Legal
What happens if my website is not GDPR compliant?
For a small business the realistic exposure is a complaint to the regulator, an investigation, and an order to fix it — with fines reserved mostly for serious or persistent cases. The more common practical cost is being blocked from advertising platforms and losing B2B clients whose procurement checks fail you.
How problems usually surface
- A visitor complains to the regulator about a cookie banner or a marketing email
- A customer makes a subject access request you cannot answer within a month
- A B2B prospect’s procurement process asks for your data handling and you have none documented
- An advertising or payment platform rejects your account for missing policies
- A breach occurs and the response obligations arrive all at once
The realistic first steps
Inventory what you collect, name every third party that receives it, write an accurate privacy notice, stop setting non-essential cookies before consent, and be able to delete someone on request. That covers the great majority of small-site exposure.
What actually attracts enforcement
Ignoring a subject access request, marketing without consent, and failing to report a qualifying breach. Regulators are considerably more interested in a business that would not cooperate than in one whose policy was out of date.
The longer version
This answer is deliberately short. If you want the full treatment, Buying a website: the questions that decide what you actually own covers it in about 5 minutes — free, ungated, written from client work.
Who answered this
Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan — fifteen live client sites, six of them stores taking real payments. These answers come from those projects rather than from a content brief. More about how I work, or ask me something directly.