The Legal Pages Every EU Website Actually Needs (And What Regulators Fine You For)
Here is a pattern I see on a depressing number of small-business websites: a cookie banner with no cookie policy behind it, a privacy policy copied from a competitor three years ago (company name not even changed), terms of service that describe a product the business no longer sells, and no accessibility statement at all.
None of those things is the end of the world on its own. Together they are the first thing a complainant, a regulator, or a competitor's lawyer will screenshot. They are visible, they are easy to prove, and they signal that nobody is minding the shop.
This is the plain-English list of what you need, why, and what actually happens if you don't have it. I'm an engineer, not a lawyer; I co-built Legal Craft because I got tired of watching clients pay for the same five documents over and over. Treat this as the briefing before you talk to someone with a bar licence.
1. Privacy policy: not optional
If your website collects any personal data, you need one. "Any" includes: a contact form, a newsletter box, an account system, analytics, a chat widget, server logs with IP addresses. Which is to say, every website.
The law: GDPR Articles 13 and 14 list exactly what you have to tell people when you collect their data. It is a defined list, not a vibe:
- Who you are and how to contact you
- What data you collect and why (the "purposes")
- The legal basis for each purpose (consent, contract, legitimate interest…)
- Who you share it with, including processors like your email provider and your analytics vendor
- Whether it leaves the EU, and under what safeguard
- How long you keep it
- The person's rights: access, correction, deletion, objection, portability, and the right to complain to the supervisory authority (in Sweden, IMY)
What goes wrong: policies that list none of the actual vendors ("we may share data with partners"), no retention periods, and no mention of the legal basis. A policy that is generic is almost as bad as no policy, because it proves you have not thought about what you do with the data.
Fine tier: failing the information duties falls under the upper tier of GDPR Article 83: up to 20 million euros or 4% of global annual turnover, whichever is higher. Nobody fines a ten-person company 20 million euros. But the tier tells you how seriously the law takes it.
2. Cookie policy and consent: the one that gets small sites
This is where European enforcement has actually been landing on small and medium companies, because it is so easy to check from the outside.
The law: the ePrivacy Directive (Article 5(3)), implemented in Sweden through lagen om elektronisk kommunikation (LEK). The rule: you may only store or read cookies that are not strictly necessary for the service after the user has been informed and has consented. "Strictly necessary" means the shopping cart and the login session. It does not mean Google Analytics, the Meta pixel, Hotjar, or your ad retargeting.
Who supervises it in Sweden: PTS for the cookie rule itself, and IMY for the personal-data side of what those cookies collect. IMY published guidance in April 2025 specifically about dark patterns in consent banners: the pre-ticked boxes, the "accept" button in bold green next to a grey "manage settings" link, the reject option hidden two screens deep. Those designs are now explicitly on the radar.
What goes wrong:
- Trackers fire before the banner is answered (the most common failure, and visible in any browser's network tab)
- "Reject all" is missing or harder to reach than "Accept all"
- There is a banner but no policy explaining what the cookies are
- Consent is never re-asked and never expires
The fix: a consent management tool that actually blocks scripts until consent (Cookiebot, OneTrust, CookieYes, Klaro, the open-source options all work), configured so reject is as easy as accept, plus a cookie policy that lists the cookies by name, purpose, provider and duration.
3. Terms and conditions: if you sell anything
If money changes hands on your site, you need terms. For a brochure site they are optional; for a shop, a SaaS, or a booking system they are the contract.
The law: EU consumer law (the Consumer Rights Directive, in Sweden distansavtalslagen) requires you to give consumers specific information before they buy: total price, delivery, the 14-day right of withdrawal, how to complain, and who you are. Your terms are where that lives.
What goes wrong: terms copied from a US template that talk about Delaware law and binding arbitration, which are unenforceable against EU consumers and make you look like you did not read your own document. Terms that do not match how you actually sell (subscription in the terms, one-off purchase on the site).
4. Return and refund policy: if you ship or sell digital goods
Technically part of your terms, but EU consumers have a statutory 14-day withdrawal right on most distance sales, and you must tell them about it clearly or the period extends to 12 months. A separate, findable return policy page is the practical way to meet this and to reduce support email.
5. Accessibility statement: newly expected
Since 28 June 2025 the European Accessibility Act applies to e-commerce and a list of other consumer services. One of its concrete requirements is a published accessibility statement: which standard you aim for (in practice WCAG 2.1 AA via EN 301 549), what you know is not yet accessible, and how someone can contact you about it. I wrote a separate guide to the EAA covering who is in scope.
Public-sector sites in Sweden have needed one since 2019 under DOS-lagen. For private sites it is new, and it is the one page almost nobody has yet.
What enforcement looks like for a small company
Let me be concrete, because the fear-marketing around GDPR is unhelpful.
The multi-million fines go to Meta, Google, Klarna, Spotify. For a small company the realistic sequence is:
- A complaint, usually from a customer or a competitor, or an automated scan by an activist group (noyb has filed hundreds of cookie-banner complaints across the EU).
- A letter from IMY or PTS asking you to explain.
- An order to fix it, sometimes with a modest administrative fine, sometimes with a conditional fine (vite) if you don't comply by a date.
The cost is mostly the week you lose and the lawyer you now have to pay. The fine, when it comes, is sized to the company. But it is public, and "fined for illegal cookies" is not a headline you want next to your brand name in a Google search.
The accessibility side is earlier on this curve in Europe, but the US shows where it goes: more than 5,000 digital accessibility lawsuits in 2025, 70% of them against online shops.
How to get the documents without a lawyer invoice
For the standard case, a shop or a SaaS with the usual tools, the documents are predictable. They are templates with your specifics filled in: your company details, which jurisdictions your customers are in, which data you collect, which vendors you use.
That is exactly what Legal Craft does. You describe the business once; it generates the privacy policy, terms, cookie policy, return policy and accessibility statement from vetted, jurisdiction-aware templates, and regenerates all of them when your details change. The legal correctness lives in the templates and the jurisdiction logic, not in an AI making things up: a model only helps with phrasing, under strict validation, and no customer data is used for training. Export as Markdown, HTML or PDF and paste into any CMS.
When you do need a lawyer: unusual data (health, children, biometrics), B2B contracts with real negotiation, anything involving an investor or an acquisition. For the five pages above, you mostly don't.
The checklist
Before you close this tab:
- Privacy policy exists, names your real vendors, states retention and legal basis, links to IMY
- Cookie banner blocks non-essential scripts until consent; reject is as easy as accept; a cookie policy lists each cookie
- Terms match what you actually sell and reference EU consumer rights, not Delaware
- Return policy states the 14-day withdrawal right
- Accessibility statement published, with a contact address and a date
If you want a longer version of this list across accessibility, legal pages, consent and security, the EU Website Compliance Checklist is a free download, ungated for Inner Circle members.
General information, not legal advice. The GDPR, the ePrivacy Directive, LEK and the EAA are the sources; IMY and PTS publish guidance in Swedish and English. Talk to a lawyer for anything with real money on the line.



