Skip to content

Marketing

What Legal Information Every Website Needs to Include

Running a website or an online store? Make sure you meet the legal requirements. Find out which data and documents are mandatory to keep your site safe, transparent, and compliant, and learn the rules around privacy policies, terms of service, and cookies. It's not just an obligation — it's also a way to build credibility with customers and search engines, and to boost your SEO.

Every website available online - whether it's a simple business card site, a full corporate site, or an online store - has to comply with applicable law, which means meeting certain information obligations and notifying visitors about what happens to their data. Do you know what every website is legally required to include? In this article, we explain which data and documents are mandatory, and what other information is worth adding.

Article summary

Every website must comply with applicable law, which means meeting information obligations and being transparent with users. You need to display your company's identifying details, a privacy policy that complies with GDPR, and inform visitors about cookies if the site collects them. Online stores should also include terms of service for electronically supplied services, along with a returns and complaints policy. It's also important to respect copyright rules when using protected content. Publishing consistent business information online has a positive effect on local SEO, search visibility, and customer trust.

State the business's identifying details

Every website belonging to a business must include basic identifying information, such as:

  • Full company name,
  • Registered address,
  • Tax identification number (NIP),
  • Business registry number (REGON),
  • Contact details (email, phone number),
  • Registration information (e.g. KRS, CEIDG) along with the registry number.

The legal basis for disclosing this information is Article 5(2) of the Act of 18 July 2002 on the Provision of Electronic Services (Journal of Laws 2002 No. 144, item 1204) - a general information obligation. Being transparent about this data builds customer trust and helps you avoid legal problems.

It's worth displaying your identifying information on your website for other reasons too. This matters not just for legal compliance, but also for SEO and visibility in search engines like Google. Here's why:

Does Google consider your website credible?

Google favors sites that are transparent and inspire trust. Providing full identifying details (company name, address, tax ID) helps Google's algorithms determine that a site is genuine and run by a real business. Missing this information can make a site look less credible, which hurts its ranking.

Consistency is the key! (Google Business Profile, local SEO, NAP consistency - Name, Address, Phone)

The relationship between your business data and Google actually goes much deeper. First, your identifying information (company name, address, phone number) is essential for local SEO. Google uses this information to connect your website with your Google Business Profile (GBP) and other local search results. If the information on your site and in your GBP is consistent, it increases your chances of better visibility in local search results and on Google Maps. And if your Google Business Profile includes a link to your website, make sure all the data is present - and consistent!

Second, NAP data (Name, Address, Phone) is the foundation of local SEO optimization. Google analyzes the contact details on your website and compares them with information from other sources, such as Panoramafirm.pl, Yelp, Targeo, or industry directories. Keeping this data consistent minimizes the risk of Google flagging your business information as "uncertain."

When your data is consistent and matches what's on your website, it strengthens your presence across these directories, increasing your reach in local search results - Google recognizes the connections between the data and gains more consistent information across multiple sources.

Users know who you are (and that you actually exist)

Providing identifying details increases users' trust in your site, which has a direct effect on visitor behavior - they can see that there's a real entity behind the site and that the information given can be verified.

A credible site, with accurate information and data - one that users feel confident browsing - translates into better metrics, such as longer session times and higher conversion.

Google tracks these metrics, and improving them has a positive effect on search rankings.

User trust in a site also depends on other things, including a valid SSL certificate. Security issues cause the browser to warn visitors that entering the site is risky.

In summary, identifying information is a key element not only for meeting legal requirements, but also for the effectiveness of your SEO strategy, building local visibility, and increasing trust from both Google's algorithms and users. Leaving it out can weaken your position in search results and in business directories.

Privacy policy (GDPR)

If your site collects users' personal data, for example through contact forms, newsletter sign-ups, cookies, or statistics tracking (even through Google Analytics), you need to include a privacy policy suited to your site, applicable to it, and describing what is done with visitors and their data. This document should include:

  • Data controller details,
  • The purpose and legal basis for processing data,
  • Information about data recipients (e.g. hosting providers),
  • The data retention period,
  • User rights (e.g. the right to erasure),
  • Information about the use of cookies.

The legal basis is GDPR, familiar to many people - Articles 12-14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

GDPR compliance isn't just a legal obligation - it's also part of building your site's credibility and transparency. It's worth checking whether your website, despite having a privacy policy document, actually processes personal data in a way that's lawful and consistent with that document. If you've started tracking statistics with Google Analytics (even just traffic tracking) on your site, or decided to add a newsletter sign-up form, make sure these are reflected in your privacy policy.

Violating GDPR on a website can lead to serious legal and financial consequences. Anyone can file a complaint with the President of the UODO (the Polish Data Protection Authority) about a site's non-compliance with GDPR or about a violation.

Violations carry very high administrative penalties. On top of that, GDPR violations are often widely publicized, especially when they involve well-known brands or large data leaks. The loss of trust from customers and business partners can be hard to rebuild, which affects a company's reputation.

Non-compliance with GDPR can also lead to exclusion from certain services or from working with partners who require regulatory compliance (e.g. technology platforms, payment operators).

How can your website violate GDPR? - examples

  1. No privacy policy, or unclear information about data processing when data is in fact being processed.
  2. Failing to obtain consent for data processing (e.g. no consent for cookies or the newsletter).
  3. Inadequate data protection - for example, a leak of customer or user data.
  4. Failing to respond to user requests regarding their rights (e.g. the right to erasure).
  5. Failing to meet information obligations toward the people whose data is being processed.

How to avoid GDPR violations?

  • Make sure your site has a privacy policy that complies with the law.
  • Inform users about data processing in a transparent way.
  • Obtain consent for data processing wherever it's required.
  • Regularly update your technical safeguards to protect data.
  • Put a data breach response policy in place that sets out quick actions to take in the event of an incident.

Terms of service for electronically supplied services

Every online store or service provided online must have terms of service. This document sets out the rules for using the site and covers things like:

  • The types and scope of services provided,
  • The procedures for entering into and terminating agreements,
  • Payment and delivery rules,
  • The complaint-handling process,
  • The rights and obligations of both parties.

Legal basis: Article 8(1) of the Act of 18 July 2002 on the Provision of Electronic Services (Journal of Laws 2002 No. 144, item 1204).

The terms of service must be available before a user starts using the services. To do this, they need to be presented in a clear, easily accessible way. Make sure the terms are easy to find and read on mobile devices too, since many users browse sites that way. Here are the key steps:

Place a link to the terms of service somewhere visible on the site

The terms of service should be accessible via a link in the following places:

  • The site footer - most users instinctively look for this kind of information there.
  • The navigation menu - particularly in an "About us" or "Legal information" section.
  • Registration forms - next to the checkbox confirming acceptance of the terms.
  • The cart page - for online stores, before the order is placed.

Confirming acceptance of the terms

Before using the services, users must confirm that they've read the terms of service. This can be done through:

  • A checkbox reading "I accept the terms of service for electronically supplied services" during registration, checkout, or login.
  • A link to the terms placed near the checkbox, so it can be opened easily.

Note: Under the law, the checkbox cannot be checked by default!

A dedicated terms-of-service page

Create a separate webpage dedicated to the terms of service, containing the full text. Make sure this page is easy to reach from other key sections of the site.

Example implementation for an online store:

  1. On the cart page, before the order is finalized, add a checkbox:
    "I have read and accept the terms of service for electronically supplied services [link to the terms]".
  2. Add an appropriate section to the order confirmation email:
    "Thank you for your purchase! You can find our terms of service here: [link to the terms]

Returns and complaints policy

Is a returns and complaints policy mandatory for an online store?

Yes, but it doesn't need to be a separate document. Information about returns and complaints can be included in the terms of service. A returns policy should cover the return procedure (required documents, return address, shipping), the consumer's right to withdraw from the contract within 14 days (since a purchase in an online store is treated as a distance contract or one concluded away from the business premises), and any exceptions to the right of return - for example, for personalized products.

A complaints policy, in turn, should clearly set out the procedure for filing a complaint and the deadlines for responding to it. It's also worth including how complaints are resolved and any information or documents that may be required from the consumer.

Article 27 and subsequent articles of the Act of 30 May 2014 on Consumer Rights (Journal of Laws 2014, item 827) define the type of contract involved (a distance contract) and set out the right to withdraw from it within 14 days of its conclusion, without giving a reason.

Not sure how to draft the terms and documents for your website or online store, or worried that your site doesn't meet the information obligations required by law? We offer consulting services and review sites for compliance with legal guidelines, along with much more - site performance, customer experience, process automation, and the potential of your online business. Find out what we can do for you and how we can support your business!

Under the ePrivacy Directive (Directive 2002/58/EC), if a site uses cookies, it must:

  • Inform users that they're being used,
  • Obtain consent for their use (except for strictly necessary cookies),
  • Provide a way for users to manage their cookie settings.

Although the ePrivacy Directive was the first piece of legislation to regulate cookies, its provisions are supplemented by GDPR (the General Data Protection Regulation). Cookies often collect personal data (such as IP addresses or user behavior data), which means their processing must comply with GDPR rules, including the requirement to obtain user consent for data processing.

If your website uses marketing tools that collect cookies, such as Hotjar or Google Analytics, you should inform users about this.

It's worth mentioning here what strictly necessary cookies (also known as "essential cookies") actually are. These are files stored in a user's browser that are required for the website to function correctly. Strictly necessary cookies are used, among other things, to maintain a user's session, ensure security, display content correctly, or carry out the site's basic functions.

Strictly necessary cookies are often temporary (so-called session cookies) and get deleted once the browser session ends. Unlike analytics or marketing cookies, strictly necessary cookies don't collect users' personal data for advertising or statistical purposes.

Information notices at points where data is collected

If your site uses a form (e.g. a contact or registration form), under GDPR it's treated as a point of data collection and is part of the data processing process. Every form therefore needs to satisfy the information obligation, covering:

  • Who the data controller is,
  • For what purpose and on what legal basis the data is processed,
  • What rights users have.

For contact forms on websites, this is usually handled through consent that the user must give before using the form. It's important that the message be worded clearly, doesn't bundle multiple consents together, and doesn't trick users into agreeing to actions they may not actually want!

Make sure your website has all the required information!

Complying with applicable law on your website is essential not only from a legal standpoint, but also for building user trust and search visibility. Following the rules around publishing identifying information, drafting a privacy policy, putting together terms of service for electronically supplied services, and respecting copyright rules:

  • Protects your business from potential financial and legal penalties.
  • Strengthens your brand's credibility with customers and partners.
  • Helps with SEO optimization, particularly in a local context.

Keep in mind that beyond meeting formal requirements, it's worth making sure your site's information is clear and easy to access. This not only makes the site easier for users to navigate, but also shapes their overall experience, which in turn increases the odds of conversion and the long-term success of your online business. Update your documents regularly and adapt your site to changing regulations to avoid problems down the road.

Is this aboutyour business?

We'll take a look at how this applies to you and what can be done about it. No-obligation conversation.