Why does the GDPR apply to a law firm's website?
Plenty of lawyers still treat GDPR compliance as a subject that concerns their clients, the companies they advise on compliance, rather than their own firm. That is a frequent mistake, and a potentially costly one. As soon as a website collects personal data, and every site with a contact form, an analytics tool or a cookie system does, its publisher is subject to the obligations of the General Data Protection Regulation.
For a law firm, the sensitivity of that question is twofold. On one side, the legal obligation: the GDPR, applicable since May 2018 across the European Union, imposes precise requirements on transparency, consent and data security. The regulator has powers of inspection and sanction that apply to any entity handling the data of European residents, whatever its size. On the other side, the credibility stake: a law firm that advises its clients on GDPR compliance while not being compliant itself sends a contradictory signal particularly damaging to its professional image.
The data collected on a law firm's site also carries a high level of sensitivity. A private individual filling in a contact form to set out their divorce, dismissal or tax dispute is transmitting personal information that is often sensitive. The firm's responsibility in protecting that data begins with the first click on "send".
What are the essential GDPR obligations for a lawyer's website?
Are the legal notices different from the privacy policy?
Yes, and confusing the two is one of the most frequent mistakes. Legal notices are an obligation arising from the 2004 law on confidence in the digital economy; they identify the publisher of the site and the host, and let any visitor know who they are dealing with. They are compulsory for any professional site, independently of the GDPR.
The privacy policy is a specifically GDPR obligation. It sets out how the site collects, uses, keeps and protects its visitors' personal data. Those two documents have to be distinct, reachable from every page of the site (generally from the footer), and written in clear, understandable language, not in legal jargon the average visitor cannot follow.
For a law firm, the legal notices have to state at minimum: the name or the corporate name of the firm, the professional address, the telephone number, the email address, the bar registration number, and the name and contact details of the site's host. The privacy policy has to answer every question a visitor might have about the use of their data.
What has to be in a law firm's privacy policy?
A lawyer's privacy policy has to answer seven fundamental questions imposed by article 13 of the GDPR. Who is responsible for processing the data? Which data is collected and by what means? For what purpose is that data used? On which legal basis does each processing rest? How long is the data kept? Who can access it? What are the rights of the person concerned and how do they exercise them?
For a law firm, the legal bases most commonly relied on are legitimate interest (for tracking browsing statistics, for instance) and consent (for sending newsletters or using non-essential cookies). The basis of performing a contract can apply to data collected within an established client relationship. Legal obligation can be relied on for certain retention duties specific to the profession.
The privacy policy also has to mention the right to complain to the regulator, and state whether data may be transferred outside the European Union, which is the case if you use services such as Google Analytics, Mailchimp or certain American hosts.
The complete GDPR checklist for a lawyer's website
Does your site meet the obligations of information and transparency?
Transparency is the first pillar of the GDPR. A visitor arriving on your site has to be able to understand easily, with no effort of research, how their data is handled. Here are the points to check.
The legal notices are present, complete and reachable from the footer of every page of the site. They state the publisher's name, full contact details, bar of registration and the host's information.
The privacy policy is distinct from the legal notices, reachable from every page, written in clear language, and covers every data processing carried out through the site: contact form, visit statistics, cookies, any newsletter.
The purposes of each processing are explicitly stated: what the data collected through the contact form is for, how long it is kept, who has access to it.
The rights of the people concerned (access, rectification, erasure, portability, objection, restriction) are clearly stated, with the concrete means of exercising them: a dedicated email address or a specific form.
A data protection officer or GDPR lead is named where applicable; for firms whose processing passes the thresholds or presents high risks, naming a data protection officer can be compulsory.
Does your site's cookie handling comply with the regulator's recommendations?
Cookie handling is the most visible compliance point and the most often badly handled. The regulator's recommendations, clarified in its 2020 guidelines and their 2022 update, require prior, informed consent before any cookie not strictly necessary to the working of the site is placed.
An information banner at the bottom of the page, with no clearly visible "reject" button, is not compliant. Refusing has to be as simple as accepting: a "reject" button has to be reachable in one click, at the same level of visibility as the "accept" button. The regulator has issued several significant sanctions against organisations that did not respect that symmetry, and the checks have been extended to the self-employed professions.
Strictly necessary cookies, the ones that allow navigation on the site, remember a basket (on an e-commerce site) or hold a login session, do not require consent. But analytics cookies (Google Analytics, Matomo not configured in exempt mode), social media cookies (share buttons) and advertising cookies require explicit, prior consent.
The consent given (or refused) cannot be kept for more than thirteen months. At the end of that period, consent has to be renewed. That information has to appear in your cookie policy.
To check which cookies your site places, use the regulator's diagnostic tool (available on its site) or a tool such as Cookiebot in analysis mode. You will often be surprised by the number of cookies placed by plugins, widgets or third-party integrations you had forgotten.
Does your site's contact form comply with the GDPR?
The contact form is often the most sensitive point of data collection on a lawyer's site. It is where visitors first set out their situation, and the nature of the information shared can be particularly personal.
Several compliance points have to be checked on every form. An information notice has to appear directly under the form (or through a clearly labelled link to the privacy policy), explaining why that data is collected, by whom, for how long and on which legal basis.
Only the fields strictly necessary to the purpose of the form should be required. Asking for a date of birth, a social security number or health information on a general contact form breaches the principle of data minimisation.
If the form includes a tick box for newsletter sign-up or to allow commercial use of the data, that box must never be pre-ticked; consent has to be a positive, deliberate act.
The data submitted through the form has to be transmitted securely (your site has to be on HTTPS, which you can check from the padlock in the browser address bar) and stored in a secure environment: your email tool, your CRM or your contact management platform.
What are the retention rules for the data collected through your site?
The principle of storage limitation is one of the pillars of the GDPR: data can only be kept for as long as necessary for the purpose it was collected for. After that, it has to be deleted or anonymised.
For a law firm, the recommended retention periods vary with the nature of the data. A prospect's data (a contact form that did not lead to a client relationship): three years from the last contact, in line with the regulator's recommendations for managing commercial relationships. A client's data within a contractual relationship: five years after the end of the relationship, in line with the general limitation period. Browsing data collected through analytics cookies: thirteen months at most.
Those periods have to be set down in your record of processing activities, an internal document every entity carrying out personal data processing has to keep up to date. That record does not have to be published, but it has to be available in the event of an inspection.
Is your site technically secure under the GDPR?
Technical data security is a GDPR obligation (article 32), and it starts with the fundamentals. An HTTPS certificate is the minimum requirement; any site on plain HTTP offers no encryption of the data travelling between the visitor's browser and the server. If your site is still on HTTP, that is both a GDPR non-compliance and a negative signal for search (Google has penalised unsecured sites since 2018).
Beyond HTTPS, several technical measures fall to the firm: choosing a host that offers regular automatic backups, updating the site's CMS (WordPress, Webflow and so on) and its plugins regularly to close known security holes, using robust administrator passwords and two-factor authentication for back-office access, and making sure the forms are protected against injection or cross-site request forgery attacks.
What are the most frequent GDPR mistakes on lawyers' websites?
Recap: the most common failings
| Failing | Risk | Priority fix |
|---|---|---|
| No privacy policy, or a generic one | A regulator's sanction, loss of trust | Write a policy specific to the firm |
| A cookie banner with no visible "reject" button | Established non-compliance | Deploy a compliant consent platform (Axeptio, Cookiebot and so on) |
| A form with no information notice | A breach of article 13 of the GDPR | Add a notice under every form |
| Pre-ticked boxes | Invalid consent | Untick them and make the action explicit |
| A site on HTTP (with no HTTPS) | A security hole and an SEO penalty | Install an SSL certificate immediately |
| No record of processing activities | No way to justify compliance | Create the record and keep it up to date |
| Retention periods not defined | The storage limitation principle breached | Define and apply formal retention periods |
| Transfers outside the EU not mentioned | Incomplete information | Mention Google Analytics and the American services used |
| Incomplete legal notices | A breach of the digital economy law and the GDPR | Check and complete the compulsory information |
| No procedure for answering rights requests | No way to respect the GDPR deadlines | Create a dedicated address and an internal procedure |
Which good practices keep you compliant over time?
How do you organise GDPR monitoring for your firm?
GDPR compliance is not a fixed state, it is a continuous process. The regulation evolves, the regulator's recommendations sharpen, the tools used on the site change, and the firm's practices adapt. Keeping serious compliance over time calls for a few organisational reflexes.
Naming a GDPR lead within the firm, even in a small structure, is the first measure. That person does not have to be a technical expert: their role is to centralise the questions, keep the record of processing up to date, be the point of contact for people exercising their rights, and watch the regulatory developments. For firms that do not want to keep the role in-house, external data protection officers offer part-time engagements suited to modest structures.
Planning an annual compliance audit of the site is a structuring good practice. That audit, which can take two to three hours with a structured checklist, lets you check that the legal documents are still up to date, that the third-party tools used have not introduced new cookies without consent, that the retention periods are respected, and that the internal procedures are still applied.
Any significant change to the site, a redesign, a new form, a third-party tool integration, a change of host, has to trigger a specific GDPR review. Those moments are the most likely to produce compliance "oversights".
How do you answer the rights exercised by your site's visitors?
The GDPR gives the people whose data you handle a set of rights they can exercise at any time: the right of access, of rectification, of erasure (the "right to be forgotten"), of portability, of objection and of restriction of processing. As the controller, the firm has one month to answer any request, extendable to three months for a complex request, provided the person is informed within the first month.
To be able to respect those deadlines, you have to anticipate: create a dedicated email address (for instance, gdpr@yourfirm.com) mentioned in the privacy policy, and define internally who is responsible for handling those requests and by what procedure. Without that prior organisation, an erasure or access request can easily go unanswered in the flow of daily email, which is a sanctionable failing.
Which tools help bring your site into GDPR compliance?
Which solutions for cookie consent management?
For cookie consent, consent management platforms let you deploy a banner compliant with the regulator's recommendations in a few clicks. Among the solutions best suited to firms: Axeptio (a French solution, a careful interface, accessible pricing), Cookiebot (international, very complete, offering an automatic audit of the cookies present on the site), and Tarteaucitron (a free open source solution, popular in France).
Those platforms generally integrate through a simple script pasted into the site's code, with no advanced technical skill. They automatically generate the consent logs (proof of consent), which lets you justify in the event of an inspection that consent was properly collected in line with the rules.
Which tools for writing and maintaining your privacy policy?
Privacy policy generators are available online and can be a useful starting point, provided you personalise them carefully to reflect your firm's real processing. Iubenda and services specialising in data law offer adaptable templates. But a generic, unpersonalised privacy policy does not meet the GDPR's requirements of precision and transparency.
The best approach is still to have your privacy policy written or validated by a data law professional, an external data protection officer, a lawyer specialising in digital law, or a compliance consultancy. That one-off investment is far below the financial and reputational risk of non-compliance found by the regulator.
For the record of processing, a simple structured spreadsheet is enough for modest firms. The regulator makes a downloadable record template available on its site, which you can adapt to your work. More elaborate tools such as Dastra, OneTrust or Privacy Bee let larger structures manage the record more industrially.
How do you check your site's technical compliance?
Several tools allow a quick diagnosis of the site's technical compliance. The regulator's diagnostic, available directly on its website, checks the presence and compliance of the cookie banner. Google Search Console flags HTTPS problems and technical errors that could affect the site's security. GTmetrix and Google PageSpeed Insights assess the site's general performance and security, useful for making sure the security updates are being applied.
For a fuller audit, tools such as Screaming Frog let you crawl every page of the site and identify missing pages, broken links or non-compliant elements. A web professional or a GDPR consultant can run a thorough audit in a few hours.
Tool: GDPR checklist for a lawyer's site
Is your site GDPR compliant ?
Tick every point already in place on your site. The items in red are critical failings exposing your firm to sanctions.
Compliance level
Start the audit
Legal notices and privacy policy
The duty to inform your visitors
The legal notices are present, complete and reachable from the footer of every page
A privacy policy distinct from the legal notices is published and reachable from every page
The privacy policy states the purposes, legal bases and retention periods of each processing
The rights of the people concerned (access, rectification, erasure, objection, portability) are explicitly stated with how to exercise them
Any transfers of data outside the EU are mentioned (Google Analytics, Mailchimp, American hosts and so on)
The privacy policy mentions the right to complain to the regulator and its contact details
Cookies and trackers
Prior, informed consent under the 2022 regulator guidelines
A cookie consent banner appears on the first visit, before any non-essential cookie is placed
The "reject" button is as visible and reachable as the "accept" button (symmetry is compulsory)
The list of cookies placed (analytics, social media, advertising) is documented and reachable
Consent can be renewed and its validity does not exceed 13 months
The consent management platform logs the consents so they can be justified in an inspection
Contact forms and data collection
The most sensitive point of collection on a lawyer's site
A GDPR information notice appears directly under every contact form
Only the strictly necessary fields are required (the minimisation principle)
No tick box (newsletter, commercial consent) is pre-ticked by default
Form data is transmitted over HTTPS and stored in a secure environment
The forms are protected against spam and injections (CAPTCHA, server-side validation)
Retention and data management
The storage limitation principle: data kept means data justified
A record of processing activities is kept up to date and includes the processing carried out through the site
Retention periods are defined for every category of data collected through the site
The data is actually deleted or anonymised at the end of the defined retention periods
A dedicated email address or form is available for visitors to exercise their GDPR rights
An internal procedure is defined for handling rights requests within the one-month deadline
The site's technical security
An obligation under article 32 of the GDPR: technical measures appropriate to the risk
The site is on HTTPS with a valid SSL certificate (a padlock visible in the address bar)
The CMS and every plugin are kept up to date (security updates applied regularly)
Access to the site's back office is protected by a strong password and two-factor authentication
Automatic, regular backups of the site are configured with the host
A notification procedure in the event of a data breach is defined (notification to the regulator within 72h)
Organisation and keeping it up over time
Compliance is a continuous process, not a fixed state
A GDPR lead is named within the firm to centralise questions and maintain compliance
A compliance audit of the site is planned at least once a year
Any significant change to the site (a rebuild, a new form, a third-party tool) triggers a GDPR review
A quarterly watch on GDPR developments and the regulator's recommendations is organised
Need support to bring your site into compliance? OURAMA works with law firms on bringing their online presence into compliance: legal notices, privacy policy, cookie consent platform and form optimisation.
Conclusion: bringing your site into GDPR compliance, step by step
GDPR compliance for a lawyer's site is neither an insurmountable project nor a purely theoretical subject. It is a series of concrete measures, most of them reachable without advanced technical skill, that protect both the site's visitors and the firm itself against real risks: regulatory sanctions, loss of trust, and professional liability in the gravest cases.
The five actions to prioritise if you have not yet structured your compliance: check that your site is on HTTPS, deploy a compliant cookie banner with the ability to refuse in one click, write a privacy policy specific to your firm, add an information notice under every contact form, and create a record of processing, even a minimal one, for the data collected through the site.
Those five measures, put in place over the coming weeks, remove the most immediate risks and lay the foundations of lasting compliance. The rest, retention periods, procedures for answering rights requests, an annual audit, can be structured progressively.
At OURAMA, we work with law firms on bringing their online presence into compliance, from rebuilding the site to integrating the compulsory GDPR elements, by way of improving the service pages and the conversion paths. If you want to assess your site's compliance and identify the priority actions, get in touch for a first conversation.
.avif)




.jpg)


