GDPR Compliance for Freelancers: The Plain-Language Guide
Practical guide · EU GDPR · applies whether you're based in Italy, elsewhere in the EU, or outside the EU and serving EU customers
Most GDPR explainers are written for corporate legal teams. If you're a freelancer,
sole trader, or micro-business (regime forfettario, ditta individuale, or a small SRL)
who runs a website, sells online, or emails clients, you don't need a €500/year
retainer to be compliant — you need to understand a handful of concepts and act on
them once. This guide covers what actually matters, without the legalese.
What GDPR actually is, in one paragraph
The General Data Protection Regulation (GDPR) is an EU law governing how you
collect, store, use, and share personal data — any information about an
identifiable living person (names, emails, IP addresses, purchase histories, even a
photo). It applies to you if you're established in the EU and process anyone's
personal data, even just an email address in a contact form. It doesn't matter if
you're a solo freelancer with one client or a growing shop — the law scales with your
risk, not your size.
The seven core principles (Art. 5)
Lawfulness, fairness, transparency — have a legal reason to process
data, and be upfront about it.
Purpose limitation — collect data for specific reasons; don't repurpose
it later without telling people.
Data minimisation — only collect what you actually need. Don't ask for a
phone number "just in case" if you never call anyone.
Accuracy — keep data correct and up to date; let people fix errors.
Storage limitation — don't keep data forever "just in case"; delete or
anonymise it once you no longer need it (subject to legal retention rules like
invoices).
Integrity and confidentiality — protect data with reasonable security.
Accountability — you must be able to demonstrate compliance, not
just claim it. This is why documentation (a ROPA, your policies) matters even if no
one ever asks to see it.
The six legal bases (Art. 6) — you need one for every processing activity
Your interest, balanced against the person's rights
Basic site security logs, replying to an enquiry someone sent you
The most common freelancer mistake: using "consent" for everything —
including things that don't need it, like replying to a contact form, which just
creates unnecessary paperwork — or using no legal basis at all for marketing
emails, which is the one place you almost always need explicit, unbundled consent.
Data subject rights — what people can ask you for
Anyone whose data you hold can ask to: access it, correct it, delete it, restrict
its use, get a portable copy, object to certain processing, or withdraw consent. You
generally have one month to respond (extendable to three for complex
requests). Keeping an up-to-date Record of Processing Activities (ROPA) is the
fastest way to answer "what do we hold on this person and where" when a request
comes in — see our ROPA basics guide.
Do you need a DPO (Data Protection Officer)?
Almost certainly not, if you're a typical freelancer or micro-business. A
DPO is mandatory only if your core activity involves large-scale systematic
monitoring (e.g. you run an ad-tech/tracking business) or large-scale processing of
special-category data (health, biometric, etc. — e.g. you run a clinic's records
system). Selling templates, running a shop, or freelancing as a designer or
consultant does not trigger this.
Cookies and ePrivacy — a separate law, often confused with GDPR
GDPR governs personal data generally; the ePrivacy Directive specifically
governs cookies and similar tracking technologies, and requires prior consent for
anything beyond strictly-necessary cookies. See our
cookie consent banner guide for
the practical checklist: no pre-ticked boxes, an equal-prominence "reject all", and
logged consent.
Eight common mistakes (fix these first)
No privacy policy at all, or one copy-pasted from a different type of business
with irrelevant clauses. See our
privacy policy checklist.
Pre-ticked marketing consent checkboxes — illegal; must default to unticked.
Bundling marketing consent with Terms & Conditions acceptance — these must
be separate, specific opt-ins. See our
consent clauses guide for the exact
wording to use instead.
No cookie banner, or a banner where "reject" is harder to find than "accept".
Using a US-based tool (email, analytics, forms) without checking its data
transfer safeguards — look for Standard Contractual Clauses or an adequacy
decision in the tool's own privacy/DPA page.
Keeping data forever "just in case" — define retention periods and actually
delete data when they expire.
No internal breach log — even if you've never had a breach, Art. 33(5)
requires being ready to log one. See our
72-hour breach guide.
Treating a supplier DPA as optional paperwork — if a supplier processes
personal data for you (hosting, email, analytics), you need a signed DPA with
them. See our DPA guide.
Day-one checklist
Publish a Privacy Policy on your site, linked from every page footer.
Publish a Cookie Policy and implement a compliant consent banner if you use any
non-essential cookies.
Add the relevant consent clauses next to every form that collects data
(contact, newsletter, checkout) — short, drop-in "informativa breve" notices, not
the full policy repeated everywhere. See our
consent clauses guide for
ready-to-adapt wording for each form type.
Check every third-party tool you use (hosting, email, payments, analytics) — do
you have, or need, a DPA with them?
Fill in a mini ROPA — one row per data-collecting activity you actually run.
Keep a breach checklist somewhere you can find it even if your main systems are
down (printed, or in a separate cloud account).
Set a calendar reminder to review all of the above every 6–12 months, or
whenever you add a new tool, supplier, or data collection point.
Where to go for official guidance (free, authoritative)
Full regulation text: EUR-Lex, Regulation (EU) 2016/679
Don't want to draft all of this from scratch?
NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this
situation: a ready-to-edit Privacy Policy, Cookie Policy, consent clauses, a full
Art. 28 DPA, a mini Records-of-Processing (ROPA) template, and a breach-notification
checklist — €29 one-time, instant download, editable .docx and .pdf.
Not legal advice. This guide is general information,
not a substitute for advice from a qualified lawyer or data protection professional
about your specific situation. NormaKit's templates are likewise informational
starting points, not legal advice, and should be reviewed and adapted before use.