Compliance proof, not promises
GDPR isn’t optional, and it isn’t light reading. It tells you how to handle personal data, emails, IPs, payment details, everything, and the penalties for ignoring it are ugly.
We’ve made it practical. Instead of drowning in legal text, you get ready-to-use tools: clauses written by our lawyers, banners that respect the law and your users, and dashboards that keep your records organized. Less stress, more confidence.
Does GDPR apply to you?
GDPR is broader than most people think. If you handle personal data connected to the EU, you’re in scope.

1
You’re based in the EU. Every business inside the EU must comply.
2
You sell to EU/UK customers. Location doesn’t matter. Serving EU residents triggers GDPR.
3
You monitor users. Analytics, cookies, remarketing? All require compliance.
4
You collect data. Emails, delivery addresses, IPs, payment info… all count.
In worst-case scenarios, fines can hit €20M or 4% of global turnover.
What GDPR requires from every business, site, or app
The rules look endless, but they boil down to a few key areas:
Privacy & Cookie Policy
Websites and apps must publish clear, current policies. If you use cookies, you need a cookie policy too. These need to explain what data is collected, why, who it’s shared with, and user rights.
Cookie Banner & Consent
Non-essential cookies can’t load until a user says yes. Banners must also let users revisit and change their preferences at any time.
Consent Records
If users have to give consent for signups, newsletters, and registrations, you’ll need to log when, how, and under what notice consent was given.
Processing Records
Organizations need a central record of data processing activities: legal basis, retention rules, and security measures. Auditors ask, you show.
Your GDPR toolkit, all in one place
Every part of GDPR points back to the same things: policies, consent, and records you can prove. Our tools cover each of these areas, so you’re not left guessing what to set up next.
Privacy and Cookie Policy Generator
Privacy Controls and Cookie Solution
Consent Database
Data Subject Rights Management Tool
Register of Data Processing Activities
Privacy and Cookie Policy Generator
Clauses written by our lawyers, auto-updating policies that explain exactly how you collect, use, and share data.

Privacy Controls and Cookie Solution
GDPR-ready banners that block cookies until consent, manage preferences, and integrate with Google Consent Mode + IAB TCF.

Consent Database
Automatic logs of who consented, when, and to what. Built for audits, synced with your forms and marketing tools.

Data Subject Rights Management Tool
A guided channel for handling access, deletion, rectification, portability requests, and more. Everything in one dashboard.

Register of Data Processing Activities
A GDPR Article 30-ready register with legal bases, retention schedules, and third-party sharing details, ready for inspections.

Expert legal input, turned into practical tools
GDPR is complex, but you don’t need to be a lawyer to get it right.
Guided setup and auto-updating documents take care of the legal text.
Manage policies, banners, and consent across multiple sites and apps in one place.
Every clause is drafted and maintained by real lawyers, not AI guesswork.
We track GDPR, ePrivacy, and related laws, so your setup evolves automatically.
Your GDPR questions, answered
What counts as personal data?
Anything that can identify a person: names, emails, IP addresses, payment info. Even a single data point, combined with others, can qualify.
What’s a data breach?
Any unauthorized loss, access, or disclosure of personal data. If it happens, users must be notified, and regulators informed within 72 hours.
Do I need GDPR if I’m not in the EU?
Yes, if you serve EU/UK users. Location doesn’t exempt you. If you sell or track in the EU, GDPR applies.
Don’t wait for an audit to get ready
150,000+ businesses already use iubenda to simplify GDPR and protect their reputation. Join them today.