Preskoči na sadržaj
BeoHosting
BeoHosting

8 min

GDPR for Websites in the US

Privacy policy, cookie banner, and compliance.

BeoHosting Tim

10+ godina iskustva — Stručnjaci za web hosting i infrastrukturu

Poslednje ažurirano:

GDPR (General Data Protection Regulation) applies to any website that processes personal data of EU citizens — and US privacy laws like California's CCPA/CPRA impose closely related obligations. If your site has a contact form, newsletter signup, or webshop, privacy compliance is essential. This guide covers everything you need: privacy policy, cookie banner, SSL, consent management, and avoiding CCPA penalties of up to $7,500 per intentional violation.

GDPR for Websites in the US

1

Create a privacy policy

A privacy policy is mandatory and must clearly state: who processes the data, what data is collected and why, legal basis, retention period, who the data is shared with, user rights and contact info. Use generators like PrivacyPolicies.com as a starting point and adapt to your site.

2

Add a cookie banner

If you use Google Analytics, Facebook Pixel, YouTube embeds or any marketing/analytics tool, a cookie banner with granular consent options is mandatory. WordPress plugins: Cookie Notice, CookieYes, Complianz. Banner must show before any non-essential cookie is set.

3

Install an SSL certificate

GDPR requires "appropriate technical measures" to protect personal data. SSL/HTTPS is a baseline. BeoHosting includes free Let's Encrypt SSL on every package — enable AutoSSL in cPanel and force HTTPS via .htaccess.

4

Add consent checkboxes to forms

Every form that collects personal data (contact, newsletter, registration) must have an explicit opt-in checkbox (not pre-ticked) with a clear link to the privacy policy. Save the consent timestamp with each submission for audit purposes.

5

Define data retention and user rights

Store personal data only as long as necessary. Document retention periods. Implement user rights: access, rectification, erasure, portability and objection. Provide a clear contact channel for data subject requests (e.g. privacy@yourcompany.com).

6

Sign a Data Processing Agreement (DPA)

You must have a DPA with every processor that handles personal data on your behalf — hosting provider, email provider, analytics, CRM, payment gateway. BeoHosting offers a DPA on request.

Spremni da pokrenete svoj sajt?

SSL zaštita
Brzina
24/7 podrška

Pridružite se 4.000+ zadovoljnih korisnika. Besplatna migracija i 15 dana garancije povrata novca.

15 dana garancija povrata novca
Besplatna migracija15 dana garancija24/7 podrška

FAQ

Odgovori na najčešća pitanja o našim uslugama.

GDPR applies directly if your site processes data of EU citizens (visitors or customers from the EU). In the US, the CCPA/CPRA in California and similar laws in states like Virginia, Colorado and Connecticut create comparable obligations. In practice, most US sites that sell or collect data nationwide should follow both CCPA-style rules and GDPR where EU visitors are involved.

Under the CCPA/CPRA, civil penalties reach up to $2,500 per unintentional violation and $7,500 per intentional violation, plus statutory damages in data-breach lawsuits. GDPR fines can reach 20 million EUR or 4% of annual turnover (whichever is higher) for EU customers. Beyond fines, non-compliance damages reputation and user trust.

Strictly speaking, if you use only essential cookies (session, login, cart), you do not need a consent banner. However, if you use Google Analytics, Facebook Pixel, YouTube embeds or any marketing/analytics tool, you are required to have a cookie banner with granular consent options.

You can use free generators (e.g. PrivacyPolicies.com, Termly.io) as a starting point, but adapt it to your site. The policy must be in plain language and include: who processes the data, what data is collected and why, legal basis, retention period, sharing, user rights and contact. For complex cases, consult an IT lawyer.

BeoHosting provides the technical infrastructure for compliance: free SSL for data encryption, servers with security measures (firewall, DDoS protection, backup), and the ability to install cookie consent plugins for WordPress. BeoHosting also stores data securely and provides a Data Processing Agreement (DPA) on request.

Naše garancije za vaš mir

Zaštićeni ste sa svake strane

15 dana garancije

Vraćamo novac bez pitanja u prvih 15 dana.

Besplatna migracija

Mi prebacimo vaš sajt bez prekida — vi ništa ne radite.

24/7 podrška

Naši stručnjaci su tu 24/7 kroz tikete i live chat.