id":1246,"date":"2026-09-12T14:51:19","date_gmt":"2026-09-12T14:51:19","guid":{"rendered":"https:\/\/netloria.com\/blog\/website-legal-requirements-privacy-cookies-en\/"},"modified":"2026-09-12T18:47:53","modified_gmt":"2026-09-12T18:47:53","slug":"website-legal-requirements-privacy-cookies-en","status":"publish","type":"post","link":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/","title":{"rendered":"What Your Website Legally Needs: Privacy and Cookies"},"content":{"rendered":"<h1>What Your Website Legally Needs: Privacy Policy, Cookies and Consent<\/h1>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1248\" src=\"https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu.webp\" alt=\"\" width=\"1672\" height=\"941\" srcset=\"https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu.webp 1672w, https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu-300x169.webp 300w, https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu-1024x576.webp 1024w, https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu-768x432.webp 768w, https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu-1536x864.webp 1536w\" sizes=\"auto, (max-width: 1672px) 100vw, 1672px\" \/><\/p>\n<p><strong>\u26a1 Quick answer:<\/strong> GDPR doesn&#8217;t apply to a company simply because its site is reachable from Europe. Under <a href=\"https:\/\/gdpr-info.eu\/art-3-gdpr\/\">Article 3 it applies to a non-EU business only if you offer goods or services to people in the EU, or monitor their behaviour there<\/a>. Signs of intent: prices in euros, a language version aimed at a specific market, delivery to EU countries. If that&#8217;s you, three things are needed: a privacy policy, a correctly implemented cookie banner, and clear consent on forms. Fines reach \u20ac20 million or 4% of global annual turnover, whichever is higher.<\/p>\n<p><strong>A note upfront:<\/strong> this is an overview, not legal advice. It will help you know which questions to ask and what&#8217;s worth doing on the technical side \u2014 but documents for a specific business should be reviewed by a lawyer.<\/p>\n<h2>The Core Question: Does GDPR Apply to You<\/h2>\n<p>The most common misconception runs like this: &#8220;the site is accessible from Europe, therefore GDPR applies.&#8221; It doesn&#8217;t work that way, and the regulation&#8217;s own text is fairly specific.<\/p>\n<p>Article 3 describes two situations where GDPR reaches a company with no EU establishment:<\/p>\n<ul>\n<li><strong>Offering goods or services<\/strong> to people located in the EU \u2014 whether paid or free.<\/li>\n<li><strong>Monitoring their behaviour<\/strong>, as far as that behaviour takes place within the EU.<\/li>\n<\/ul>\n<p>The operative word is intent. Technical accessibility from Europe doesn&#8217;t demonstrate it. What does: prices in euros, a dedicated language version for a European market, delivery terms for EU countries, advertising aimed at a European audience.<\/p>\n<p>The second limb \u2014 monitoring \u2014 catches more companies than people expect. If you install an advertising pixel and build audiences for <a href=\"https:\/\/netloria.com\/en\/blog\/retargeting-how-to-bring-back-visitors-en\/\">retargeting<\/a>, and some of your visitors are in the EU, you are monitoring their behaviour.<\/p>\n<h2>When It Probably Doesn&#8217;t Apply<\/h2>\n<p>Worth stating plainly, because a fair amount of unnecessary service has been sold on GDPR anxiety.<\/p>\n<table>\n<tbody>\n<tr>\n<th>Situation<\/th>\n<th>GDPR<\/th>\n<\/tr>\n<tr>\n<td>Local business, local-language site, domestic clients<\/td>\n<td>Most likely no<\/td>\n<\/tr>\n<tr>\n<td>Local-language site, someone from the EU stumbles in<\/td>\n<td>No \u2014 incidental reach doesn&#8217;t count<\/td>\n<\/tr>\n<tr>\n<td>You have an English version and prices in euros<\/td>\n<td>Yes, that indicates intent<\/td>\n<\/tr>\n<tr>\n<td>You accept European cards and ship to the EU<\/td>\n<td>Yes<\/td>\n<\/tr>\n<tr>\n<td>You advertise to audiences in EU countries<\/td>\n<td>Yes<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>If entering the European market is in your plans, it&#8217;s worth building that into the site structure early \u2014 we covered this in the piece on <a href=\"https:\/\/netloria.com\/en\/blog\/multilingual-website-when-you-need-one-en\/\">multilingual websites<\/a>. The legal side follows the same rule: cheaper upfront than retrofitted.<\/p>\n<h2>Local Data Protection Law Still Applies<\/h2>\n<p>Independently of GDPR, most countries have their own personal data legislation, and it usually requires the same two things: telling people why you&#8217;re processing their data, and having a lawful basis for doing so.<\/p>\n<p>For a website that means what the European logic means: you can&#8217;t quietly collect a name, phone number and email from a form and use them however you like. The person has to understand what the data is for and what happens to it.<\/p>\n<p>Worth knowing that this area of law keeps moving. Ukraine, where our team is based, has a draft reworking of its personal data law intended to bring national rules closer to European standards; it passed a first reading at the end of 2024 and was being revised through 2025. Because the status of such documents changes, check the current state before relying on specific provisions \u2014 and do that with a lawyer rather than a blog post.<\/p>\n<p>The good news: the practical steps below are needed under any version. Nobody has repealed the requirement to explain to people what you do with their data.<\/p>\n<h2>On Fines: How Real Is the Risk<\/h2>\n<p>The question owners ask first is simple: what happens if we do nothing.<\/p>\n<p>The GDPR ceiling looks frightening: <a href=\"https:\/\/gdpr-info.eu\/art-83-gdpr\/\">up to \u20ac20 million or 4% of global annual turnover, whichever is higher<\/a>. But context matters: those sums are applied to serious breaches by large organisations, not to a brochure site missing a cookie banner. Regulators weigh the nature of the breach, how long it lasted, how many people were affected, and whether the company cooperated. For a small business the realistic scenario isn&#8217;t a multimillion fine but a complaint from a specific person, a demand to delete data, and friction with a European partner for whom compliance is a condition of doing business. In Netloria&#8217;s experience that last one is the actual trigger far more often than any inspection: a company operates for years with no policy, then a large EU client sends a supplier questionnaire with questions about data processing \u2014 and there&#8217;s nothing to put in the answers.<\/p>\n<p>So the motivation here is commercial rather than fear of punishment. Compliance is an entry condition for certain markets and certain clients.<\/p>\n<h2>Three Documents a Site Should Have<\/h2>\n<p>The minimum set looks like this, and for most businesses it&#8217;s enough.<\/p>\n<p><strong>Privacy policy.<\/strong> The main document. It should answer plain questions: what data you collect, why, how long you keep it, who you share it with (that includes Google Analytics, ad platforms, CRM, delivery services), and how someone can ask for deletion. Link it from the footer of every page.<\/p>\n<p><strong>Cookie policy.<\/strong> Either a separate document or a section of the privacy policy. It describes which files you set and why.<\/p>\n<p><strong>Terms of service or a public offer.<\/strong> Mandatory for stores: ordering, payment, delivery and returns. For a services site, situational.<\/p>\n<p>The worst thing you can do with these documents is download the first template you find and not read it. They typically retain somebody else&#8217;s company name, mentions of services you don&#8217;t use, and references to a jurisdiction you have nothing to do with. Such a document is worse than none: it creates the appearance that the question is settled while actually describing a different business. At Netloria we routinely find, during technical audits, policies listing analytics tools that aren&#8217;t on the site \u2014 and conversely, scripts that are installed but appear nowhere in the document.<\/p>\n<h2>Cookie Banners: When You Need One and How Not to Make It Pointless<\/h2>\n<p>This is where most of the confusion sits, because banners get installed &#8220;just in case&#8221; without understanding the logic.<\/p>\n<p>The rule set by the European directive is straightforward: <a href=\"https:\/\/gdpr.eu\/cookies\/\">consent must be obtained before any cookies are set, except strictly necessary ones<\/a>. Strictly necessary means the ones without which the site doesn&#8217;t function: cart storage, authentication, language settings. Those don&#8217;t need consent, but their purpose should still be explained.<\/p>\n<p>Everything else \u2014 analytics, advertising pixels, chat widgets, embedded maps \u2014 requires consent in advance.<\/p>\n<p>What makes a banner pointless:<\/p>\n<ul>\n<li><strong>It appears, but the scripts have already loaded.<\/strong> The most common technical failure: the banner is there for appearance while Analytics and the pixel fired before the click. Legally that&#8217;s the same as having no banner.<\/li>\n<li><strong>No &#8220;reject&#8221; button.<\/strong> If declining takes three clicks through settings while accepting takes one, that isn&#8217;t a free choice.<\/li>\n<li><strong>Consent pre-selected.<\/strong> Pre-ticked boxes don&#8217;t count as consent.<\/li>\n<li><strong>The banner covers content with no way to dismiss it.<\/strong> That one isn&#8217;t about law \u2014 it&#8217;s about people leaving.<\/li>\n<\/ul>\n<h2>Forms: What Proper Consent Looks Like<\/h2>\n<p>An enquiry form is the most common point where personal data gets collected, and it&#8217;s the easiest place to get right.<\/p>\n<p>The working minimum: a separate, unticked checkbox with short text along the lines of &#8220;I consent to the processing of my personal data in accordance with the privacy policy,&#8221; where the policy is a link. The wording should be comprehensible to someone without a legal background.<\/p>\n<p>What not to do: merge consent to data processing and consent to marketing emails into one checkbox. They&#8217;re different things with different consequences, and combining them is a common mistake. If you plan to send emails, ask separately \u2014 we covered why this matters practically in the piece on <a href=\"https:\/\/netloria.com\/en\/blog\/email-marketing-for-business-en\/\">email marketing<\/a>: a list built without explicit consent generates spam complaints and damages your sending domain.<\/p>\n<p>One more thing: every field in a form is data you&#8217;re responsible for. A pointless &#8220;date of birth&#8221; field creates an obligation for nothing.<\/p>\n<h2>Analytics and Pixels: Where Compliance Fails Most Often<\/h2>\n<p>The typical site has Google Analytics installed, a Meta pixel, sometimes a few more scripts \u2014 and no mention of any of them in its documents.<\/p>\n<p>This is the most widespread failure and simultaneously the easiest to fix. Three things are needed: list every service in the privacy policy, load them through a consent management system so they don&#8217;t fire before the click, and verify that declining actually disables them.<\/p>\n<p>That last check is the most important and the most frequently skipped. Click &#8220;reject,&#8221; then look in developer tools to confirm the scripts genuinely didn&#8217;t load. In our experience they load anyway in roughly half of cases.<\/p>\n<p>The side effect of doing this correctly is unwelcome, and it&#8217;s fairer to say so in advance: some visitors will decline, and your <a href=\"https:\/\/netloria.com\/en\/blog\/web-analytics-metrics-that-matter-en\/\">analytics<\/a> will start showing smaller numbers. That isn&#8217;t a malfunction \u2014 it&#8217;s the real picture replacing a complete one.<\/p>\n<h2>Common Mistakes<\/h2>\n<p><strong>A copied policy.<\/strong> The fastest way to end up with a document describing someone else&#8217;s business.<\/p>\n<p><strong>The document exists, the link doesn&#8217;t.<\/strong> The policy sits at a URL nothing points to. Formally present, functionally absent.<\/p>\n<p><strong>A banner with no actual blocking.<\/strong> Covered above \u2014 appearance instead of action.<\/p>\n<p><strong>Collecting data &#8220;for later.&#8221;<\/strong> More fields means more obligations. Collect what you genuinely need now.<\/p>\n<p><strong>Ignoring processors.<\/strong> If anyone else handles your data \u2014 hosting, CRM, an email service \u2014 that belongs in the policy.<\/p>\n<h2>What It Costs and How Long It Takes<\/h2>\n<p>The technical part is small: connect a consent management platform, configure script blocking until consent, add footer links and form checkboxes. That&#8217;s a few hours of developer work on a typical site.<\/p>\n<p>The main expense is legal: drafting a policy for your specific business and your specific list of services. Cost there depends on complexity and on whether you need European compliance or domestic rules suffice.<\/p>\n<p>The order we recommend at Netloria: first compile a complete list of what the site actually collects and where it sends it \u2014 without that list no lawyer can write a correct document. Then the documents. And only then the technical implementation of banner and forms.<\/p>\n<p>Breaking that order is a familiar story: a ready-made banner gets bought first, the policy is commissioned afterwards, and it emerges that the banner blocks the wrong scripts while the policy describes the wrong services. Both need redoing.<\/p>\n<h2>A Self-Check Checklist<\/h2>\n<ul>\n<li>Every page footer links to the privacy policy.<\/li>\n<li>The policy describes your business and lists the services actually installed.<\/li>\n<li>Forms carry a separate, unticked consent checkbox linking to the policy.<\/li>\n<li>Data-processing consent and marketing consent are separated.<\/li>\n<li>The cookie banner has equally weighted &#8220;accept&#8221; and &#8220;reject&#8221; buttons.<\/li>\n<li>After declining, analytics and pixels genuinely don&#8217;t load \u2014 verified in the browser.<\/li>\n<li>Forms contain no fields you don&#8217;t need.<\/li>\n<\/ul>\n<p>If most of those aren&#8217;t in place, that&#8217;s a normal starting point for most sites, and it closes in a few days of work.<\/p>\n<p>If you want the technical side built correctly from the outset \u2014 <a href=\"https:\/\/netloria.com\/en\/services-en\/\">get in touch<\/a>. We&#8217;re a web studio based in Ukraine, and we&#8217;d start with an audit of what your site actually collects. That list usually surprises the owner more than the documents do.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GDPR doesn&#8217;t apply to everyone \u2014 only if you target the EU market. The three documents a site needs, when a cookie banner is required, and how not to waste it.<\/p>\n","protected":false},"author":2,"featured_media":1248,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_opengraph-title":"What Your Website Legally Needs","_yoast_wpseo_opengraph-description":"\u00abVisible from Europe, therefore GDPR\u00bb is a myth. Article 3 requires intent. When the regulation actually applies and which documents a site needs.","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","_wpml_set_language":"en","_wpml_translation_of":1245,"footnotes":""},"categories":[45],"tags":[14],"class_list":["post-1246","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en","tag-rozrobka"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What Your Website Legally Needs: Privacy and Cookies<\/title>\n<meta name=\"description\" content=\"GDPR doesn&#039;t apply to everyone \u2014 only if you target the EU market. The three documents a site needs, when a cookie banner is required, and how not to waste it.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What Your Website Legally Needs\" \/>\n<meta property=\"og:description\" content=\"\u00abVisible from Europe, therefore GDPR\u00bb is a myth. Article 3 requires intent. When the regulation actually applies and which documents a site needs.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/\" \/>\n<meta property=\"og:site_name\" content=\"NetLoria - \u0421\u0442\u0432\u043e\u0440\u0435\u043d\u043d\u044f \u0441\u0430\u0439\u0442\u0456\u0432 \u043f\u0456\u0434 \u043a\u043b\u044e\u0447\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-12T14:51:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-12T18:47:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1672\" \/>\n\t<meta property=\"og:image:height\" content=\"941\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"\u0412\u0430\u0434\u0438\u043c \u0411\u0430\u0433\u0440\u0456\u0439\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u0412\u0430\u0434\u0438\u043c \u0411\u0430\u0433\u0440\u0456\u0439\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/\"},\"author\":{\"name\":\"\u0412\u0430\u0434\u0438\u043c \u0411\u0430\u0433\u0440\u0456\u0439\",\"@id\":\"https:\\\/\\\/netloria.com\\\/#\\\/schema\\\/person\\\/09fa31b32e780b5362ae5e2908a2b094\"},\"headline\":\"What Your Website Legally Needs: Privacy and Cookies\",\"datePublished\":\"2026-09-12T14:51:19+00:00\",\"dateModified\":\"2026-09-12T18:47:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/\"},\"wordCount\":1897,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/netloria.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/shcho-yurydychno-potribno-sajtu.webp\",\"keywords\":[\"\u0420\u043e\u0437\u0440\u043e\u0431\u043a\u0430\"],\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/\",\"url\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/\",\"name\":\"What Your Website Legally Needs: Privacy and Cookies\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/netloria.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/shcho-yurydychno-potribno-sajtu.webp\",\"datePublished\":\"2026-09-12T14:51:19+00:00\",\"dateModified\":\"2026-09-12T18:47:53+00:00\",\"description\":\"GDPR doesn't apply to everyone \u2014 only if you target the EU market. The three documents a site needs, when a cookie banner is required, and how not to waste it.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/#primaryimage\",\"url\":\"https:\\\/\\\/netloria.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/shcho-yurydychno-potribno-sajtu.webp\",\"contentUrl\":\"https:\\\/\\\/netloria.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/shcho-yurydychno-potribno-sajtu.webp\",\"width\":1672,\"height\":941},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/netloria.com\\\/en\\\/blog-en\\\/website-legal-requirements-privacy-cookies-en\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/netloria.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\\\/\\\/netloria.com\\\/en\\\/category\\\/blog-en\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"What Your Website Legally Needs: Privacy and Cookies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/netloria.com\\\/#website\",\"url\":\"https:\\\/\\\/netloria.com\\\/\",\"name\":\"NetLoria - \u0421\u0442\u0432\u043e\u0440\u0435\u043d\u043d\u044f \u0441\u0430\u0439\u0442\u0456\u0432 \u043f\u0456\u0434 \u043a\u043b\u044e\u0447\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/netloria.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/netloria.com\\\/#organization\",\"name\":\"Netloria\",\"url\":\"https:\\\/\\\/netloria.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/netloria.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/netloria.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/cropped-logo.png\",\"contentUrl\":\"https:\\\/\\\/netloria.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/cropped-logo.png\",\"width\":512,\"height\":512,\"caption\":\"Netloria\"},\"image\":{\"@id\":\"https:\\\/\\\/netloria.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.instagram.com\\\/net.loria\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/vadim-bahrii-6736991a1\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/netloria.com\\\/#\\\/schema\\\/person\\\/09fa31b32e780b5362ae5e2908a2b094\",\"name\":\"Vadym Bahrii\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/netloria.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/img_1262-photoroom-picsart-aiimageenhancer-2-150x150.webp\",\"url\":\"https:\\\/\\\/netloria.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/img_1262-photoroom-picsart-aiimageenhancer-2-150x150.webp\",\"contentUrl\":\"https:\\\/\\\/netloria.com\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/img_1262-photoroom-picsart-aiimageenhancer-2-150x150.webp\",\"caption\":\"Vadym Bahrii\"},\"description\":\"Vadym Bahrii is a full-stack developer and co-founder of the Netloria web studio, with over 6 years of experience building fast, responsive, and scalable websites and digital products for businesses in Ukraine and abroad.\\n\\nHe works across every stage of development \u2014 from architecture and back-end logic to the final front-end. He specializes in custom WordPress development using ACF, PHP, JavaScript, HTML, and CSS, as well as building functionality tailored to a client's specific business needs \u2014 from simple landing pages to complex web applications.\\n\\nHe has hands-on experience integrating WooCommerce for e-commerce projects, connecting payment systems, building subscriptions, LMS platforms (LearnDash), CRM systems, REST APIs, and third-party services. He's comfortable working with databases, server-side logic, AJAX, performance optimization (Core Web Vitals), and complex front-end logic for interactive interfaces.\\n\\nDuring his time at Netloria, he's worked on the full cycle of turnkey website development for startups, e-commerce projects, and corporate clients from the Netherlands, the US, and the UK \u2014 from the technical spec and architecture through launch and support. He writes original articles about web development, design, and digital marketing on the Netloria blog.\\n\\nHis main focus isn't just clean code \u2014 it's comprehensive technical solutions that combine a reliable back end, a smooth UX\\\/UI, and real business results for the client.\",\"url\":\"https:\\\/\\\/netloria.com\\\/en\\\/author\\\/bahrii\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What Your Website Legally Needs: Privacy and Cookies","description":"GDPR doesn't apply to everyone \u2014 only if you target the EU market. The three documents a site needs, when a cookie banner is required, and how not to waste it.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"What Your Website Legally Needs","og_description":"\u00abVisible from Europe, therefore GDPR\u00bb is a myth. Article 3 requires intent. When the regulation actually applies and which documents a site needs.","og_url":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/","og_site_name":"NetLoria - \u0421\u0442\u0432\u043e\u0440\u0435\u043d\u043d\u044f \u0441\u0430\u0439\u0442\u0456\u0432 \u043f\u0456\u0434 \u043a\u043b\u044e\u0447","article_published_time":"2026-09-12T14:51:19+00:00","article_modified_time":"2026-09-12T18:47:53+00:00","og_image":[{"width":1672,"height":941,"url":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu.webp","type":"image\/webp"}],"author":"\u0412\u0430\u0434\u0438\u043c \u0411\u0430\u0433\u0440\u0456\u0439","twitter_card":"summary_large_image","twitter_misc":{"Written by":"\u0412\u0430\u0434\u0438\u043c \u0411\u0430\u0433\u0440\u0456\u0439","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/#article","isPartOf":{"@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/"},"author":{"name":"\u0412\u0430\u0434\u0438\u043c \u0411\u0430\u0433\u0440\u0456\u0439","@id":"https:\/\/netloria.com\/#\/schema\/person\/09fa31b32e780b5362ae5e2908a2b094"},"headline":"What Your Website Legally Needs: Privacy and Cookies","datePublished":"2026-09-12T14:51:19+00:00","dateModified":"2026-09-12T18:47:53+00:00","mainEntityOfPage":{"@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/"},"wordCount":1897,"commentCount":0,"publisher":{"@id":"https:\/\/netloria.com\/#organization"},"image":{"@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/#primaryimage"},"thumbnailUrl":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu.webp","keywords":["\u0420\u043e\u0437\u0440\u043e\u0431\u043a\u0430"],"articleSection":["Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/","url":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/","name":"What Your Website Legally Needs: Privacy and Cookies","isPartOf":{"@id":"https:\/\/netloria.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/#primaryimage"},"image":{"@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/#primaryimage"},"thumbnailUrl":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu.webp","datePublished":"2026-09-12T14:51:19+00:00","dateModified":"2026-09-12T18:47:53+00:00","description":"GDPR doesn't apply to everyone \u2014 only if you target the EU market. The three documents a site needs, when a cookie banner is required, and how not to waste it.","breadcrumb":{"@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/#primaryimage","url":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu.webp","contentUrl":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/09\/shcho-yurydychno-potribno-sajtu.webp","width":1672,"height":941},{"@type":"BreadcrumbList","@id":"https:\/\/netloria.com\/en\/blog-en\/website-legal-requirements-privacy-cookies-en\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/netloria.com\/en\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/netloria.com\/en\/category\/blog-en\/"},{"@type":"ListItem","position":3,"name":"What Your Website Legally Needs: Privacy and Cookies"}]},{"@type":"WebSite","@id":"https:\/\/netloria.com\/#website","url":"https:\/\/netloria.com\/","name":"NetLoria - \u0421\u0442\u0432\u043e\u0440\u0435\u043d\u043d\u044f \u0441\u0430\u0439\u0442\u0456\u0432 \u043f\u0456\u0434 \u043a\u043b\u044e\u0447","description":"","publisher":{"@id":"https:\/\/netloria.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/netloria.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/netloria.com\/#organization","name":"Netloria","url":"https:\/\/netloria.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/netloria.com\/#\/schema\/logo\/image\/","url":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/03\/cropped-logo.png","contentUrl":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/03\/cropped-logo.png","width":512,"height":512,"caption":"Netloria"},"image":{"@id":"https:\/\/netloria.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.instagram.com\/net.loria","https:\/\/www.linkedin.com\/in\/vadim-bahrii-6736991a1\/"]},{"@type":"Person","@id":"https:\/\/netloria.com\/#\/schema\/person\/09fa31b32e780b5362ae5e2908a2b094","name":"Vadym Bahrii","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/02\/img_1262-photoroom-picsart-aiimageenhancer-2-150x150.webp","url":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/02\/img_1262-photoroom-picsart-aiimageenhancer-2-150x150.webp","contentUrl":"https:\/\/netloria.com\/wp-content\/uploads\/2026\/02\/img_1262-photoroom-picsart-aiimageenhancer-2-150x150.webp","caption":"Vadym Bahrii"},"description":"Vadym Bahrii is a full-stack developer and co-founder of the Netloria web studio, with over 6 years of experience building fast, responsive, and scalable websites and digital products for businesses in Ukraine and abroad.\n\nHe works across every stage of development \u2014 from architecture and back-end logic to the final front-end. He specializes in custom WordPress development using ACF, PHP, JavaScript, HTML, and CSS, as well as building functionality tailored to a client's specific business needs \u2014 from simple landing pages to complex web applications.\n\nHe has hands-on experience integrating WooCommerce for e-commerce projects, connecting payment systems, building subscriptions, LMS platforms (LearnDash), CRM systems, REST APIs, and third-party services. He's comfortable working with databases, server-side logic, AJAX, performance optimization (Core Web Vitals), and complex front-end logic for interactive interfaces.\n\nDuring his time at Netloria, he's worked on the full cycle of turnkey website development for startups, e-commerce projects, and corporate clients from the Netherlands, the US, and the UK \u2014 from the technical spec and architecture through launch and support. He writes original articles about web development, design, and digital marketing on the Netloria blog.\n\nHis main focus isn't just clean code \u2014 it's comprehensive technical solutions that combine a reliable back end, a smooth UX\/UI, and real business results for the client.","url":"https:\/\/netloria.com\/en\/author\/bahrii\/"}]}},"_links":{"self":[{"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/posts\/1246","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/comments?post=1246"}],"version-history":[{"count":1,"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/posts\/1246\/revisions"}],"predecessor-version":[{"id":1250,"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/posts\/1246\/revisions\/1250"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/media\/1248"}],"wp:attachment":[{"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/media?parent=1246"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/categories?post=1246"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/netloria.com\/en\/wp-json\/wp\/v2\/tags?post=1246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}