GDPR in the online environment: compliance begins with the law, not with technology
If I had to choose one of the most dangerous illusions in the online environment, it would be the belief that GDPR is “resolved” once a cookie plugin is installed or a privacy policy copied from the internet. It is a comforting idea, yet entirely wrong. In reality, most breaches of Regulation (EU) 2016/679 do not stem from bad faith, but from the false impression that data protection is an exclusively technical problem that the website developer, the marketing agency or the platform provider can handle.
We live in a world where almost every online interaction produces personal data. A simple contact form, an order in an online shop, subscribing to a newsletter, logging into an application, using Google Analytics or integrating a chatbot all involve the collection and processing of information about individuals. In most cases we do not even realise the scale of these processing activities. IP addresses, cookie identifiers, order histories, user preferences, device location or email addresses are, in numerous situations, personal data and fall within the scope of GDPR protection.
Many entrepreneurs believe that using a well-known platform such as WordPress, WooCommerce, Shopify or Wix automatically shields them from any legal issue. This is the same reasoning as thinking that merely owning a type-approved motor vehicle means you no longer have to obey the rules of the road. The platform is only a tool. It provides functionalities, yet it does not decide what data you collect, for what purpose you use them, how long you keep them, to whom you disclose them or what the legal basis is for each processing operation. Those decisions belong exclusively to the data controller.
Hence two companies using the same platform may face entirely different legal situations. One may rigorously meet GDPR requirements while the other may breach the Regulation every day without realising it. The difference is not technology; it is how that technology is embedded in a correct legal framework.
In practice, the privacy policy displayed on a website is only the tip of the iceberg. Behind it there should be a thorough analysis of the categories of data collected, the purposes of processing, the applicable legal bases, retention periods, contractual relationships with processors, technical and organisational measures implemented, procedures for exercising data-subject rights, security-incident management and, where relevant, data-protection impact assessments. All of these are legal obligations, not mere recommendations.
Experience over recent years shows that most vulnerabilities arise precisely in the areas where companies invest most heavily: online marketing and process automation. Newsletters, remarketing campaigns, tracking pixels, subscription forms, CRM applications, email-marketing platforms and traffic-analytics tools daily transfer vast volumes of data to third parties. Very often the technical implementation is flawless, yet the legal implementation is incomplete. Correct notices are missing, consent is obtained formally or not at all, retention periods are undefined and contractual relationships with suppliers do not cover all obligations set out in the Regulation.
Here one of the most frequent misunderstandings appears: an attempt is made to solve a legal problem with an exclusively technical solution. Yet GDPR is neither a programming manual nor a guide to digital marketing. It is a European normative act that establishes fundamental rights of individuals and concrete obligations for data controllers. Compliance begins with interpreting the law and only then proceeds to the technical implementation of the necessary solutions.
For this reason the role of the legal counsel is far more important than it first appears. It is not enough to draft standard documents or answer ad-hoc questions. A legal counsel specialised in data protection and qualified as a Data Protection Officer (DPO) analyses the organisation’s processes before they generate risks. They identify data flows, establish legal bases, verify the legality of contractual relationships, assess risks and propose measures that reconcile legal requirements with the organisation’s operational realities.
The value of such an approach is rarely visible when everything is running normally. It becomes evident the moment a supervisory authority launches an investigation, a data subject makes a request, a security incident occurs or a data breach happens. At that point the difference between documents copied from the internet and a genuine compliance system can mean not only avoiding a fine but also protecting the organisation’s reputation.
Data protection has long since ceased to be a domain reserved for large corporations. Today any professional practice, commercial company, online shop, medical clinic, educational institution or non-profit organisation processes personal data and, to a greater or lesser extent, falls within the scope of GDPR. The more an activity takes place in the digital environment, the more complex the legal responsibilities become.
Ultimately, the most important lesson GDPR teaches us is a simple one: technology can collect, store and transmit data anywhere in the world, yet it cannot interpret the law. That remains the responsibility of people. And in a field where every decision has legal consequences, the person best placed to turn legal obligations into a genuine compliance system is the legal counsel who holds specialist data-protection expertise and the qualification of Data Protection Officer. In an increasingly digitalised economy, this professional is no longer merely a consultant called in to solve problems when they arise, but the professional who prevents them before they exist.