Common GDPR conformance issues on older websites

A computer screen showing a tick next to GDPR conformance.

Nov 13, 2025

by Irene Koukia

Table of contents

Most older websites, especially those built before 2018 (before the GDPR came into effect), typically face several compliance challenges. Let’s explore the most common issues and what you can do to fix them.​

Cookie banners that don’t comply with the GDPR

Many older sites feature cookie banners that merely inform visitors cookies are being used, often with just a single “Accept” button. However, under the EU ePrivacy Directive and GDPR, you must provide clear information about the cookies your website uses. Importantly, you must offer visitors the choice to accept or decline them. Visitors should also have the ability to withdraw their consent at any time.

Additionally, your site must include a dedicated Cookie Policy or Privacy Policy that explains how cookies are used and how personal data collected through your website is processed. This ensures full transparency.​

Opt-in forms need proper consent mechanisms

If your site has opt-in forms for newsletters or digital downloads like PDFs, ensuring valid consent is essential. While the GDPR doesn't explicitly mandate double opt-in (the email confirmation step), it does require that consent is freely given, specific, informed, and unambiguous.

Double opt-in is considered best practice because it provides strong evidence that the person who submitted the form actually owns that email address and genuinely consented. It also helps protect you from spam complaints and invalid email addresses.

Missing legal information lowers trust

Have you ever visited a site and wondered who owns it or where the company is based? Finding essential legal details such as a VAT ID can be frustrating if they are missing. Without these details, customers may question your legitimacy, especially if you sell goods or services online.

Your website should clearly display your company’s legal information and contact details, either in the footer or on a dedicated contact page. This transparency builds credibility and trust with visitors.​

Country-specific legal requirements

  • Greece: Legal entities must display their GEMI (EUID) on their website. This allows anyone to verify company ownership and VAT ID through the General Commercial Register.
  • German-speaking countries: By law, all commercial websites (including Facebook business pages) must include an Impressum: a statement of ownership and responsibility with contact details and VAT-ID.
  • United Kingdom: Under The Companies (Trading Disclosures) Regulations 2008, limited companies must show their registration location, registered number, and registered office address on their websites.​

What to do next

If your website is outdated and you’re not yet ready for a full redesign, reach out to whoever originally built your site (if still in business). Alternatively, consider hiring a web agency for remediation. While agencies do not offer legal advice, they can guide you toward the right resources (for example, by recommending that you consult a legal expert) and then make any necessary corrections to your website to ensure conformance.

Irene Koukia as a speaker at the BP19 conference

I've always been drawn to the moment when something clicks for a business, when the right words, the right positioning, the right presence online suddenly make everything make sense. Lavender Giraffe grew out of years in hospitality, coaching, translation, and marketing strategy, and a conviction that businesses deserve more than cookie-cutter solutions. I work in English, German, and Greek, and the cross-cultural side of my work is something I genuinely love. Athens is home, but my clients are spread across the EU and UK.

Found this useful?

Get more like it every first Monday of the month. The Lavender Giraffe Newsletter covers practical web design, SEO, and digital marketing tips for business owners and marketing managers.