Skip to content

What GDPR Protects You From (in Plain English)

9 min readBy Jussi Saarinen

You clicked a link. Here's what happened in the next 2 seconds without your permission.

Let me tell you about something that happened to you today.

You probably don't remember it. It took about two seconds. You didn't feel anything. Nobody asked you. But it happened.

You visited a website.

Maybe you were looking for a recipe. Maybe checking a restaurant's opening hours. Maybe browsing for a new pair of shoes. Something ordinary. Something you do dozens of times a day without thinking.

And in those two seconds, before you read a single word, your personal information was collected, packaged, and sent to companies you've never heard of. In countries you've never been to. For purposes nobody explained to you.

You didn't agree to this. You weren't asked. It just happened.

Let me show you exactly what I mean.


The moment you clicked

You click a link to a website. A bakery, let's say. You want to see their opening hours and maybe look at some cinnamon rolls.

The page starts loading.

In the first 500 milliseconds, before anything even appears on your screen, a script runs. It looks at your device. What kind of phone or computer you're using. What browser. What language. What your screen size is.

This information leaves the bakery's website and travels to a company you've never heard of.

At 800 milliseconds, another script activates. This one checks if it recognizes you from other websites. It looks at your browsing history. What you looked at yesterday. What you searched for last week. It builds a picture of who you are.

This information also leaves the bakery's website. To another company. In another country.

At 1.2 seconds, your location is determined. Not just your country. Your city. Sometimes your neighborhood.

At 1.5 seconds, a tracking pixel fires. Facebook now knows you visited this bakery's website. So does Google. So do advertising networks you've never heard of.

At 2 seconds, the cookie banner finally appears. "We value your privacy," it says. "Click here to accept cookies."

But here's the thing.

Everything I just described already happened. Before the banner appeared. Before you could read it. Before you could click anything.

The banner isn't asking for permission. The banner is telling you what already happened.


Why this matters to you personally

Maybe you're thinking: "So what? I have nothing to hide."

Let me explain what "nothing to hide" actually looks like in practice.

That recipe website you visited last month? An advertising company knows about it. That medical symptom you searched for in a private moment? Logged. That surprise gift you were researching for your partner? Multiple companies now know about it. That political article you read? Recorded. Your late night browsing? Catalogued.

These companies don't just know individual things. They combine everything. They build a profile. They predict your income, your political views, your health concerns, your insecurities, your desires.

And they sell access to this profile. To anyone who pays.

That's why you see ads that feel eerily specific. That's why the internet seems to know what you're thinking. Because dozens of companies are watching everything you do online. Building a file on you. Trading it among themselves.

You didn't agree to this. You were never clearly asked. It just happens, silently, on almost every website you visit.


The websites that lie to your face

Here's where it gets worse.

Some websites have cookie banners that are pure decoration. They show you a popup. You click "Reject" or "Only necessary cookies." You think you've protected yourself.

But nothing changes. The trackers keep running. Your data keeps flowing. The button you clicked did nothing.

This is called fake consent. The website shows you a choice, but the choice is an illusion. No matter what you click, the same thing happens.

Other websites have what's called hardcoded tracking. This means the tracking is built so deeply into the website that it can't be turned off. There is no "off" switch. The consent banner is just theater. A performance to make you feel like you have control when you don't.

You trusted the website. The website lied to you.


Why GDPR exists

Now you understand why GDPR matters.

GDPR is a European law that says something very simple: you can't take people's personal information without asking them properly first.

"Asking properly" means asking before you collect, not after. Explaining clearly what you're collecting and why. Giving people a real choice to say no. Actually respecting that choice.

That's it. That's the core of GDPR. It's not complicated. It's just basic respect.

The law exists because what I described above became the normal way the internet works. Silent surveillance. Invisible data collection. Fake choices. Companies treating your personal information as their property.

GDPR says: no. That information belongs to you. And nobody gets to take it without your genuine permission.


You are not the product

There's a saying in the tech industry: "If you're not paying for the product, you are the product."

This has been true for years. Free websites make money by selling access to you. Your attention. Your data. Your profile.

GDPR challenges that model. It says that even if a service is free, you still have rights. Your data is still yours. Nobody gets to harvest it without your knowledge and consent.

When you visit a website and trackers fire before you can even see the cookie banner, that website is treating you as the product. You are being packaged and sold before you've had a chance to say no.

When a website shows you a fake consent banner that does nothing, that website is lying to you. They're pretending to respect your rights while violating them.

This is what GDPR is trying to stop.


What this means if you own a website

Now think about your own website.

When your customers visit, is this happening to them? Are they being tracked before they can consent? Is their data being shipped to companies they've never heard of? Is your cookie banner actually doing what it claims, or is it just decoration?

Most business owners don't know. They didn't set this up deliberately. It came with the website template. The developer added some tools. Nobody thought about what those tools actually do.

But your customers trust you. They visit your website expecting you to treat them with respect. They don't expect to be surveilled by 47 companies before they've even seen your menu.

The question is: do you actually know what your website is doing to your customers?


Finding out is easy

Here's the good news. You don't need to become a privacy expert to understand what your website does.

You can scan any website in 20 seconds. See exactly what loads before consent. See which companies receive your visitors' data. See whether your cookie banner actually works or whether it's just theater.

You can do this for your own website. You can do it for any website. The tools exist. They're free. And they're getting easier to use every year.

That's also why GDPR complaints are increasing. Citizens are checking. Customers are looking. The invisible is becoming visible.


Respect is not expensive

Being compliant isn't complicated. It's not expensive. It doesn't require a legal team.

It just means asking yourself: am I treating my customers the way I'd want to be treated?

Would you want websites to track you before you've had a chance to say no? Would you want your data sent to 47 companies while you're looking at cinnamon rolls? Would you want fake buttons that pretend to give you a choice?

Of course not. Nobody would.

GDPR just asks you to extend that same respect to your own customers.

That's why privacy pays off. Not because of fear of fines. But because customers increasingly notice which businesses respect them and which ones don't.

Be one of the good ones. It's easier than you think.

Safe browsing,

Jussi Saarinen

Founder

GDPR Scanner
Privacy that pays off.

Built in Finland, EU
for businesses everywhere.

Scan your website for free at

gdprscanner.eu