EU Website Compliance Guide 2026
A 24-page handbook for the person who owns the website, not the lawyer. One rule per chapter, what it asks of a site in practice, and a checklist at the end of each. Free as a PDF, and you do not have to leave an email to get it.
A4, about 45 KB. Written in August 2026 and reviewed when the rules change.
What is in it
- Why compliance mattersWhat has changed since 2018, what regulators actually fine, and why most findings are fixable in an afternoon.
- GDPR fundamentals for websitesLawful basis, the rights people have, and what a website owner is responsible for.
- Cookie consentWhat the ePrivacy Directive actually requires, what a banner must and must not do, and when you do not need one.
- Privacy policyThe Article 13 checklist: everything a policy has to say, in the order people look for it.
- Imprint and legal noticeWho must have an Impressum, what it contains, and how German warning letters work.
- Security headersHSTS, CSP, Referrer-Policy and friends, with copy-paste configuration for common servers.
- Third-party trackersGoogle Analytics, Meta Pixel and consent mode, and what "before consent" means technically.
- European Accessibility ActIn force since June 2025. Who it covers, what an accessibility statement is, and where to start.
- NIS2 and DORAWhy suppliers of regulated companies get questionnaires, and how to answer them without a consultant.
- Email: SPF, DKIM, DMARCThe three DNS records that decide whether your mail arrives and whether someone can forge it.
- Compliance by platformWordPress, Shopify, Webflow, Squarespace, Wix and custom stacks: where each setting lives.
- Monthly maintenance checklistWhat to look at once a month so the fixed things stay fixed.
- Tools and resourcesOfficial sources, open-source consent tools, and how to read a regulator's decision.
- Regulation overview tableOne page: regulation, who it applies to, what it demands of a website, penalty range.
Who it is written for
Small-business owners
You have a website, customers in the EU and no legal department.
Freelancers
You collect client data and want to be able to say "yes, I have that covered" and mean it.
Marketing and web managers
You run the company site and get the compliance questions nobody else answers.
Agencies
You need something to hand a client that explains why the invoice has a line called "consent banner".
What it is not
It is not legal advice, and it says so in every chapter where the honest answer is "ask a lawyer". It is the guide I wished I could send clients instead of explaining the same ten things by email. It does not replace a data protection officer, and it will not make a non-compliant business compliant by being read.
If you find a mistake, write to me through mahoje.dk and I will correct the next revision.
Questions
Why is it free?
Because the scanner sends people here when it flags something, and the explanation should not be behind a paywall. The planned paid products are the ongoing monitoring and the document templates, not the knowledge.
Can I share it with my team or clients?
Yes. Send the PDF or link to this page. Please do not sell it or strip the attribution.