NormaKit Guide

GDPR Compliance for Freelancers: The Plain-Language Guide

Practical guide · EU GDPR · applies whether you're based in Italy, elsewhere in the EU, or outside the EU and serving EU customers

Most GDPR explainers are written for corporate legal teams. If you're a freelancer, sole trader, or micro-business (regime forfettario, ditta individuale, or a small SRL) who runs a website, sells online, or emails clients, you don't need a €500/year retainer to be compliant — you need to understand a handful of concepts and act on them once. This guide covers what actually matters, without the legalese.

What GDPR actually is, in one paragraph

The General Data Protection Regulation (GDPR) is an EU law governing how you collect, store, use, and share personal data — any information about an identifiable living person (names, emails, IP addresses, purchase histories, even a photo). It applies to you if you're established in the EU and process anyone's personal data, even just an email address in a contact form. It doesn't matter if you're a solo freelancer with one client or a growing shop — the law scales with your risk, not your size.

The seven core principles (Art. 5)

  1. Lawfulness, fairness, transparency — have a legal reason to process data, and be upfront about it.
  2. Purpose limitation — collect data for specific reasons; don't repurpose it later without telling people.
  3. Data minimisation — only collect what you actually need. Don't ask for a phone number "just in case" if you never call anyone.
  4. Accuracy — keep data correct and up to date; let people fix errors.
  5. Storage limitation — don't keep data forever "just in case"; delete or anonymise it once you no longer need it (subject to legal retention rules like invoices).
  6. Integrity and confidentiality — protect data with reasonable security.
  7. Accountability — you must be able to demonstrate compliance, not just claim it. This is why documentation (a ROPA, your policies) matters even if no one ever asks to see it.

The six legal bases (Art. 6) — you need one for every processing activity

Legal basisWhen it appliesExample
ConsentFreely given, specific, informed, unambiguous opt-inNewsletter signup
ContractNecessary to perform a contract with the personProcessing an order
Legal obligationYou must do it by lawKeeping invoices for tax purposes
Vital interestsLife-or-death situationsRare for most businesses
Public taskOfficial authority tasksNot applicable to private business
Legitimate interestYour interest, balanced against the person's rightsBasic site security logs, replying to an enquiry someone sent you
The most common freelancer mistake: using "consent" for everything — including things that don't need it, like replying to a contact form, which just creates unnecessary paperwork — or using no legal basis at all for marketing emails, which is the one place you almost always need explicit, unbundled consent.

Data subject rights — what people can ask you for

Anyone whose data you hold can ask to: access it, correct it, delete it, restrict its use, get a portable copy, object to certain processing, or withdraw consent. You generally have one month to respond (extendable to three for complex requests). Keeping an up-to-date Record of Processing Activities (ROPA) is the fastest way to answer "what do we hold on this person and where" when a request comes in — see our ROPA basics guide.

Do you need a DPO (Data Protection Officer)?

Almost certainly not, if you're a typical freelancer or micro-business. A DPO is mandatory only if your core activity involves large-scale systematic monitoring (e.g. you run an ad-tech/tracking business) or large-scale processing of special-category data (health, biometric, etc. — e.g. you run a clinic's records system). Selling templates, running a shop, or freelancing as a designer or consultant does not trigger this.

Cookies and ePrivacy — a separate law, often confused with GDPR

GDPR governs personal data generally; the ePrivacy Directive specifically governs cookies and similar tracking technologies, and requires prior consent for anything beyond strictly-necessary cookies. See our cookie consent banner guide for the practical checklist: no pre-ticked boxes, an equal-prominence "reject all", and logged consent.

Eight common mistakes (fix these first)

Day-one checklist

  1. Publish a Privacy Policy on your site, linked from every page footer.
  2. Publish a Cookie Policy and implement a compliant consent banner if you use any non-essential cookies.
  3. Add the relevant consent clauses next to every form that collects data (contact, newsletter, checkout) — short, drop-in "informativa breve" notices, not the full policy repeated everywhere. See our consent clauses guide for ready-to-adapt wording for each form type.
  4. Check every third-party tool you use (hosting, email, payments, analytics) — do you have, or need, a DPA with them?
  5. Fill in a mini ROPA — one row per data-collecting activity you actually run.
  6. Keep a breach checklist somewhere you can find it even if your main systems are down (printed, or in a separate cloud account).
  7. Set a calendar reminder to review all of the above every 6–12 months, or whenever you add a new tool, supplier, or data collection point.

Where to go for official guidance (free, authoritative)

Don't want to draft all of this from scratch?

NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this situation: a ready-to-edit Privacy Policy, Cookie Policy, consent clauses, a full Art. 28 DPA, a mini Records-of-Processing (ROPA) template, and a breach-notification checklist — €29 one-time, instant download, editable .docx and .pdf.

See what's included →

Not legal advice. This guide is general information, not a substitute for advice from a qualified lawyer or data protection professional about your specific situation. NormaKit's templates are likewise informational starting points, not legal advice, and should be reviewed and adapted before use.