Our Blog

GDPR And Cookies: What Your Small Business Website Needs
28 Jul

GDPR And Cookies: What Your Small Business Website Needs

Data protection can feel like something only large companies need to worry about. It is not. If your website has a contact form, uses Google Analytics or shows a map, it collects or shares some personal data. This guide covers what GDPR and cookies mean for a small business website, in plain English, so you know what to check.

This article is general information, not legal advice, so speak to a qualified adviser if you are unsure about your own situation.

Who Makes The Rules

In the UK, two sets of rules matter most for websites. UK GDPR and the Data Protection Act cover how you collect, store and use personal data. The Privacy and Electronic Communications Regulations, usually called PECR, cover cookies and electronic marketing. The Information Commissioner's Office enforces both, and its guidance for organisations is written with small businesses in mind. It is the first place to look if you have a question.

What Counts As Personal Data On A Website

Personal data is any information that can identify a living person. On a typical small business website, that includes:

  • Names, email addresses and phone numbers sent through a contact form
  • Details entered when someone books, orders or signs up to a newsletter
  • IP addresses and device information collected by analytics tools
  • Data gathered by embedded content such as maps, videos and social media feeds

You are responsible for this data even when a third party, such as Google or your email provider, stores it for you.

A Clear Privacy Notice

Every business website that collects personal data should have a privacy notice. It should be easy to find, usually linked in the footer, and written so a normal person can understand it. It should explain:

  • Who you are and how to contact you
  • What data you collect and why
  • The lawful basis you rely on for each use
  • Who you share it with, such as your hosting company or email provider
  • How long you keep it
  • What rights people have, including how to ask for a copy of their data

A notice copied from another site, or generated without checking, often lists tools you do not use and misses the ones you do. Keep it accurate and review it when you add something new to your site.

Cookies And Consent

Cookies are small files that a website stores on a visitor's device. Some are essential, such as the ones that keep a shopping basket working. Others are used for analytics, advertising or tracking. Under PECR, you need consent before setting cookies that are not strictly necessary. The ICO's page on cookies and similar technologies explains the rules in detail.

In practice, this means a cookie banner that:

  • Appears before any non-essential cookies are set
  • Makes it as easy to reject cookies as to accept them
  • Does not use pre-ticked boxes
  • Lets visitors change their mind later
  • Links to a cookie policy that lists what each cookie does

A banner that only says "By using this site you accept cookies" does not meet these rules. Neither does one that loads Google Analytics before the visitor has clicked anything.

Contact Forms

Contact forms are the most common way a small business website collects personal data. Keep them simple. Only ask for what you need to reply. If you want to add people to a mailing list, use a separate, unticked box so they can choose. Make sure the form sends over a secure connection, which means your site needs a valid SSL certificate, and that messages are not stored in places you have forgotten about, such as an old plugin database.

Analytics, Maps And Embedded Content

Many small sites load third-party tools without the owner realising. A Google Map, a YouTube video, a Facebook feed or a chat widget can all set cookies or send data to another company. Check what your site actually loads. Where you can, hold non-essential content back until the visitor consents, or use privacy-friendly settings. Your analytics tool may offer options that reduce what it collects.

Security Is Part Of Data Protection

UK GDPR expects you to keep personal data secure. For a website, that means keeping software up to date, using strong passwords, taking regular backups and removing plugins you no longer use. A hacked site can leak form submissions and customer details. Our website maintenance plans cover security and plugin updates, daily backups, uptime monitoring and malware protection, which takes a lot of this off your plate.

Some Sectors Need Extra Care

If you handle more sensitive information, the stakes are higher. Law firms, accountants and healthcare providers often receive financial or personal details through their websites. Think carefully about what your forms ask for, and whether some information should be collected another way. We talk about this on our pages on websites for solicitors and websites for accountants.

A Quick Checklist

  • Do you have an up-to-date privacy notice linked from every page?
  • Does your cookie banner block non-essential cookies until consent is given?
  • Is rejecting cookies as easy as accepting them?
  • Do your forms only ask for what you need?
  • Is your site running on HTTPS with current software?
  • Do you know every third-party tool your site loads?
  • Are you registered with the ICO and paying the data protection fee if you need to?

Building It In From The Start

It is far easier to get this right when a site is built than to fix it later. When we handle website builds, we set up the privacy notice page, a proper consent banner and secure forms as part of the job, and we keep third-party scripts to what you actually need. If you are worried your current site is not up to scratch, get in touch and we will take a look with you.