GDPR
Does a small Irish business website need a privacy notice?
We fetched 82 Irish business websites in one week. Thirty-four had no privacy notice at any of the usual addresses, and three had one that nothing on the site linked to.
By Oscar CobbeCurrent as at 9 minute read3 sources
The short answer, and a number
If your website has a contact form, a booking page, a newsletter sign-up, or analytics that sets a cookie, you are processing personal data and you owe the people involved information about it. That obligation is Article 13 of the GDPR, and it is not conditional on your size, your turnover or whether anybody has ever complained.
It is also very commonly missed. In August 2026 we fetched the public websites of 82 Irish businesses across two sectors, accountancy practices and artisan food producers, as part of ordinary research. Every check was a plain GET of a public page, the same request a browser makes when anybody visits.
Thirty-four had no privacy notice at the homepage or at any of /privacy, /privacy-policy, /privacy-notice, /gdpr, /data-protection or /privacy-statement. Three more did have one, at /privacy or /privacy-policy, with nothing on the site linking to it.
Those last three are the interesting case, and we will come back to it, because a notice nobody can reach is not the same as no notice and is not a defence either.
The test in one sentence
If a person can type anything into your website, or if your website watches what they do, you owe them a notice. Almost every business website meets one of those two.
What Article 13 requires you to say
Article 13 applies where you collect personal data from the person themselves, which is what a contact form is. It lists what you must tell them, and the list is shorter than most templates suggest.
Who you are and how to contact you. Why you are processing the data and the lawful basis for it. Who else receives it. Whether it goes outside the EU. How long you keep it. Their rights, which are access, rectification, erasure, restriction, objection and portability. And the right to complain to the Data Protection Commission.
Two more apply only in certain cases: the contact details of a Data Protection Officer if you have one, and an explanation of your legitimate interests if that is the basis you are relying on. Most small businesses have no DPO and do not need one, and saying so plainly is better than inventing a role.
The Data Protection Commission's own guidance sets out the same list. It is worth reading their version rather than a template, because a template written for a US company will tell you about laws that do not apply to you and omit the regulator you actually answer to.
- 1Who you are, and how to reach you
- 2Why you are processing the data, and on what lawful basis
- 3Who else gets it, including processors
- 4Whether it leaves the EU
- 5How long you keep it
- 6The rights they have, and the right to complain to the DPC
When it has to be given, which is the part people miss
Article 13(1) says the information must be provided at the time the data is obtained. Not afterwards, not on request, not in a confirmation email. At the time.
In practice that means the notice has to be reachable from the form, not merely present somewhere on the site. A link beside the submit button is the ordinary way of doing it, and it is also the thing the three businesses above were missing: their notice existed and the person filling in the form had no way of knowing.
Article 14 covers the other case, where you have somebody's data and did not get it from them. The timing there is different and more generous, and it is set out in Article 14(3): within a reasonable period and at the latest within one month; or, if you are going to use the data to contact the person, at the latest at the time of the first communication; or, if you are going to disclose it to somebody else, at the latest when you first disclose it.
That middle limb is the one that catches anybody doing outreach, including us. If you build a prospect list from public sources and then email somebody on it, the first email is the deadline. Not the second, not the follow-up.
| Where the data came from | Which article | When you must tell them |
|---|---|---|
| They typed it into your form | Article 13(1) | At the time you collect it |
| You found it somewhere else | Article 14(3)(a) | Within a reasonable period, at the latest one month |
| You found it and are emailing them | Article 14(3)(b) | At the latest, in that first email |
| You found it and are passing it on | Article 14(3)(c) | At the latest, when you first disclose it |
The one that catches sales lists
Article 14(3)(b) means the first email is the deadline, and the notice has to be in it. A list built from public sources is lawful in principle; emailing it without telling anybody where you got their details is not.
Cookies are a separate law, and a separate consent
A privacy notice does not cover cookies. In Ireland the rule for storing or reading anything on somebody's device comes from the ePrivacy Regulations, S.I. No. 336 of 2011, and it requires consent before the cookie is set, not a notice afterwards.
The practical consequence is the one most small sites get wrong: Google Analytics cannot run until the visitor has agreed to it. A banner that says "by continuing you accept cookies" is not consent, and neither is one where the analytics has already loaded behind it.
This is genuinely fixable in an afternoon and it is worth doing properly, because a consent banner that does nothing is worse than none: it demonstrates that you knew and did it anyway.
If you hold health data, the stakes are different
Article 9 treats data concerning health as a special category, along with racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, sex life and sexual orientation. Processing it is prohibited unless one of the conditions in Article 9(2) applies.
A physiotherapy clinic taking a booking is processing health data the moment the form asks what is wrong. So is an eldercare service, a counselling practice, a dentist and a chiropractor. For those businesses the notice is not housekeeping: it is the document that explains a category of processing the Regulation starts by prohibiting.
Across the two sectors we checked, nineteen sites had a form on the page collecting details with no notice attached to it. That is the combination that turns a housekeeping problem into an Article 13 one: the moment somebody types into it, the information was owed and was not given.
What you do not need
You almost certainly do not need a Data Protection Officer. Article 37 requires one only where you are a public authority, where your core activities involve regular and systematic monitoring of people on a large scale, or where they involve large-scale processing of special category data. A clinic with one location is not doing anything on a large scale, and appointing a DPO you do not need creates an obligation you then have to meet.
You do not need to register with the Data Protection Commission. Notification was abolished when the GDPR replaced the 1988 and 2003 Acts, and any service charging you to register you is selling you nothing.
You do not need a cookie banner if you set no cookies. A static site with no analytics and no embedded video needs no banner, and adding one because everybody else has one trains visitors to click through a control that should mean something.
And you do not need six pages. A notice a person can read is worth more than a notice a lawyer can defend, and Article 12(1) actually requires it to be concise, transparent, intelligible and in clear and plain language.
Registration was abolished
There is no register to join and no fee to pay. If something arrives asking you to renew your data protection registration, it is not from the DPC.
What good looks like
One page, at a stable address, linked from the footer of every page and from beside every form that collects anything. Written in the second person. Naming the actual systems the data goes into rather than saying "our service providers", because that is the sentence a person is entitled to and the one that is hardest to write without doing the work first.
Dated, and with the date meaning something: a notice that says "last updated" and has not changed since the site added a booking system is a notice that is now wrong.
And accurate about retention. "We keep your data as long as necessary" is not a period. "Enquiries are deleted after six months unless you become a client" is.
If it is useful to see one that follows its own advice, ours is published alongside the retention schedule behind it, which names every category of record, the period, the trigger that starts the clock and the statute. The schedule is the document that makes the notice true, and publishing it is the only way to prove the notice was written from something rather than from a template.
Sources
- 1.Transparency obligations · Data Protection Commission
- 2.Regulation (EU) 2016/679, the GDPR: articles 9, 13, 14 and 37 · Official Journal of the European Union
- 3.S.I. No. 336/2011, European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 · Irish Statute Book, Office of the Attorney General
Free, and the answers stay in your browser
Check whether a DPIA sits behind your notice
A privacy notice describes processing that sometimes needed an assessment before it started. The free check says whether yours is one of those.
Run the free checkA notice that says what actually happens
We map where the data in your business actually goes, then write the notice from that rather than from a template. It comes with the Article 30 record behind it, which is the document that makes the notice true.
Talk to us about complianceWho wrote this
Oscar Cobbe · Founder, FourWinds Digital
Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.
More about how we work →Read next
GDPR
Cookie banners in Ireland, and what the DPC actually said
Scrolling is not consent, pre-ticked boxes are not consent, and the six month rule everybody quotes is softer than they think.
GDPR
Sending personal data to the US from Ireland, in 2026
Yes, and with conditions. The Framework holds, the checks are specific, and the part people skip is whether the particular company is actually on the list for the particular data.
GDPR
Do you need a DPIA? Ireland has its own list, and it is specific
Most guidance answers this with European criteria. Ireland has a published list of its own, and it is the one that decides the question here.
Written on 27 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.