Yes, this could be major and if your site--free or paid or anything in between--receives visitors from EU, you may be affected. Best thing you can do now is talk to a lawyer proficient in enacting GDPR policies to see what you may need to do in order to become compliant.
|