Who this is for
Owners of Swedish solo and micro service businesses with a brochure website, contact form, booking link, newsletter form or website analytics.
Start with the owner question: what does your site actually do?
A service-business website can process personal data even when it does not sell online. Sweden’s privacy authority, IMY, explains that personal data is information that can identify a living person directly or indirectly. Common website examples include a name, phone number, image, IP address, cookie and a work email that identifies an individual. An inquiry sent through a contact form, a booking request or an email link can therefore involve personal data. 3
For a small service business, separate the question into two activities. First, do you collect or receive information about people—for example through a contact form, appointment tool, embedded map, newsletter signup or customer enquiry? Second, does your website store or read anything on a visitor’s device, such as analytics, advertising or preference cookies? The first activity points to GDPR information duties; the second can trigger Sweden’s cookie information and consent requirements. 3 4
Practical interpretation: do not begin by buying a banner or copying a privacy-policy template. Make a one-page inventory of each customer-facing feature on the live site. Record what a visitor can submit, which external services load, and whether those services use cookies or similar device storage. That inventory gives you a defensible basis for deciding what information is needed. 5 7
When a privacy notice is the useful baseline
The GDPR requires a business collecting personal data from an individual to provide information when the data is obtained. Article 13 lists core items including the controller’s identity and contact details, the purposes and legal basis for processing, recipients where relevant, and information about certain international transfers. It also requires further information needed for fair and transparent processing, such as retention information and rights-related details. 1 2
The European Commission’s business guidance says people should be told, among other things, the organisation’s name, purposes, data categories, legal basis and storage period. They must also be informed about relevant rights and the right to complain to a data-protection authority. Information should be concise, transparent, intelligible and in clear, plain language. 2
For an owner, a short privacy notice is normally more useful than a vague statement that you “respect privacy.” Write only what matches the real site. For example: identify the business and a contact route; explain what happens to an enquiry; state the purpose for using it; name the booking, email, hosting or analytics providers that receive data where applicable; describe the retention approach; and explain how a person can exercise their rights or complain to IMY. Have the owner check every sentence against the actual tools in use before publishing. 1 6 2
When a cookie banner is needed—and when it is not enough
PTS states that a website using cookies has two core obligations: provide information and obtain consent, including a possibility for the user to withdraw consent. The information must cover the purposes, cookies used, any third-party cookies, storage duration and the type of information collected and used. PTS says the presentation must be clear and complete enough for a user to understand what they are agreeing to. 4
Not every cookie needs consent. PTS identifies an exception for cookies necessary for a service requested by the user, or necessary to transmit an electronic communication. The authority specifically cautions that this is not based on what the website owner considers necessary; gathering statistics is not included merely because the business wants it. A functional checkout basket or a login-session cookie can be examples of necessary use, depending on the service. 4
Practical interpretation: a contact-only website that sets no non-essential cookies may need clear privacy information without needing a consent banner for analytics or marketing. By contrast, if the site loads visitor analytics, advertising tags, social-media pixels or other non-essential third-party cookies, use a choice mechanism before those tools run. A cookie banner does not replace the privacy notice: it deals with device storage and consent choices, while the notice explains the wider handling of personal data. 4 2
Check the services behind your website, not only the pages visitors see
A simple-looking website can rely on multiple outside suppliers. IMY notes that further GDPR rules can become relevant where a business engages a personal-data processor, transfers personal data outside the EU/EEA, or handles sensitive data, criminal-offence data or personal identity numbers. This is why an owner should not describe suppliers from memory or assume that a familiar software brand has no data-protection implications. 5
IMY also explains that a processing record should be written, kept electronically, kept current and made available to the authority on request. Its page notes an exemption can apply in some circumstances, but IMY recommends that organisations maintain records so they can keep track of their processing. The record content includes the controller’s details, processing purposes, categories of people and personal data, and recipient categories. 7
For a micro-business, make a lightweight working register even if you are unsure whether a formal exemption applies. Use rows such as “contact-form enquiries,” “booking requests,” “newsletter subscribers” and “website analytics.” For each row, note the data fields, purpose, supplier, access, likely deletion point and public wording used on the site. This is operational housekeeping, not a substitute for legal advice on difficult cases. 7 6
A practical publish-or-pause decision for this week
Use this decision rule. If a visitor can submit, email, book, call through a tracked number, sign up or otherwise give you information that identifies them, publish a tailored privacy notice before treating the website as finished. If your site also uses non-essential cookies, make the cookie information and consent choice work before those cookies are placed. If you cannot yet say what a widget, analytics script or embedded service does, pause that feature rather than publishing a statement you cannot support. 1 4 6
Keep the notice visible where a visitor needs it: in the website footer and next to a form or booking step where appropriate. The European Data Protection Board’s guidance notes that a general website privacy policy alone may not be sufficient in every context; relevant information may need to be presented when a person is asked to provide data. For an owner, that means pairing a clear link with a short, truthful form-level explanation such as why the enquiry details are needed. 8
Review the setup whenever you add a new booking system, pixel, chat tool, CRM connection or newsletter provider. IMY’s principles require specific and legitimate purposes, data minimisation, accuracy, storage no longer than necessary and openness toward the people concerned. The sensible owner habit is therefore to update the inventory first, then update the public notice and cookie choices if the real processing changes. 6 5
Keep the scope proportionate
This guide is designed for ordinary service-business websites and helps you identify the next practical question. It does not determine your precise legal basis, whether a specific cookie is strictly necessary, whether a supplier arrangement needs particular contractual terms, or whether a transfer outside the EU/EEA is lawful. Those points depend on the tools, configuration and data involved. Seek qualified privacy advice before launching higher-risk processing or handling sensitive client information. 5 1
The immediate owner outcome is not a longer legal document. It is a website you can accurately explain: what data comes in, what technology runs, who receives data, how long it is kept, and what choice the visitor has. That clarity makes it easier to spot a mismatch between your public wording and your actual website setup before a customer, supplier or authority does. 2 6
Website privacy and cookie decision checklist
01 · List features
Open the live site and list every form, booking link, chat widget, embedded map, video, analytics tag and newsletter signup.
02 · Capture data
For each feature, record exactly which visitor details, identifiers or messages are collected, received, stored or passed onward.
03 · Name suppliers
Write down the host, form provider, booking tool, email system and analytics provider that can access or receive website data.
04 · Check cookies
Use your site and browser tools to identify cookies or similar storage, then separate necessary functions from analytics and marketing.
05 · Draft notice
Publish plain-language privacy information that matches your inventory, including contact details, purposes, retention approach and rights route.
06 · Set choices
Before enabling non-essential cookies, provide clear cookie information, a consent choice and a practical way to withdraw consent.
07 · Review changes
Repeat the inventory and update website wording before adding a new third-party tool, tracking script or customer-data connection.
Evidence boundary
This is a practical triage guide, not legal advice or a compliance certification. It relies on public GDPR, IMY, PTS and EU guidance, but your obligations depend on your actual tools, configuration, customers, data categories, contracts and international data flows.
How this relates to Stacksen
If you use Stacksen, it can help you record the initial website inventory, name an owner for each review step, and track whether the privacy notice and cookie choices have been checked. It does not establish legal compliance or promise an improved business outcome.
Sources
1. eur-lex.europa.eu — eur-lex.europa.eu
2. commission.europa.eu — commission.europa.eu
3. www.imy.se — imy.se
4. pts.se — pts.se
5. www.imy.se — imy.se
6. www.imy.se — imy.se
7. www.imy.se — imy.se
8. www.edpb.europa.eu — edpb.europa.eu