EUComply

Squarespace GDPR Compliance Guide 2026: What Site Owners Actually Need

· Filed under: Guides · Free compliance scanner →

Table of Contents

1. Does GDPR apply to Squarespace sites? 2. Six compliance requirements for Squarespace 3. Squarespace cookie consent setup 4. Privacy policy requirements 5. Data Processing Agreement (DPA) 6. Squarespace's built-in privacy features 7. Common compliance mistakes 8. Free compliance check for your site

If you built your site on Squarespace and it gets visitors from the EU, GDPR applies to you — even if your business is based in the US, UK, Australia, or anywhere else. GDPR follows your visitors, not your headquarters.

Squarespace is one of the most popular site builders in the world, and like every platform it ships with defaults that are not compliant out of the box. This guide walks through exactly what to set up, in plain language — no lawyer required.

1. Does GDPR apply to your Squarespace site?

Yes, if any of these are true:

GDPR's territorial scope (Art. 3) covers any business processing EU residents' personal data, regardless of where the business is registered. A wedding photographer in California with a Squarespace booking form serving clients in Germany? GDPR applies.

The same logic holds under the UK GDPR if you serve UK customers.

2. Six compliance requirements for Squarespace sites

Here is what every Squarespace site needs for GDPR compliance in 2026. These are the most common gaps we see when scanning sites across platforms with our free compliance scanner.

RequirementWhyCommon gap
Cookie consent banner ePrivacy Directive requires consent before non-essential cookies load Squarespace's built-in banner is off by default — most owners never switch it on
Privacy policy GDPR Art. 13: users must be told what data you collect and why Left as the untouched default template, or missing entirely
Data Processing Agreement (DPA) GDPR Art. 28: Squarespace processes data on your behalf; a DPA must cover it Most owners don't know Squarespace's DPA exists or that it applies automatically
Legal basis per purpose GDPR Art. 6: each data use needs consent, contract, or legitimate interest "Legitimate interest" claimed for marketing cookies — invalid in most EU countries
Data subject rights process Visitors can request access, deletion or export of their data No idea how to actually fulfil such a request when one arrives
Security measures GDPR Art. 32 requires appropriate technical safeguards Assuming "Squarespace handles security" covers everything — third-party scripts often don't

4. Privacy policy requirements

Your privacy policy must state, in plain language:

Squarespace can generate a starter policy, but treat it as a skeleton: it will not know about your Meta Pixel, your newsletter tool, or your booking software. Every tool you connect is a disclosure you owe visitors.

Also link the policy visibly — from your footer and next to any form that collects personal data. A policy nobody can find doesn't satisfy Art. 13.

5. Data Processing Agreement (DPA)

Squarespace acts as a processor for the personal data on your site, so GDPR Art. 28 requires a DPA between you and them. Good news: Squarespace's DPA applies automatically under their Terms of Service — you don't need to sign anything separately. Read it once so you know what they commit to.

But the chain doesn't stop there. You also need processing terms with:

If you work with business clients who ask you for a DPA — for example as an agency or freelancer — you need your own template ready. Ours is included in the document pack.

6. Squarespace's built-in privacy features worth using

What Squarespace deliberately does not give you is a full CMP for third-party scripts. If you inject custom pixels or chat widgets, blocking them is your job.

7. Common compliance mistakes on Squarespace

  1. Cookie banner enabled in "banner-only" mode. Looks compliant, blocks nothing. Choose "restrict data collection".
  2. Meta Pixel in Code Injection without consent gating. Fires on every visit, before any consent.
  3. Newsletter double opt-in turned off. In several EU countries, confirmed opt-in is expected for marketing emails.
  4. No imprint/legal notice. Required in Germany (Impressum) and several other member states even for foreign sellers — see our Impressum guide.
  5. Default privacy policy never edited. It won't mention your actual tools, so it fails Art. 13 transparency.
  6. Contact forms with no privacy-policy link beside them. A top enforcement target across the EU.

8. Free compliance check for your Squarespace site

You don't need to hire a consultant to find the obvious gaps. Our scanner checks HTTPS/HSTS security headers, cookie-consent platforms, Google Consent Mode v2, trackers loading without consent, privacy-policy links, legal pages, and more — on any platform including Squarespace.

Run it now, get a score in seconds, and see exactly which checks fail and how to fix them:

Scan my Squarespace site free →

Need documented proof — PDF reports, daily monitoring, and ready-made DPA/NIS2/accessibility documents? That's what EUComply Pro ($79/year) adds.

Further reading

How does EUComply compare with the established tools? See our head-to-head comparison — pricing, features and where each one falls short.

Related: Compliance is only half the story — knowing when your site goes down is the other. See our free uptime monitoring tools comparison.