STUDIO 1
legal

GDPR and cookies for Estonian websites: a simple guide

E
Eduard Ignatjev · Founder of STUDIO 1
·updated ·7 min read

GDPR sounds intimidating, but for a small business website the practical requirements are limited and manageable. Here is what your Estonian site actually needs, without the legal jargon.

Share:
02

The easy path: cookieless analytics

The simplest way to reduce GDPR friction is to use analytics that does not set cookies, such as Plausible.

Cookieless analytics needs no consent banner for itself and still gives you the numbers that matter: visitors, sources, popular pages. Many small sites do not need anything heavier than this.

03

A real privacy policy

Your site needs a privacy policy that reflects what it actually does: what data you collect, why, how long you keep it, and how someone can request deletion.

A copied template that does not match your site is worse than useless. If you collect form submissions, say so. If you use analytics, name it. Honesty is the standard.

05

Who supervises an Estonian company's website

For a company registered in Estonia the data protection supervisor is the Estonian Data Protection Inspectorate, in Estonian Andmekaitse Inspektsioon. It publishes guidance, handles complaints from individuals and is the body a visitor would turn to if they felt your site misused their data.

This matters to e-residents in a practical way. You may live in Brazil or Turkey, but if the OÜ is the one collecting form submissions and orders, the OÜ is the data controller and EU rules apply to it. Your privacy policy should therefore name the Estonian company, not you personally and not a brand name.

If the business is really managed from another EU country, or has staff and offices in several, which authority takes the lead can be less obvious. That is a question for a lawyer, not for a website template.

06

What the privacy notice of an OÜ should identify

The general content of a privacy policy is the same everywhere. The details that make it yours are local.

  • The controller: full company name with OÜ, registry code and registered address.
  • A contact for privacy requests: an email address that someone actually reads.
  • Recipients typical for an Estonian site: the payment provider (Montonio, Maksekeskus, Stripe), the carrier whose parcel locker the buyer picks (Omniva, SmartPosti, DPD), your hosting company, your email service and your accounting software.
  • The right to complain to the supervisory authority, with the Inspectorate named.

Buyers hand a phone number to a carrier every time they choose a locker, because the pickup code arrives by text message. Say so in plain words. It is the kind of detail copied templates never contain.

07

Worked example: one banner, three languages

Picture a hypothetical Tallinn bike repair shop with a site in Estonian, Russian and English, Google Analytics, and an embedded map.

The banner and the privacy policy need to exist in all three languages, because consent only means something if the visitor understood the question. A banner that stays in English on the Estonian page is a common and avoidable flaw.

The choice should be stored once and respected across language versions, so a visitor who declined on the Estonian page is not asked again on the Russian one. And the embedded map deserves attention: it can set cookies of its own, so either load it after consent or replace it with a static picture that links to the map.

FAQ

Do I need a cookie banner if I have no analytics?+

If your site sets no tracking cookies at all, you may not need a consent banner. But the moment you add analytics or ads that track, you do.

Is Google Analytics allowed under GDPR?+

It can be used with proper consent and configuration, but it adds complexity. Cookieless analytics like Plausible is the simpler compliant choice for most small sites.

Can I be fined for a small business site?+

Enforcement focuses on real violations and complaints, not tiny sites by default. Still, a proper banner and honest privacy policy are simple to do and remove the risk.

I am an e-resident living outside the EU. Does GDPR still apply to my site?+

If the site belongs to your Estonian company, typically yes, because the company is established in the EU. Where you personally live does not change that. For unusual structures, for example several companies or customers only outside the EU, have a lawyer confirm.

In which language should the privacy policy be?+

In every language the site itself is offered in. If you sell in Estonian, Russian and English, a visitor should be able to read the policy and the cookie choices in the same language they are browsing in.

Share:

Related articles

Let's talk about your project

Send a short brief, we'll get back within one business day with a free quote.