A GDPR kit for your website: what you actually need to be compliant (not just a fake banner)
What a data-collecting website legally needs in Romania: real cookie consent, correct policies, data mapping and a short DPIA. The common mistakes, and what a GDPR kit includes — 1,500–3,500 RON.

There’s a common misconception that GDPR is a corporate problem. It isn’t. Any website that collects data — a contact form, Google Analytics, a Facebook pixel, a newsletter — falls under Regulation (EU) 2016/679. And the authority doesn’t look at company size; it looks at what you do with people’s data.
The good news: compliance for an ordinary business site is neither expensive nor complicated — if it’s done right from the start. The bad news: most sites “have GDPR” only for show, with a banner that does nothing.
What a compliant site actually needs
Four things, concretely:
- Real cookie consent — a tool that blocks trackers until the user accepts, not a banner that says “we use cookies” while Analytics is already running.
- A specific privacy policy — what data you collect, why, how long you keep it, who you share it with. Not a generic text copied from another site.
- A cookie policy — which cookies you use and for what.
- A clear lawful basis for each collection — consent, contract, legitimate interest.
If you sell or handle sensitive data (health, minors, financial data), you also need a Data Protection Impact Assessment (DPIA) and data-flow mapping.
Mistake #1: the fake cookie banner
It’s the most common and the riskiest. A banner saying “By continuing to browse you agree to cookies” is not consent under GDPR. Neither is a single “Accept” button that loads trackers no matter what you click.
Valid consent must be:
- prior — nothing loads before “Accept”;
- granular — the user can accept only the essentials and refuse marketing;
- as easy to withdraw as to give;
- provable — you must be able to show, in an audit, that the user consented.
That’s why we use real consent tools (Klaro open-source or Cookiebot), configured to keep trackers blocked until acceptance. Not a decorative banner.
What a GDPR kit includes
With us, a GDPR kit for websites costs 1,500–3,500 RON and covers everything needed for the site to comply with Regulation 2016/679:
- real cookie consent (Klaro/Cookiebot), blocking until acceptance and recording the choices;
- a privacy policy and cookie policy written for your site, not generic;
- data-flow mapping — what you collect and where it goes (hosting, email, payments, analytics);
- a short DPIA where applicable.
The price varies with how many integrations you have (more trackers, payments, CRM = more mapping) and whether you handle sensitive data.
Who needs it most clearly
Practically anyone with a form or analytics. But as a priority:
- online stores — you collect customer data, addresses, sometimes accounts;
- clinics, practices, optics — health data, a sensitive category (we did exactly this, for example, for Joy Optic);
- gyms, clubs, subscription services — members, recurring payments;
- anyone running ads (Meta/Google Ads) — those pixels are exactly what requires consent.
“I set it up once” isn’t enough
Compliance isn’t a box you tick once. You add a new tool (a chat, a pixel, an embed) and the cookie map changes — so the banner must be updated too. That’s why the GDPR part connects naturally to website maintenance: it stays compliant as the site evolves, not just on launch day.
In short
If your site collects any kind of data, GDPR concerns you — no matter how small the company. You need real cookie consent, specific policies, a data map and, where applicable, a DPIA. A complete kit costs 1,500–3,500 RON and gets you out of the risk zone, not just puts up a banner for looks. Tell us what you collect and with which tools, and we’ll tell you exactly what you need.
(This isn’t legal advice — for atypical situations or complex sensitive data, it’s wise to also consult a lawyer specialized in data protection.)