By the Vertexweb team. Last reviewed 4 October 2026.
If your website has a contact form, a booking tool, analytics or a newsletter sign-up, it handles personal data. In the UK, that brings you under data protection law, so GDPR website compliance in the UK is something every small business owner needs to understand, even if you are not a technical person. The good news is that the basics are manageable with a clear plan.
This plain-English starter guide covers privacy policies, cookies and consent, forms, security, data requests, email marketing and the ICO fee. It is general information, not legal advice, so check the latest guidance from the Information Commissioner’s Office (ICO) or take professional advice for your situation.
Key takeaways
- Any website that collects names, emails, phone numbers or booking details is handling personal data.
- Publish a clear privacy policy that explains what you collect, why and how long you keep it.
- Non-essential cookies, such as many analytics and advertising ones, generally need consent in the UK.
- Only collect the data you need, keep it secure and know how to respond to requests.
- Check whether you need to pay the ICO data protection fee.
UK GDPR and PECR in simple terms
Two sets of rules matter most for websites. UK GDPR and the Data Protection Act set out how you must handle personal data: collect it fairly, use it for clear purposes, keep it secure and not hold it longer than needed. The Privacy and Electronic Communications Regulations, usually called PECR, cover cookies and electronic marketing such as email and text messages. Both apply to small businesses, not just large ones.
What personal data does your website collect?

- Names, emails and phone numbers from contact and enquiry forms.
- Booking details, which may include sensitive information for clinics.
- Newsletter sign-ups.
- Information collected by analytics and advertising cookies.
- Payment-related details handled by your payment provider.
List everything your site collects. You cannot explain or protect data you have not identified.
Write a clear privacy policy
Your privacy policy should explain, in plain language, who you are, what data you collect, why you collect it, what legal basis you rely on, who you share it with, how long you keep it, how people can exercise their rights and how to contact you. Link it in your footer and next to forms. Do not copy a policy from another company without checking that it truly describes what you do.
Cookies and consent
Cookies that are strictly necessary for your site to work, such as those keeping a basket or a login working, do not need consent. The ICO’s guidance treats analytics and advertising cookies as non-essential, so they generally need consent. That consent must be a clear, positive action: carrying on browsing is not enough, boxes must not be pre-ticked, non-essential cookies must not load before the visitor agrees and people should still be able to use the site if they refuse. Guidance and law in this area do change, so always check the latest ICO position before setting up tracking.
Forms and booking tools
Only ask for what you need. A contact form rarely needs a date of birth or home address. Add a short notice near the form explaining how you will use the details and linking to your privacy policy. Clinics and other health-related businesses should avoid collecting detailed medical information through standard forms. Our clinic website guide and booking system guide cover this further.
Keep data secure
Use HTTPS, strong unique passwords and two-step login, keep software updated and back up your site. Limit who can access forms and booking data and delete old enquiries you no longer need. Our website maintenance guide explains the routine that keeps sites safe.
Handling data requests and breaches
People have rights over their personal data, including the right to see it, correct it and in some cases ask for it to be erased. Be ready to respond, usually within one month. If a data breach occurs that risks people’s rights and freedoms, you may need to report it to the ICO within 72 hours. Make a short plan so you know who does what.
Email and text marketing
PECR sets rules for marketing messages. Generally you need consent to send marketing emails to individuals, with limited exceptions for existing customers, and every message must make it easy to opt out. Read our post on email marketing tips that keep subscribers engaged for practical advice on building a permission-based list.
The ICO data protection fee
Many organisations that process personal data must pay an annual data protection fee to the ICO, unless exempt. The ICO has a short self-assessment on its website. Check it, and keep a record of the result.
Other details your website may need
If you operate as a limited company, UK rules also expect certain company details on your website. Check current government guidance and our website launch checklist to make sure nothing is missed.
Common mistakes to avoid
- No privacy policy, or one copied from elsewhere.
- Setting analytics and advertising cookies before consent.
- Collecting more information than you need.
- Sending marketing emails without proper consent.
- Forgetting to delete old data.
- Not checking the ICO fee.
Frequently asked questions
Do small businesses need to comply with GDPR?
Yes. UK GDPR applies to organisations of all sizes that handle personal data, including small businesses with a simple contact form.
Do I need a cookie banner on my website?
If you use non-essential cookies, such as many analytics or advertising cookies, you generally need to get consent first. Check current ICO guidance for your set-up.
What should a privacy policy include?
Who you are, what data you collect, why, your legal basis, who you share it with, how long you keep it, people’s rights and how to contact you.
Do I have to register with the ICO?
Many organisations that process personal data must pay a data protection fee unless they are exempt. The ICO website has a short self-assessment to check.
Can I copy a privacy policy from another website?
It is not a good idea. A policy must describe your own practices accurately. Use a template as a starting point only and edit it to match what you do.
Final thoughts
Good GDPR website compliance in the UK starts with knowing what data your site collects, explaining it clearly and protecting it. Publish a proper privacy policy, handle cookies and consent carefully, collect only what you need and keep your site secure and up to date. This article is general guidance, so check the latest ICO resources or seek professional advice.
If you would like your website built with the basics in place, talk to our team.
Sources and further reading
- ICO: What are the rules on cookies and similar technologies?
- ICO: Data protection fee self assessment
Related reading
- Website Maintenance for UK Small Businesses
- Online Booking System for Small Businesses
- Clinic Website Design UK
- Small Business Website Checklist
Launch offer for UK small businesses. Get a professional website for just £299 a year. Only the first 20 customers, for restaurants, small clinics and small businesses.


