If you built your site on Squarespace and it gets visitors from the EU, GDPR applies to you — even if your business is based in the US, UK, Australia, or anywhere else. GDPR follows your visitors, not your headquarters.
Squarespace is one of the most popular site builders in the world, and like every platform it ships with defaults that are not compliant out of the box. This guide walks through exactly what to set up, in plain language — no lawyer required.
1. Does GDPR apply to your Squarespace site?
Yes, if any of these are true:
You sell products or services to customers in the EU or EEA
EU residents visit your site — even without buying anything
You use analytics, ad pixels, or email marketing tools (nearly every Squarespace site does)
You collect any personal data at all: contact forms, newsletter signups, bookings, memberships, comments
GDPR's territorial scope (Art. 3) covers any business processing EU residents' personal data, regardless of where the business is registered. A wedding photographer in California with a Squarespace booking form serving clients in Germany? GDPR applies.
The same logic holds under the UK GDPR if you serve UK customers.
2. Six compliance requirements for Squarespace sites
Here is what every Squarespace site needs for GDPR compliance in 2026. These are the most common gaps we see when scanning sites across platforms with our free compliance scanner.
Requirement
Why
Common gap
Cookie consent banner
ePrivacy Directive requires consent before non-essential cookies load
Squarespace's built-in banner is off by default — most owners never switch it on
Privacy policy
GDPR Art. 13: users must be told what data you collect and why
Left as the untouched default template, or missing entirely
Data Processing Agreement (DPA)
GDPR Art. 28: Squarespace processes data on your behalf; a DPA must cover it
Most owners don't know Squarespace's DPA exists or that it applies automatically
Legal basis per purpose
GDPR Art. 6: each data use needs consent, contract, or legitimate interest
"Legitimate interest" claimed for marketing cookies — invalid in most EU countries
Data subject rights process
Visitors can request access, deletion or export of their data
No idea how to actually fulfil such a request when one arrives
Squarespace includes a native cookie banner, but it is disabled by default. To turn it on:
Open Settings → Cookies & Visitor Data (older versions: Settings → Advanced → Cookie Banner)
Enable the cookie banner
Choose "Banner + restrict data collection" — this is the critical setting. It blocks analytics and marketing cookies until the visitor opts in.
Write a clear description linking to your cookie policy
The default setting isn't enough. If you choose plain "Banner" mode without restricting data collection, analytics cookies fire before consent — which breaches the ePrivacy Directive in most EU countries. German regulators in particular issue fines (Abmahnungen) for this.
Third-party scripts Squarespace won't block
The native banner does not reliably block scripts you added yourself:
Google Analytics / GA4 — added via Settings → Marketing, partially covered; custom code injections are not
Meta Pixel, TikTok Pixel — usually pasted into Code Injection, never blocked by the native banner
Live chat widgets (Intercom, Tidio) — load immediately, set cookies before consent
Embedded videos — YouTube/Vimeo embeds set cookies on page load unless you use no-cookie domains or a click-to-play facade
If you run any of these, you need a dedicated consent management platform (CMP) that blocks them until consent — or remove them. Our guides on Meta Pixel consent and Google Analytics consent cover the details.
4. Privacy policy requirements
Your privacy policy must state, in plain language:
Who you are — your business name and contact details (and EU representative if you're outside the EU)
What you collect — order data, form submissions, analytics data, IP addresses
Why — the legal basis for each purpose: contract fulfilment, consent, legitimate interest
Who receives it — Squarespace, payment processors (Stripe/PayPal), email tools, shipping partners
How long you keep it — actual retention periods
Their rights — access, correction, deletion, portability, objection, and how to exercise them
Transfers outside the EU — Squarespace stores data in the US; SCCs apply
Squarespace can generate a starter policy, but treat it as a skeleton: it will not know about your Meta Pixel, your newsletter tool, or your booking software. Every tool you connect is a disclosure you owe visitors.
Also link the policy visibly — from your footer and next to any form that collects personal data. A policy nobody can find doesn't satisfy Art. 13.
5. Data Processing Agreement (DPA)
Squarespace acts as a processor for the personal data on your site, so GDPR Art. 28 requires a DPA between you and them. Good news: Squarespace's DPA applies automatically under their Terms of Service — you don't need to sign anything separately. Read it once so you know what they commit to.
But the chain doesn't stop there. You also need processing terms with:
Your email marketing provider (Mailchimp, Klaviyo, Squarespace Email Campaigns)
Payment processors (Stripe, PayPal — mostly covered by their standard terms)
Any consultant or agency with access to your customer data
If you work with business clients who ask you for a DPA — for example as an agency or freelancer — you need your own template ready. Ours is included in the document pack.
6. Squarespace's built-in privacy features worth using
Cookie banner with restricted data collection — described above; the single highest-impact setting
Acuity Scheduling privacy settings — if you take bookings, configure retention limits
Data request handling — Squarespace support can help fulfil access/deletion requests for site visitor data; know the process before a request arrives
SSL everywhere — automatic on custom domains; verify yours actually serves HTTPS and redirects HTTP (our scanner checks this free)
What Squarespace deliberately does not give you is a full CMP for third-party scripts. If you inject custom pixels or chat widgets, blocking them is your job.
7. Common compliance mistakes on Squarespace
Cookie banner enabled in "banner-only" mode. Looks compliant, blocks nothing. Choose "restrict data collection".
Meta Pixel in Code Injection without consent gating. Fires on every visit, before any consent.
Newsletter double opt-in turned off. In several EU countries, confirmed opt-in is expected for marketing emails.
No imprint/legal notice. Required in Germany (Impressum) and several other member states even for foreign sellers — see our Impressum guide.
Default privacy policy never edited. It won't mention your actual tools, so it fails Art. 13 transparency.
Contact forms with no privacy-policy link beside them. A top enforcement target across the EU.
8. Free compliance check for your Squarespace site
You don't need to hire a consultant to find the obvious gaps. Our scanner checks HTTPS/HSTS security headers, cookie-consent platforms, Google Consent Mode v2, trackers loading without consent, privacy-policy links, legal pages, and more — on any platform including Squarespace.
Run it now, get a score in seconds, and see exactly which checks fail and how to fix them: