What Legal Requirements Does a Website Need to Meet in the EU?

Building a website is not only about design, development, hosting and performance. Once a website starts collecting information, running analytics, accepting enquiries, selling products or interacting with customers, it also becomes part of a much larger legal framework. And GDPR is only one part of it.

There is no single piece of legislation called “the website law”. Instead, European websites can fall under several different regulations and directives depending on what the website actually does.

A simple company website, an online store and a marketplace do not necessarily have the same obligations.

GDPR and personal data

The General Data Protection Regulation, better known as GDPR, applies whenever a business processes personal data covered by the regulation. On a website, that can happen more easily than people realise. A contact form collecting a name and email address is processing personal data. So can newsletter registrations, customer accounts, analytics systems, advertising tools, IP addresses, booking systems and CRM integrations. GDPR requires businesses to have a lawful basis for processing personal information and to explain what information is collected, why it is collected, how long it is retained, who it may be shared with and what rights the individual has. That is why a privacy policy should not simply be copied from another website. The policy should describe what the particular business and its website actually do.

 

GDPR also includes the principle of data protection by design and by default. Privacy therefore should not be something added to a website after development has finished.

The way forms, databases, integrations, analytics and third-party services are implemented can all form part of the compliance picture.

Cookie consent and the ePrivacy rules

GDPR and cookie consent are often treated as if they were the same thing. They are not. European cookie requirements also originate from the ePrivacy framework. Strictly necessary cookies can generally operate without prior consent. A shopping-cart cookie, for example, may be necessary to provide functionality specifically requested by the visitor. Advertising, behavioural tracking and many analytics technologies are different. Where consent is required, those technologies should not start collecting information before the visitor has made a choice. Visitors must receive clear information about the purposes involved and withdrawing consent should be as easy as giving it. This is why a cookie banner that simply says “By continuing to use this website you accept cookies” is not a proper technical solution for many modern websites. A consent management platform needs to control what is actually loaded behind the banner.

Who owns and operates the website?

European rules also require commercial websites to make certain information about the business accessible. Depending on the business, this can include the legal company name, geographical address, contact information, company or trade register details, registration number and VAT identification number. Prices displayed by online services must also be presented clearly. In other words, a website should make it reasonably clear who the customer is actually dealing with. This becomes especially important when a brand name is different from the legal company operating the website.

E-commerce and consumer protection

Once customers can purchase through a website, considerably more legislation becomes relevant. EU consumer protection rules require online traders to provide clear information before a customer enters into a contract. This includes information about the product or service, total price, additional charges, payment, delivery, the identity and contact information of the trader and, where applicable, the right of withdrawal. Checkout design itself can also have legal consequences. For example, when placing an order creates an obligation to pay, the customer must clearly understand that consequence when submitting the order. EU rules also prohibit practices such as using pre-ticked boxes to charge customers for additional products or services. And since 19 June 2026, another particularly visible requirement has become relevant to many online traders: where the consumer has a right of withdrawal from an eligible distance contract concluded through an online interface, the trader must provide an easily accessible online withdrawal function.

We have written about the withdrawal button separately because it is a good example of how legal changes can create actual development requirements — not merely another paragraph that needs to be added to a Terms & Conditions page.

Accessibility is becoming a development requirement

Accessibility is another area that can no longer be treated purely as a design preference.

The European Accessibility Act has applied to covered products and services since 28 June 2025. Among the services within its scope is e-commerce. Accessibility can affect navigation, keyboard operation, contrast, forms, content structure, screen-reader compatibility, alternative text and the way interactive elements are implemented. There are exemptions. For example, EU guidance notes an exemption for microenterprises providing services, subject to the applicable criteria. But even where a business falls outside a specific statutory requirement, accessibility is increasingly something worth considering during development rather than trying to retrofit later.

AI adds another layer

Artificial intelligence is now beginning to affect website compliance as well. From 2 August 2026, transparency obligations under Article 50 of the EU AI Act apply to certain AI systems. Among other things, users interacting directly with an AI system generally need to be informed that they are interacting with AI unless that fact is already obvious in the circumstances. This matters for websites using AI customer-service agents, conversational assistants and certain other AI-powered interactive features. There are also transparency requirements relating to certain AI-generated or manipulated content. The exact obligations depend on how the AI system and content are being used. Adding an AI chatbot to a website is therefore no longer purely a question of installing a plugin and choosing where the chat bubble should appear.

Security is part of privacy

Legal compliance and technical security are also closely connected. GDPR requires appropriate technical and organisational measures to protect personal data. The appropriate level depends on the nature and risk of the processing, but website security cannot simply be separated from data protection.

Secure hosting, access management, HTTPS, software updates, backups, protection against common attacks and sensible handling of customer data all contribute to the wider picture. A beautiful privacy policy does very little if the underlying website is poorly secured.

Not every website has the same requirements

This is perhaps the most important point. There is no universal checklist that can make every European website compliant. A five-page website for a construction company has very different requirements from a Shopify store selling across the EU. A booking platform, financial service, healthcare provider or online marketplace can introduce another set of sector-specific obligations. National legislation also continues to matter alongside EU law. That is why we prefer to think about compliance as part of the website architecture rather than as a collection of legal pages added immediately before launch.

How we approach it

When we develop a website, we consider the technical side of compliance as part of the project.

That can include consent management, controlling analytics and advertising scripts, privacy-friendly form configuration, required company information, e-commerce functionality, accessibility considerations, withdrawal functionality and the implementation of customer-provided legal documentation.

 

We can build the technical infrastructure required to support compliance and point out common requirements that affect website development. The business itself remains responsible for determining which legislation applies to its activities and for the accuracy of its legal documents.

For projects involving unusual processing, regulated industries, complex international operations or other significant legal questions, we recommend having the final implementation and legal documentation reviewed by a qualified legal or data-protection professional.

© Vossen Studios. All rights reserved.