Skip to content

GDPR v spletnem okolju: vodnik za podjetja 2026

12 min read

GDPR in the Online Environment: A Guide for Businesses 2026


TL;DR:

  • GDPR requires businesses to ensure the lawful, transparent, and secure processing of personal data on websites. Companies must establish a privacy policy, maintain records of processing activities, implement technical measures to protect data, and obtain appropriate consent for cookies. It is also important to monitor individuals' rights, such as the right to erasure, and appoint a clearly designated Data Protection Officer where required.

The General Data Protection Regulation (GDPR) is European legislation that sets the rules for the lawful, transparent, and secure processing of personal data in the online environment. Every time your website collects email addresses, tracks visitor behavior, or stores customer information, you are required to comply with these rules. In Slovenia, GDPR is implemented together with ZVOP-2, which regulates additional issues relating to data processing and protection at the national level. For entrepreneurs and managers of medium-sized companies, this means specific obligations at every digital touchpoint with customers, from web forms to analytics tools and email marketing.

What Is GDPR in the Online Environment and What Obligations Does It Impose on Businesses?

In online business operations, GDPR means that every company collecting or processing personal data online must have a clear legal basis for each individual processing activity. The three most common legal bases are: the individual's consent, performance of a contract, and the controller's legitimate interest. Each of these requires a different approach to documentation and informing users.

Obligations that GDPR imposes on online businesses include:

  • Privacy Policy: The document must clearly state the purpose of processing, the legal basis, retention period, any transfers of data to third countries, and the rights of individuals. A privacy policy is not merely a formal document; it must accurately reflect the company's actual practices.
  • Record of Processing Activities: Every company with more than 250 employees must maintain one. Smaller businesses are also required to do so when processing special categories of data or carrying out high-risk processing activities.
  • Technical and Organizational Measures (TOMs): These include data encryption, access controls, backups, and incident response procedures.
  • Data Processing Agreements: Any external provider that processes data on your behalf (e.g., email marketing providers or analytics service providers) must have a data processing agreement in place with your company.
  • Transparency Toward Users: Website visitors must be clearly informed about what data you collect, why you collect it, and how long you retain it.

Expert Tip: Before drafting a privacy policy, create an inventory of every point where your website collects data. This includes contact forms, newsletter subscriptions, analytics tools (e.g., Google Analytics), cookies, and any CRM integrations. Only then can you create a privacy policy that accurately reflects your actual practices.

A mismatch between what a privacy policy promises and what a company actually does is the most common finding of supervisory authorities during audits. This means that formal documentation without appropriate internal processes is not sufficient for compliance.

A professional carefully reviewing a website privacy policy on a computer.

How Does GDPR Regulate Cookies and Consent on Websites?

Cookie management is an area where GDPR and the ePrivacy Directive overlap and together impose strict requirements. GDPR governs the lawful processing of personal data, while the ePrivacy Directive specifically regulates access to users' devices and the storage of cookies. Together, they require that no tracking or marketing cookie may be activated before the user has given active consent.

Overview of the steps for managing cookie consent in compliance with GDPR.

Cookies are divided into strictly necessary cookies (technical cookies required for website functionality) and non-essential cookies (analytics, marketing, and third-party cookies). Consent is not required for strictly necessary cookies, but it is mandatory for all others. A cookie banner must provide a clear option for active consent and an equally visible option to refuse, without manipulative designs that steer users toward acceptance.

Common mistakes in consent management:

  • The “Reject All” button is hidden or visually less prominent than the “Accept All” button.
  • Cookies are loaded immediately when the page is visited, before the user clicks anything.
  • Consent is obtained for an entire category without allowing granular choices.
  • There is no mechanism for withdrawing consent that is as easy to use as granting it.

What Does the Right to Erasure Mean and How Can It Be Implemented?

The right to erasure, also known as the “right to be forgotten,” allows an individual to request the complete removal of their personal data from all of a company’s systems. The right to erasure requires a multi-layered technical implementation, as data must be deleted from all systems rather than merely being hidden or visually removed. This is one of the areas where companies most frequently make mistakes.

Practical steps for compliant implementation of the right to erasure:

  1. Inventory All Systems: Identify all databases, CRM systems, email platforms, backups, and archives where a customer’s personal data is stored.
  2. Establish a Procedure: Designate a responsible person, define a response deadline (30 days under GDPR), and provide a form or communication channel through which customers can submit requests.
  3. Perform Actual Deletion: Remove the data from all systems, including backups where technically feasible, as well as from the systems of data processors.
  4. Maintain Documentation: Record the date of the request, the date of deletion, the systems involved, and any exceptions (e.g., legal obligations to retain invoices).
  5. Notify the Individual: Confirm that the deletion has been carried out and explain any applicable exceptions.
Step Description Common Mistake
System Identification Inventory of all data storage locations Overlooked backups and archives
Deletion Execution Actual deletion from all systems Merely deactivating an account without deleting data
Documentation Record of requests and completed deletions Lack of an audit trail
Notification Written confirmation to the individual Failure to notify or providing incorrect information

The report from the joint European CEF 2025 action found that digital service providers often limit deletion to visible changes rather than actual deletion across all systems. This constitutes a direct GDPR violation and may result in fines.

When and How Should You Appoint a Data Protection Officer (DPO)?

A Data Protection Officer (DPO) is a role required by GDPR and ZVOP-2 for certain categories of organizations. Appointing a DPO is mandatory for public authorities, companies that systematically monitor individuals on a large scale, and organizations that process special categories of personal data (such as health data or biometric data). For medium-sized companies with intensive online operations, appointing a DPO is often advisable even when it is not strictly required.

The responsibilities of a DPO in online projects include:

  • Advisory and Oversight Role: The DPO advises the controller on compliance matters and monitors GDPR implementation in day-to-day processes.
  • Point of Contact for Supervisory Authorities: The DPO serves as the contact person for the Information Commissioner and must be officially registered with the authority.
  • Risk Assessment: When introducing new online solutions or processing activities, the DPO conducts a Data Protection Impact Assessment (DPIA) where high risks are involved.
  • Training: The DPO is responsible for ensuring regular training of employees who process personal data.

ZVOP-2 and GDPR together define the criteria for appointing a DPO and the scope of the role’s responsibilities, including online services. A DPO may be either an employee of the company or an external specialist, which is often a more economical solution for small and medium-sized businesses. The key requirement is that the DPO operates independently and has direct access to senior management.

Best Practices and Common Mistakes When Implementing GDPR in Online Business

Companies that approach GDPR comprehensively achieve long-term compliance. Those that limit their efforts to drafting documents without changing their processes tend to encounter recurring compliance issues. The data lifecycle, from collection and processing to deletion, must be consistent with GDPR requirements and reflected across all online systems within the company. This is a principle that many organizations underestimate.

Common implementation mistakes:

  • The privacy policy is copied from another company and does not reflect actual practices.
  • Employees who process customer data have not received GDPR training.
  • No procedure exists for responding to data security breaches (including the mandatory notification to the Information Commissioner within 72 hours).
  • Data processing agreements with processors (e.g., cloud service providers) are missing or outdated.
  • The legal bases for processing differ across forms, CRM systems, analytics tools, and marketing platforms without overall alignment.
Best Practice Common Mistake
Regular privacy policy reviews One-time creation without updates
Maintaining records of processing activities Lack of documentation
Employee training Only management understands GDPR
Contracts with all processors Missing or outdated agreements
Data breach response procedure No defined response process

Expert Tip: Conduct an internal GDPR compliance audit at least once a year. Verify that policies are up to date, all processors are covered by contracts, and employees know how to handle requests from individuals. Tools such as OneTrust, Osano, or DataGrail can automate consent tracking and rights request management.

For a secure online infrastructure, it is essential that technical measures such as HTTPS, encryption, and access controls are not treated separately from GDPR requirements but as part of a unified security framework.

Key Takeaways

GDPR in the online environment requires a comprehensive system that combines legal documentation, technical safeguards, trained employees, and clear procedures for exercising individuals’ rights.

Point Details
A legal basis is mandatory Every data processing activity must have a clear and documented legal basis.
The cookie banner must be compliant Consent must be active, granular, and equally easy to withdraw.
The right to erasure requires actual deletion Data must be removed from all systems, not merely deactivated or hidden.
The DPO is a key partner For medium-sized businesses, an external DPO is often the most efficient solution.
Compliance is a process, not a document Regular training, audits, and updates are essential for long-term compliance.

GDPR and the Future of Online Business: My Experience

When working with medium-sized companies on GDPR implementation, I consistently observe the same pattern: most organizations approach the project believing it is primarily about drafting documents. The privacy policy is written, a cookie banner is added, and management assumes everything is in order. The reality is different. During audits, supervisory authorities are not looking for well-written documents; they are looking for evidence that the company actually operates in accordance with what those documents state.

I am particularly concerned about the growing use of artificial intelligence and automated decision-making. Companies are increasingly deploying AI tools for customer analysis, personalization, and automated responses without verifying whether these processing activities have an appropriate legal basis or whether proper risk assessments have been conducted. GDPR contains clear rules in this area, yet many organizations overlook them.

My recommendation for 2026 is simple: treat GDPR as part of your business culture, not as a regulatory burden. Companies that understand this build customer trust and avoid fines that can reach up to 4% of annual global turnover within the EU. Legislative developments arising from the AI Act and the revision of the ePrivacy Regulation will require even greater adaptability. Start your compliance review today—not when an inspector arrives.

— Ziga

How Moxy-web Helps You Achieve GDPR Compliance

Moxy-web treats GDPR compliance as an integral part of every web development project, not as an afterthought. When creating your website or application, we ensure the proper implementation of a cookie banner, prepare a privacy policy that accurately reflects your company's actual practices, and implement technical safeguards that protect your customers' data. Our solutions are tailored to the needs of medium-sized businesses that require practical support without unnecessary complexity. If you want your online operations to comply with GDPR and ZVOP-2, contact us through Moxy-web, and together we will find the right solution for your business.

FAQ

What Is GDPR and Why Does It Apply to Websites?

GDPR is a European regulation governing the protection of personal data and applies to any company that collects or processes the personal data of individuals in the EU, regardless of where the company is registered. Any website that collects email addresses, logs IP addresses, or uses tracking cookies is required to comply with GDPR.

When Do I Need Consent for Cookies?

Consent is required for all cookies that are not strictly necessary for the technical operation of a website, including analytics cookies, marketing cookies, and third-party cookies. Consent must be actively given before these cookies are loaded.

What Happens If a Company Violates GDPR?

The Information Commissioner may impose a fine of up to €20 million or up to 4% of the company’s annual global turnover, whichever amount is higher. In addition to financial penalties, temporary restrictions or prohibitions on data processing may also be imposed.

Do I Need to Appoint a DPO?

Appointing a Data Protection Officer is mandatory for public authorities, organizations that systematically monitor individuals on a large scale, and companies that process special categories of personal data. For other businesses, appointing a DPO is recommended but not legally required.

How Long Must I Retain Personal Data?

A retention period must be defined for each category of personal data and specified in the privacy policy. Data may only be retained for as long as necessary to fulfill the purpose for which it was collected or for as long as required by law (for example, accounting records may need to be retained for 10 years).

Recommended Reading

Read next

Got a project, or just a question?

Write us a few sentences about your business and what you would like to change. It doesn't have to be precise or fully thought through.